Reference

Privacy Policy: How We Handle Your Information

We collect your account details, payment records and session activity to run the platform and process bKash, Nagad and Rocket transactions. This page explains what we gather, why we need it, how long we keep it, and the choices you have.

Account & wallet dataTransaction recordsSession & device logsContact preferencesRights & requests
win bd Privacy Policy: How We Handle Your Information
DATA SECURITY

How We Protect Your Information

Your login password is hashed so even our own systems cannot read it in plain text. Payment requests to bKash, Nagad and Rocket travel over encrypted connections and we never store your wallet PIN or OTP code. Session cookies expire after fourteen days of inactivity and we log you out automatically if you switch devices.

Encryption in transit

Every page and API call uses HTTPS so login credentials, deposit amounts and withdrawal requests cannot be intercepted between your phone and our servers. Payment confirmations from bKash, Nagad and Rocket also arrive over secure webhooks.

Password hashing

We hash your password with a one-way algorithm at registration. When you log in we hash what you typed and compare the hashes; we never store or compare the plain-text password itself, so a database leak would not expose usable…

Retention periods

Active account records stay available as long as your profile is open. Transaction logs are kept for at least two years to meet audit requirements.

Third-party sharing

We send transaction data to bKash, Nagad and Rocket only to complete deposits and withdrawals; those providers have their own privacy policies. Game studios receive a session token but not your name or wallet details.

POLICY QUESTIONS

Contact Us About Privacy

If you want to know what data we hold, request a copy of your records, ask us to delete your account, or update your contact preferences, reach us through live chat or email. Support handles privacy requests during the same hours we answer payment and account questions.

Live chat Open the chat icon in the bottom corner and tell the agent you have a privacy or data request. They will confirm your identity with your registered mobile number and process erasure, access or correction requests on the spot or escalate to the data team.
Email support Send your request to the support address shown in the footer. Include your username and registered mobile number so we can verify the account. We aim to respond within two business days and complete most privacy actions within a week.
Account settings Log in and visit the profile page to change your email address, mobile number or marketing consent toggles. Updates to contact details take effect immediately; preference changes apply to the next campaign cycle.

Privacy Policy FAQ

We ask for a mobile number, a username and a password. The mobile number is used for login OTP and withdrawal verification. Your email address is optional but helps with password recovery and account notices.

No. You enter your wallet PIN directly in the bKash, Nagad or Rocket app when you confirm a deposit or withdrawal. That PIN never passes through our platform; we only receive a transaction success or failure message.

Deposit and withdrawal records are retained for at least two years to meet financial audit and anti-fraud requirements. After that period older logs may be archived or anonymised unless local law requires longer retention.

Yes. Contact support via live chat or email with your username and registered mobile number. We will send you a file listing your account details, transaction history, session logs and support tickets within seven business days.

Open a live chat or send an email request with your username. We will close the account and anonymise or erase personal identifiers within thirty days, except transaction records that must be kept for audit purposes under local law.

We share transaction details with bKash, Nagad and Rocket to process payments, and we send a session token to game studios so you can launch slots and live tables. We do not sell contact lists or session data to advertisers.
Reference

Privacy Policy

Service availability depends on eligible regions and local law. Users should check local rules before opening an account.

Access may be available only where local law permits.