Reference

How We Handle Your Data and Account

We keep your account information, payment records and personal details under clear internal policies. Access to our platform depends on your local law and eligible regions — we outline exactly what applies to you here, from data use to wallet verification through bKash, Nagad…

Data Handling PoliciesAccount Access TermsbKash & Nagad VerifiedWallet Security ProtocolsRegion-Dependent Access
sona2 How We Handle Your Data and Account
REACH OUR POLICY TEAM

Contact Us About Legal Matters

If you have questions about how we store your data, process your bKash or Nagad transactions, or handle account verification, our policy team is reachable through multiple paths. We respond to data-related queries with priority because your account security matters to us.

Live Chat Open live chat from any page on our site. Raise your legal or data query and an agent will route it to the policy team. You get a reference number for tracking, and responses come back through the same chat window or your registered contact.
Email Support Send your request to our support email with your account username included. Data access requests, correction requests and account closure queries all go through this channel. We acknowledge receipt and follow up within the timeframe shown in your confirmation.
In-App Message Tap the support icon inside your mobile account to send a message directly. This works whether you deposited via bKash, Nagad or Rocket — reference your last transaction if the query relates to payment data and our team will pull the relevant records.
HOW WE PROTECT YOU

Data Handling and Account Security Practices

We apply specific measures to keep your account, wallet details and personal data under control. Each practice below describes something concrete we do — not a vague promise. From cookie management to how long we retain your records, this is how the system actually works when you use sona2.

Data Encryption

All data moving between your device and our servers travels through encrypted channels. This covers login credentials, bKash or Nagad transaction details, personal information and session tokens.

Cookie Usage

We use session cookies to keep you logged in and preference cookies to remember your language and layout choices. No tracking cookies are shared with advertisers.

Account Verification

Before processing your first withdrawal through Rocket, bKash or Nagad, we verify that the linked wallet matches your registered name. This one-time step prevents unauthorised fund transfers and protects your balance if your login credentials are ever compromised.

Data Retention

We keep transaction records and account activity logs for as long as your account remains active, plus a defined period after closure for audit compliance.

Requesting Your Data

You can ask for a full export of the personal data we hold on you. Send the request through live chat or email with your username, and we compile the file for you.

Policy Updates

When we change how data is collected or used, we notify you via your registered contact method before the change takes effect.

Common Questions About Our Policies

Below are the questions our support team receives most often about data, access and account rights. Each answer gives you the specific steps or facts — no vague pointers.

We collect your name, phone number, email address and the mobile wallet details you link for deposits via bKash, Nagad or Rocket. We also record your device type and IP region to confirm access eligibility based on local law and eligible regions.

Yes. Contact our support team through live chat or email with your username and a deletion request. We close the account, process any remaining balance to your linked wallet, and remove personal identifiers from active systems within the retention window stated in our policy.

Open live chat or send an email to support with the specific detail you need updated — for example, a new phone number tied to your Nagad wallet. We verify ownership through a confirmation step and apply the change to your profile.

We do not sell or share your personal information with unrelated third parties. Data may be shared only with payment processors like bKash, Nagad or Rocket to complete your transactions, and with internal audit systems required for compliance.

If access rules shift in your area, we may restrict or close accounts in that region. Your data is retained for the standard post-closure audit period, after which personal identifiers are stripped. You can request an export before closure takes effect.

We use session and preference cookies only — no advertising trackers. You can delete cookies through your browser settings at any point. This logs you out and resets layout preferences, but no personal data is lost from your account.

No. Payment references including wallet numbers are encrypted at rest within our database. Even in the unlikely event of a data breach, raw wallet numbers would not be readable. We apply the same standard to Rocket and Upay details.

Reach our support team immediately through live chat or the in-app message icon. Provide your username and describe the suspicious activity. We freeze the account, review recent login and transaction logs, and guide you through wallet re-verification before restoring access.

We send a notification to your registered email or phone number before any policy change takes effect. The notification includes a summary of what changed. You can review the full updated text on this page, and raise concerns through support if needed.

Yes. Eligibility to use sona2 depends on your local law and the regulations of your specific region. We do not make blanket claims about legality. If you are unsure, check your local rules or contact our support team for clarification on region-specific access.