Reference

How We Handle Your Data and Account

Everything here explains what we collect, how we store it, and what rights you hold over your own account information.

Data ProtectionAccount RightsCookie DisclosurebKash & Nagad ContextContact Paths
super8 How We Handle Your Data and Account
POLICY CONTACT PATHS

Reach Us About Legal or Data Queries

If something in these policies raises a question or you want to exercise a data right, reach us through one of the channels below. We handle legal and data queries separately from general account help, so mention the word 'data' or 'legal' when you write in and we route it to the correct team faster.

Team online

Live Chat

Open the chat widget from any page on mobile or desktop. State your query relates to legal or data and you will be escalated past general support. Response is typically quick — no need to send multiple messages.

Email Channel

Send your request to the address listed in your account settings under Help. Include your registered phone number and a brief description of what you need — data copy, correction or deletion — so the team can verify ownership immediately.

Account Settings Request

Inside your account dashboard, under the personal information section, you can submit a formal data request directly. This creates a logged ticket tied to your profile, which makes tracking and follow-up straightforward for both sides.

DATA AND ACCOUNT SECURITY

How We Protect What Belongs to You

We treat your account information the way you treat your bKash PIN — carefully and with layers between it and anyone who should not see it. Below are six specific practices that define how we manage, protect and give you control over your data within the super8 environment.

Encrypted Storage

All personal identifiers and payment-linked data are encrypted at rest using industry-standard protocols. Even internal team members access records only through permissioned, logged queries — no raw data sits exposed in any system layer.

Session Cookies

We use session cookies to keep you logged in across pages and to prevent cross-site request attacks. These expire when you close your browser or after a set idle period.

Wallet Verification

When you link bKash, Nagad or Rocket, we verify ownership through a micro-confirmation step. This ensures no one else can attach their wallet to your account or initiate a withdrawal to an unverified destination.

Retention Policy

Transaction records stay on file for as long as applicable financial regulations require in your eligible region. Non-essential session data and browsing logs are purged on a rolling schedule — we do not hoard what we no longer need.

Right to Access and Deletion

You can request a full copy of your stored data or ask us to delete non-essential records. Submit the request via live chat or the account settings form. We confirm what was actioned and notify you once complete.

Incident Response

If we detect unusual activity on your account — login from an unrecognised device, rapid password attempts — we lock access and notify you through your registered contact. You regain control by verifying identity through the original linked mobile number.

Common Questions About Policies and Data

Real questions we receive about legal matters, data rights and account policies. If your question is not here, reach out through live chat or the email channel and mention it relates to legal.

We collect your name, phone number and the payment identifier linked to your bKash, Nagad or Rocket wallet. This data is used for identity verification, transaction processing and fraud prevention — nothing more.

Yes. Open a data request via live chat or through the account settings form. Mention you want a full data copy, provide your registered mobile number for verification, and we will compile and deliver the file within a reasonable timeframe.

Contact us through any support channel and specify which records you want removed. We delete non-essential data promptly. Transaction records required by financial regulation in eligible regions may be retained until the mandatory holding period ends.

We do not sell your data to advertisers or data brokers. Limited information may be shared with payment processors like bKash, Nagad or Rocket solely to complete your transactions, and with fraud-prevention services where required.

We deploy session cookies for login persistence and security tokens. Analytics cookies are anonymised. You can manage or block cookies through your mobile browser or device settings — though blocking session cookies may require you to log in again each visit.

Yes. Eligibility depends on your local law and whether your region is supported. We may restrict or suspend accounts located in jurisdictions where access is not permitted, and we update this page if coverage changes.

When you add a wallet, we send a micro-confirmation to the number associated with it. You confirm receipt inside your super8 account, which locks that wallet to your profile and prevents unauthorised attachment by someone else.

We detect unrecognised login attempts and lock the account immediately. A notification goes to your registered contact. You regain access by verifying your identity through the original linked mobile number — no one else can bypass that step.

Financial transaction data is retained for the period required by applicable regulation in your eligible region. Once that window closes, records are purged. Non-financial session logs rotate on a much shorter cycle.

Open a correction request through live chat or the account settings panel. Provide the detail you want changed and confirm your identity via your registered phone number. We process corrections and confirm once the update is live.