winaba Privacy Policy: How We Handle Your Information
At winaba, the way we collect, store and use your information is set out clearly here — no buried clauses. This policy covers every interaction you have with our platform, from opening an account to making a payment via bKash, Rocket or Upay, and it applies to you wherever access is permitted under your local law and eligible region.
Account data protected
bKash, Rocket, Upay payment privacy
Your rights, clearly stated
Contact us any time
POLICY SCOPE NOTICE
What This Policy Covers and How It Applies
This policy applies to all data winaba collects when you use our platform — account registration details, session activity, device information and payment transaction records. When you deposit or withdraw using bKash, Rocket or Upay, those transactions pass through the respective payment provider's own systems; their privacy terms apply to that leg of the journey, and ours apply to the record we hold on our side. We collect only what is necessary to operate your account, process transactions and respond to support requests. We do not sell your personal data to third parties. Data is retained for as long as your account remains active and for any period required by applicable law in your eligible region. If you close your account, we will retain only what we are legally required to keep and delete the rest in line with our internal retention schedule. Access to your stored data is restricted to authorised staff and systems. Any third-party service we use — such as analytics or fraud-detection tools — is bound by data-processing agreements that limit how they may use your information. Your use of this platform and the applicability of this policy depend on your local law and the eligible regions we serve.
bKash
Payment records for bKash transactions are held on our side only; bKash's own privacy terms govern their processing.
Rocket
Rocket payment data follows the same split: we hold the transaction record; Rocket holds the transfer detail under their policy.
Upay
Upay deposits and withdrawals are subject to Upay's privacy terms for their leg; winaba retains only the account-side record.
INSIDE VS OUTSIDE
Where This Policy Applies and Where It Does Not
Not every data interaction on or around our platform falls under this policy. Understanding the boundary helps you know who to contact when a question arises. The four areas below draw that line clearly — what we own, what we process on your behalf, what sits with a third party, and what falls outside our reach entirely.
Account Access
All data tied to your winaba account — login credentials, profile details, session history and account wallet records — falls fully within this policy. You can review and request corrections to this data at any time through your account settings or by contacting support.
Transactions
Payment transaction records that winaba holds are covered here. The data processed by bKash, Rocket or Upay on their own infrastructure is governed by their respective privacy policies, not ours. We recommend reading those policies alongside this one.
Site Content
Your browsing behaviour on our platform — pages visited, games opened, time on site — is collected by us and covered by this policy. We use this data to improve the experience and to detect unusual account activity, not to build advertising profiles.
Third-Party Services
Links or integrations that take you away from winaba — including external payment gateways, identity verification services or any linked site — operate under their own privacy terms. Once you leave our domain, this policy no longer applies.
YOUR PRACTICAL RIGHTS
Actions You Can Take Under This Policy
You have real, actionable rights over the data winaba holds about you. These are not abstract promises — each one has a concrete path you can follow right now. Log in to your account and open the profile or settings section to review the personal details we hold. If something is wrong — a name, a contact number, an address — you can update it directly from that screen without needing to contact us. For data that cannot be self-edited, our support team can make the correction on your behalf once your identity is confirmed. If you want to know exactly what data we hold, you can submit a data access request through the support channel. We will respond within the timeframe required by applicable law in your eligible region. Closing your account triggers our data-deletion process for non-mandatory records. The steps below outline the four main actions available to you.
Review Your Records
Open your account settings page to see the personal data currently stored against your profile, including contact details and account wallet history.
Correct Account Details
Edit your name, phone number or email directly in the profile section. For fields that are locked, raise a correction request with our support team and we will update it after verifying your identity.
Submit a Data Query
If you want a full record of what we hold, contact us via the support route listed on this page. State clearly that you are making a data access request and include your registered account details.
Request Account Closure
To close your account and trigger deletion of non-mandatory data, contact support directly. We will confirm the closure and outline which records we are required to retain under applicable law.
REACH OUR TEAM
How to Contact Us About This Policy
Questions about this policy, your data or a correction request can be sent through the channels below. Use the route that suits you — all of them reach the same team. When writing in, include your registered account identifier so we can locate your records without delay.
Live Chat
Open the chat widget on winaba while logged in to reach our support team directly. This is the quickest route for account-specific data questions.
Email Support
Send your privacy or data request to the support email address listed in your account's help section. Include your account ID and a clear description of your request.
Help Centre
The Help Centre on winaba carries written answers to common privacy questions. Check there first — many data and account queries are answered without needing to contact the team.
HOW WE PROTECT DATA
Data Handling, Cookies and Account Security
We take a straightforward approach to data security: limit what we collect, protect what we hold, and make it easy for you to understand both. The four areas below cover the main ways we handle your information day to day.
Cookies and Tracking
We use cookies to keep your session active, remember your preferences and measure how the platform is used. You can manage cookie settings through your browser. Disabling non-essential cookies will not prevent you from using your account.
Account Security
Your account is protected by password authentication and, where enabled, additional verification steps shown in your security settings. We do not store your payment credentials — bKash, Rocket and Upay handle those on their own secure infrastructure.
Data Retention
We keep your data for as long as your account is active and for any period required by law in your eligible region. When retention is no longer required, records are deleted or anonymised in line with our internal schedule.
Policy Updates
When this policy changes in a material way, we will notify you via the contact details on your account before the change takes effect. Continued use of the platform after that date means you have acknowledged the updated terms.
COMMON POLICY QUESTIONS
Privacy Policy Questions Answered
The questions below cover what we hear most often from account holders about data, rights and contact. If your question is not here, reach out through the support routes listed above.
What personal data does winaba collect when I open an account?
We collect the details you provide during registration — name, contact information and account credentials — along with session and device data generated when you use the platform. Payment transaction records are also held on our side when you transact via bKash, Rocket or Upay.
Does winaba share my data with third parties?
We do not sell your data. We share it only with service providers who help us operate the platform — such as fraud-detection or analytics tools — and only under data-processing agreements that restrict how they may use it. Payment providers like bKash and Rocket receive only what is needed to process your transaction.
How do I see what data winaba holds about me?
Log in and open your account settings to review your stored profile details. For a full data access request covering all records we hold, contact our support team via live chat or the support email in your account's help section and state clearly that you are making a data access request.
Can I correct wrong information on my account?
Yes. Most fields — contact number, email, address — can be updated directly in your profile settings. For locked fields, contact support with your account ID and the correction needed. We will update the record after confirming your identity.
How long does winaba keep my data after I close my account?
When you close your account, we delete non-mandatory records as part of our standard closure process. Certain data must be retained for the period required by applicable law in your eligible region. We will tell you which records fall into that category when you submit a closure request.
Does this policy apply to my bKash or Rocket transactions?
This policy covers the transaction record winaba holds on our side. The data processed by bKash, Rocket or Upay within their own systems is governed by their respective privacy policies. We recommend reading those alongside this one for a complete picture of how your payment data is handled.