Reference

How We Handle Your Data and Account

We keep our legal policies transparent so you know exactly what happens with your information when you use rocketplay. Access, eligibility and data rights depend on your local law and eligible regions — read on for specifics on how we store, process and protect…

Account Data PolicyCookie DisclosurebKash & Nagad ContextRegional EligibilityUser Rights
rocketplay How We Handle Your Data and Account
DATA AND ACCOUNT HANDLING

How We Protect What Belongs to You

We built our data practices around the principle that your account information is yours. From encrypted storage to controlled access and clear retention timelines, every step is designed so you understand what we hold and why. If you transact via bKash, Nagad or Rocket, your wallet credentials never sit in plain text on our servers — they are tokenised at the point of entry and only the reference token is stored for repeat transactions.

Encrypted Storage

All personal and financial data is encrypted at rest and in transit. Whether you deposit through Nagad or verify your identity, the information travels through secured channels and lands in encrypted databases with tiered access controls.

Cookie Management

We use session cookies to keep you logged in and analytics cookies to improve platform performance. You control which optional cookies run — adjust preferences in your browser or through the cookie banner that appears on first visit.

Account Security Layers

Your account is protected by password plus OTP verification sent to your registered mobile number. If you access rocketplay from a new device, we trigger an additional confirmation step before granting full account control.

Data Retention Policy

We retain account data only as long as your account is active or as required by applicable law. Once you request deletion and no legal hold applies, we remove personal records within a defined processing window and confirm completion via…

Third-Party Disclosure

We share data only with payment processors (bKash, Nagad, Rocket, Upay, bank partners) to execute your transactions, and with authorities if lawfully compelled. No data is sold for advertising or shared with unrelated marketing platforms.

How to Request Changes

Log in to your account, open settings, and select the data rights section. From there you can submit a request to export, correct or delete your personal data.

POLICY CONTACT PATHS

Reach Us About Any Legal Query

If something in our legal documentation is unclear, or you want to exercise a data right, we have multiple ways for you to get in touch. Our support channels handle policy questions alongside general account help, so you never need to hunt for a separate legal desk. Reach out from your mobile — the same device you use for bKash or Nagad deposits — and a team member will pick up your query.

Live Chat Open the chat widget from any page on mobile or desktop. Policy questions are tagged for priority routing, so you connect with someone who can speak to data rights, account restrictions or cookie queries without being bounced between departments.
Email Support Send your legal query to the address listed in your account settings. Include your registered username and a brief description of what you need — data export, correction request, or eligibility clarification — and we aim to respond within one…
Account Notification Centre Policy updates and responses to formal requests appear in your notification centre. Check there for confirmations after you submit a data access request or when we push an updated privacy or cookie notice that affects your account.

Common Questions About Our Legal Policies

Below are the questions we hear most often from account holders about data, eligibility, cookies and their rights. If your question is not covered here, reach out through live chat or email and we will address it directly.

We collect your name, email, mobile number, date of birth and the payment method you register — whether that is bKash, Nagad, Rocket or bank transfer. Device type, IP address and session timestamps are also logged for security and compliance.

Yes. Go to account settings, select data rights, and submit an export request. We compile your records — transaction history, identity documents, session logs — into a downloadable file and notify you by email when it is ready for collection.

Submit a deletion request through your account settings. If no legal retention obligation applies, we process the deletion and confirm by email. Some transaction records may be held longer if required under the laws of your jurisdiction.

Your wallet credentials are tokenised at the point of entry. We store only a reference token for repeat transactions — never your full wallet PIN or login details. The tokenisation process means even internal staff cannot view your raw payment credentials.

Access is restricted to authorised personnel who handle account verification, compliance queries or payment processing. Each access event is logged, and team members operate under strict internal data handling policies with regular audits.

No. We share data only with payment processors to execute your transactions and with authorities if lawfully compelled. We do not sell, lease or pass your information to external advertising networks or unrelated marketing services.

Access to rocketplay depends on local law and eligible regions. It is your responsibility to verify whether participation is permitted where you reside. We may restrict account features or registration based on jurisdiction-level compliance requirements.

We use essential session cookies to keep you logged in and optional analytics cookies to track platform performance. You can disable optional cookies through your browser settings or the cookie banner. Essential cookies cannot be turned off without losing session functionality.

Material policy changes are communicated via your registered email and through the notification centre inside your account. We provide advance notice before changes take effect so you have time to review updated terms and decide how to proceed.

Dormant accounts are flagged after a defined inactivity period. We may reach out to confirm whether you wish to keep the account open. If you do not respond and no legal hold applies, data retention timelines begin and we eventually remove personal records.