Reference

How We Handle Your Privacy at sona88

We process personal data only to run your account, verify payments and keep the platform secure. This policy explains what we collect, why we hold it, and how you can request changes or deletion — availability depends on your local law and eligible regions.

bKash, Nagad, Rocket Payment DataAccount Verification StepsData Access RequestsCookie PreferencesEncrypted Storage
sona88 How We Handle Your Privacy at sona88
DATA HANDLING PRACTICES

How We Protect and Manage Your Information

Every piece of data we hold serves a specific operational purpose — running your deposits via bKash or Nagad, confirming withdrawal requests, or keeping your login secure. Below is a breakdown of six areas that matter most when it comes to your privacy on the platform.

Encryption at Rest and in Transit All data moving between your device and our servers uses SSL encryption. Stored data sits on encrypted databases. Even internal staff access requires multi-factor authentication and role-based permissions, so only the team handling your specific request can view relevant records.
Cookie Usage We use session cookies to keep you logged in and analytics cookies to understand how pages load on mobile devices. We do not use advertising trackers that follow you across other websites. You can clear cookies from your browser settings at any time without losing your account.
Account Security Your account is protected by a password you set and an OTP sent to your registered mobile number during sensitive actions like withdrawal or password reset. If you notice unusual activity, contact us immediately through live chat — we can freeze the account while we investigate.
Data Retention Period We keep your personal data for the lifetime of your active account. After you close your account, we retain records for a limited period to satisfy any legal or dispute-resolution requirements. Once that window passes, data is permanently deleted from our systems.
Who to Contact for Data Changes For corrections to your name, mobile number or email, use the account settings page. For a full data export or complete deletion request, email our support team or open a live chat and ask for the data-handling desk. Provide your registered number so we can verify ownership quickly.
Third-Party Sharing Limits We share payment reference data with bKash, Nagad or Rocket solely to process your deposit or withdrawal. No marketing data leaves our platform. If a lawful authority in an eligible region requests specific records, we comply only within the boundaries of that legal order.
PRIVACY HELP CHANNELS

How to Reach Us About Your Data

If you have a privacy concern or data request, we have specific channels set up so your query reaches the right team without delay. You do not need to explain your entire account history — just state what data action you need and include your registered mobile number or email.

Live Chat Open the chat widget from any page. Tell the agent you have a privacy or data request, and they will escalate it to the data team. You can do this from mobile or desktop — the same chat handles both.
Email Send your request to our support email with the subject line 'Data Request'. Include the mobile number linked to your account and specify whether you want access, correction or deletion. We aim to acknowledge within a few working days.
Account Settings Log in and head to your profile section. Under privacy preferences you can update marketing consent, change your contact email, and see which devices are currently linked. For full data export or deletion, use chat or email.

Common Questions About Your Data and Privacy

These are the questions our support team receives most often regarding privacy, data access and account information. If your question is not covered here, reach out via live chat and reference this page so the agent knows the context.

We collect your name, mobile number, email address, and the device identifier you use to access the platform. If you deposit via bKash, Nagad or Rocket, we also store the transaction reference linked to that payment. We do not ask for unnecessary documents unless verification is triggered.

Your mobile number is the primary verification channel. We send a one-time password during login from a new device, during withdrawal requests, and when you reset your password. It is also how we confirm ownership if you raise a data request through support.

Only the minimum transaction details needed to complete your deposit or withdrawal are shared with the relevant payment provider. We do not pass your browsing activity, game history or marketing preferences to any payment partner.

Open a live chat or send an email to our support team with the subject 'Data Export Request'. Include your registered mobile number and email. We will verify your identity through OTP, then prepare and deliver the export within a reasonable timeframe.

Yes. After you close your account you may submit a deletion request through email or live chat. We will remove personal data once any applicable retention period has passed. Some anonymised transaction records may remain for legal compliance, but they cannot be linked back to you.

We use session cookies to maintain your login state and basic analytics cookies to monitor page performance on mobile. We do not run third-party advertising trackers. You can disable cookies in your browser settings, though this may require you to log in again each session.

The transaction happens within the bKash app environment. We receive only the confirmation reference and amount — never your bKash PIN or full wallet credentials. Communication between our server and the payment gateway is encrypted via SSL throughout.

Yes. When we make material changes, we notify you by email or through an account notification the next time you log in. The updated policy takes effect from the date stated at the top of this page. If you disagree with a change, you can close your account and request data removal.

Access to the platform and how your data is processed depends on your local law and eligible regions. We do not make legal determinations about your jurisdiction — but we apply consistent encryption and access controls regardless of where you connect from.

Access is role-based. Only staff handling account verification, payment processing or support queries can view your records, and only the specific fields relevant to their task. Administrative access is logged and audited regularly to prevent misuse.