Reference

How We Handle Your Personal Information

We built this policy so you know exactly what data we collect, why we collect it, and how we protect it when you deposit through bKash, Nagad or Rocket.

Data collection transparencyPayment data handlingAccount security practicesWithdrawal verification stepsYour right to request changes
ultra9 How We Handle Your Personal Information
PRIVACY CONTACT PATHS

How to Reach Us About Your Data

Have a question about what we store or want something deleted? These are the channels where our team handles privacy-related requests. Each channel connects you to staff trained on data queries, not general account issues, so your request gets handled properly without being passed around.

Team online

Live Chat

Open the chat widget from any page on our site. Tell the agent your request is about personal data—they will route it to the privacy queue. You will get a reference number to track progress. Most data queries receive an initial response within the same chat session.

Email

Send your privacy request to our support email with the subject line containing your registered mobile number. Include what you need: a data copy, correction or deletion. Our team reviews email privacy requests and sends confirmation once processing begins.

Account Settings

Log into your account and head to the profile section. From there you can update your name, email and phone number directly without contacting support. For full data export or account deletion requests, use live chat or email as those require manual verification by our team.

DATA HANDLING PRACTICES

How We Protect and Manage What We Collect

Every piece of data you share with us goes through defined handling steps. Below we explain the six core areas of our data practices—from encryption in transit to how long we keep records after account closure. We want you to understand each layer clearly, because your confidence in how we treat data directly affects whether you feel comfortable depositing via bKash, Nagad or Rocket.

Encryption in Transit All data exchanged between your device and our servers travels over SSL-encrypted connections. This applies whether you are logging in, making a bKash deposit or updating your profile details. The encryption standard prevents third parties from intercepting information mid-transfer between your phone and our platform.
Stored Data Security Personal records sit on servers with access restricted to authorised personnel only. Payment details from Nagad or Rocket transactions are tokenised—meaning we store a reference code, not your full wallet credentials. Periodic internal checks verify that access logs match expected staff activity.
Cookie Management We use session cookies to keep you logged in and preference cookies to remember your language and display settings. No advertising cookies track you across other websites. You can delete cookies from your mobile or desktop browser settings at any time—doing so simply means you will need to log in again next visit.
Data Retention Period Your data stays on file while your account is active. After you close your account, we retain records for a period consistent with applicable regulatory obligations in eligible regions. Once that period ends, personal identifiers are permanently deleted from our active databases. Transaction hashes may remain for audit trails.
Your Right to Request Changes You can ask us to correct inaccurate information, provide a full copy of what we hold, or delete your data entirely. Submit the request through live chat or email with your account verification details. We process corrections directly; deletion requests go through a confirmation step to prevent accidental account loss.
Who Receives Your Data We share transaction data with bKash, Nagad or Rocket only to process your deposits and withdrawals. No personal data goes to marketing partners. If a legal authority in an eligible jurisdiction makes a lawful data request, we review it for validity before disclosing the minimum information required by that specific order.

Common Questions About Your Privacy

We have gathered the data-related questions that come through our live chat most often. If yours is not answered below, reach out directly and our team will clarify your specific situation.

We collect your full name, mobile number, email address and date of birth during registration. If you deposit via bKash, Nagad or Rocket, we also log the transaction reference and amount. Device model and browser type are recorded automatically for session security purposes.

No. We do not sell, rent or share your personal information with any third-party marketing company. Data is shared only with payment processors like bKash, Nagad or Rocket to complete your transactions, and only the minimum information those processors need to settle the transfer.

Open live chat or send an email request including your registered phone number. Our team will verify your identity through the standard account verification process, then compile a data export. You will receive it as a downloadable file sent to your registered email address.

Yes. Submit a deletion request through live chat or email. We will confirm your identity, then begin the deletion process. Some records may be kept for a limited period if required by applicable law in eligible regions, but personal identifiers are removed from active systems promptly.

After closure, we retain essential records for a regulatory compliance period. Once that window passes, personal data is permanently erased from active databases. Transaction hashes—anonymised references without your name or wallet details—may remain in audit logs as required.

We do not store your full wallet credentials. When you deposit through bKash, Nagad or Rocket, the transaction generates a tokenised reference code. That code is what sits on our servers—enough to match the payment to your account, but not enough for anyone to access your wallet directly.

Every connection between your phone and our servers is encrypted using SSL. Session tokens expire after inactivity, forcing a fresh login. If we detect an unusual device or location attempting to access your account, we trigger an additional verification step before granting access.

This policy governs how we handle data for every account interaction on our platform. However, access to our services and the specific legal frameworks that apply depend on your local law and eligible regions. We encourage you to understand the rules that apply where you are located.

Log in, go to your profile section and edit your name, email or phone number directly. Changes to verified identity documents require contacting support through live chat so our team can re-verify. Corrections are processed without charge and reflected on your account within a short period.

We use session cookies to keep you logged in and preference cookies to remember display settings. No advertising or cross-site tracking cookies are deployed. You can block or delete all cookies in your browser settings at any time—the only effect is that you will need to log in again on your next visit.