Reference

How sona2 Handles Your Privacy

We collect only what we need to run your account, process your bKash, Nagad or Rocket transactions, and keep your wallet secure.

Data Collection TransparencyPayment Info ProtectionAccount Deletion RightsCookie PreferencesRegional Compliance
sona2 How sona2 Handles Your Privacy
DATA HANDLING PRACTICES

How We Keep Your Information Safe

We take a layered approach to protecting the data tied to your account, your transactions and your sessions. Every measure described here applies whether you access sona2 from a mobile browser, a desktop, or through your bKash, Nagad or Rocket app flow. Below are the six areas we focus on to maintain the integrity of your personal information.

Encryption in Transit

All data moving between your device and our servers travels through SSL-encrypted channels. This means your login credentials, wallet details and session tokens cannot be intercepted by third parties during transmission — the same standard used by major mobile wallet providers.

Cookie Management

We use session cookies to keep you logged in and preference cookies to remember your language and layout choices. No cookie stores your wallet PIN or full payment credentials. You can clear cookies from your browser settings at any time without losing your account balance.

Account Verification

Before processing a withdrawal or a data export request, we verify your identity through a one-time code sent to your registered phone number. This prevents someone else from moving your funds or accessing your personal data even if they gain temporary access to your device.

Data Retention Policy

We retain personal data only while your account remains active and for the minimum period required in your jurisdiction. After you confirm deletion and no pending Rocket, Nagad or bKash withdrawals remain, we strip personal identifiers from our active records within a defined processing window.

Third-Party Sharing Limits

Payment processors receive only the fields they need to complete a transaction — your wallet ID and the transfer amount. We never share your full transaction log, browsing history or device fingerprint with advertisers, affiliates or data brokers under any circumstance.

Change and Deletion Requests

You can ask us to correct inaccurate data or delete your profile entirely. Submit through live chat or your account settings panel. We confirm receipt, verify ownership via OTP, and process the request. Deletion removes personal identifiers; anonymised analytics data may remain for internal reporting.

PRIVACY CONTACT PATHS

How to Reach Us About Your Data

If you have questions about how your information is handled, want to request a copy of your stored data, or need to submit a deletion request, our support channels are available. We aim to acknowledge every privacy-related enquiry within one working day, and most data requests are resolved within a reasonable timeframe depending on complexity.

Team online

Live Chat

Open the chat widget from any page on sona2. Select the privacy or account category and describe your request. An agent will pick up the conversation and guide you through identity verification before processing any data action on your behalf.

Email Support

Send your data request to our support email with your registered phone number and a brief description. We verify your identity by matching the sender address against your account record, then action deletion or export requests in the order received.

Account Settings

Inside your sona2 dashboard, open the privacy section under account preferences. From there you can view which data categories we hold, toggle marketing communications off, and submit a formal deletion request that routes directly to our data team without needing to wait in chat.

Common Questions About Your Data Rights

Below are answers to the questions our support team receives most often about data handling, account privacy and your rights when using sona2. If your specific concern is not covered here, reach out through live chat or email and we will respond directly.

We collect your name, phone number, email address, preferred mobile wallet (bKash, Nagad or Rocket) and a password you create. We also log your device type, IP address and session timestamps to detect unusual access patterns and protect your account from unauthorised logins.

Only the minimum data needed to process a payment goes to our payment partners — your wallet ID and transfer amount. We do not sell, rent or give your browsing history, personal details or full transaction records to advertisers, data brokers or any unrelated third party.

Open your account settings, go to the privacy section, and submit a deletion request. Alternatively, contact live chat. We verify your identity with an OTP sent to your registered number, confirm no pending withdrawals exist, then remove personal identifiers from our active database.

We retain your information while your account is active. After confirmed deletion, personal identifiers are removed from active systems. Some anonymised data may remain for internal analytics, but it cannot be traced back to you individually. Retention timelines depend on applicable regional regulation.

We use session cookies (to keep you logged in), preference cookies (to remember your language and layout) and analytics cookies (to understand lobby usage patterns). None store your wallet PIN. You can disable or clear cookies in your browser settings at any time without affecting your balance.

No. We never store, log or have access to your mobile wallet PIN. Transactions are initiated on our side and completed when you confirm within your own bKash, Nagad or Rocket app. The PIN entry happens entirely within the wallet provider's secure environment, not on our servers.

All connections use SSL encryption, which you can verify by checking for the padlock icon in your browser address bar. This applies whether you access the site from a mobile browser or desktop. SSL ensures your credentials and transaction data remain encrypted during every session.

Yes. Submit a data export request via live chat or through the privacy section in your account settings. After identity verification via OTP, we compile your stored data — profile details, transaction history, login records — and deliver it to your registered email in a standard format.

We notify you of material changes via email or an in-account banner before they take effect. Your continued use after the notice period means you accept the updated terms. If you disagree with any change, you can request account deletion before the new policy applies.

Access to sona2 and the data protections described here depend on your local law and eligible regions. We apply baseline protections uniformly, but specific rights such as data portability or erasure timelines may vary based on the regulations that govern your jurisdiction.