Reference

How We Handle Your Account Information

We collect and protect the details you share when you access Sona101 — your contact information, payment preferences through bKash, Nagad and Rocket, and the activity visible in your account wallet.

Account securityPayment data protectionAccess controlsContact preferencesRetention periods
Sona101 How We Handle Your Account Information
POLICY QUESTIONS

Reach Us About Your Data

If you want to review the personal information we hold, request a correction, or ask us to delete records no longer required by regulation, contact our privacy team through any of the channels below. We respond to data-subject requests within the timeframe set by applicable law in eligible regions, and we will walk you through each step of the verification process before making changes to your account.

Live chat Open the chat bubble on any page and ask for the privacy team. An agent will verify your account and explain the request process, usually within a few minutes during operating hours.
Email support Send your data request to our support address with your registered mobile number and account username. We reply within two business days with the next steps and any documents you need to complete.
Account settings Log in, navigate to Privacy Controls, and toggle your marketing preferences or download a copy of your transaction history. Changes take effect immediately and apply to future communications.
SECURITY PRACTICES

How We Protect Member Records

Your account sits behind encrypted connections, two-factor login codes sent to your mobile, and role-based access limits that restrict which staff members can view payment details. We audit our data flows regularly, apply security patches as they are released, and train our support team on confidentiality protocols so your information stays within the platform and is never shared without your explicit consent or a lawful regulatory obligation.

Encrypted storage Payment records and personal identifiers are stored in encrypted databases with access logged and reviewed. We use industry-standard protocols to protect data at rest and in transit between your device and our servers.
Login verification Every sign-in triggers an OTP sent to your registered mobile number. Without that code, the session remains locked, even if someone knows your password, adding a second layer of protection against unauthorized access.
Cookie management Essential cookies keep you logged in and remember your language choice. Non-essential cookies track session behaviour for analytics; you can opt out in your browser settings without losing core account functions.
Data retention limits Transaction logs are kept for the minimum period required by financial regulations, then archived or purged. Closed accounts are anonymized after the retention window expires, removing personal identifiers while preserving audit trails.

Privacy Policy Questions

We ask for your mobile number, email address and a password, then record your chosen payment method — bKash, Nagad or Rocket — so we can match deposits to your account and process withdrawals back to the same wallet.

Yes. Contact our support team via live chat or email, verify your identity with your registered mobile number, and we will send you a copy of your account records, transaction history and any marketing preferences on file.

Log into your account, open Settings, navigate to Privacy Controls, and toggle off marketing messages. The change is immediate, and you will still receive essential notifications about withdrawals, security alerts and policy updates.

We share transaction data only with the payment processor handling your bKash, Nagad or Rocket transfer, and only to the extent needed to complete or verify that specific transaction. We do not sell contact lists or payment records.

Transaction logs are retained for the period required by financial regulations in the jurisdictions where we operate, typically several years. After that window, records are archived or anonymized, and personal identifiers are removed.

We anonymize your profile after the mandatory retention period expires, removing your name, mobile number and email while keeping an audit trail of transactions for regulatory compliance. You can request early deletion of non-required data by contacting support.
Reference

Privacy Policy

Service availability depends on eligible regions and local law. Users should check local rules before opening an account.

Access may be available only where local law permits.