Reference

How xxx66 Handles Your Personal Information

When you open an account with us, we collect certain personal details to keep your wallet secure and your sessions running smoothly — including payment data from bKash, Nagad and Rocket transactions.

Account data protectedbKash, Nagad, Rocket payment privacyNo data sold to third partiesYou control your preferencesContact us to update records
xxx66 How xxx66 Handles Your Personal Information
DATA SECURITY PRACTICES

How We Protect and Retain Your Account Data

We use SSL encryption on every page where you enter account details or payment information. Session tokens expire automatically after a period of inactivity, so an unattended device cannot stay logged into your account indefinitely. We review our data-retention schedule periodically and remove records that no longer serve a legitimate purpose.

Encryption on Every Transaction All data exchanged during bKash, Nagad or Rocket transactions is encrypted in transit. We never store raw wallet credentials on our servers — only the references needed for reconciliation.
Cookie Use and Your Choices We use session cookies to keep you logged in and analytics cookies to understand how the lobby is used. You can adjust cookie preferences from your browser settings at any time.
Account Security and OTP Login to your account triggers an OTP sent to your registered mobile number. This step blocks access even if someone has your password — a direct safeguard for your wallet balance.
Data Retention and Deletion We retain transaction records to meet our internal compliance requirements. Once your account has been inactive beyond the retention threshold, we remove personal identifiers from our records on request.
PRIVACY CONTACT PATHS

Reach Us About Your Privacy Rights

If you want to review the data we hold, request a correction or ask us to remove your details, our support team handles privacy requests directly. Send your request through any of the channels below and include your registered account email so we can locate your records promptly.

Live Chat Open the chat widget from your account dashboard. Agents handle privacy requests alongside general account queries during support hours.
Email Support Write to our support address with your account email and the subject line 'Privacy Request'. We aim to respond within the timeframe shown in your confirmation reply.
Account Help Page Log in and visit the Account Help section to submit a data-access or data-deletion form. Your request is logged and tracked until resolved.

Privacy Policy Questions We Hear Most

Below are the questions we receive most often about how xxx66 handles your data. If your question is not covered here, reach out via live chat or email and our team will respond with the specific detail you need.

We collect your name, email address, mobile number and the payment references from your bKash, Nagad or Rocket transactions. We do not collect your wallet PIN or full card details.

Yes. Send a data-access request through live chat or email with your registered account email. We will compile and share the records we hold on you within the timeframe stated in our acknowledgement reply.

We share data only with payment processors handling your bKash, Nagad or Rocket transactions, and with fraud-prevention services when investigating a dispute. We do not sell your data to advertisers.

Session cookies keep your account active during a visit. Analytics cookies help us improve the lobby layout. You can block or delete cookies through your browser settings without losing your account access.

We retain transaction records for our internal compliance period. After your account becomes inactive beyond that threshold, we remove personal identifiers from active systems on request or per our review schedule.

Contact support immediately via live chat. Change your password and check your OTP settings. We will investigate any suspicious login activity and can temporarily lock your account while we review it.
Reference

Privacy Policy

Service availability depends on eligible regions and local law. Users should check local rules before opening an account.

Access may be available only where local law permits.