Reference

How winking Handles Your Personal Information

We collect only what we need to run your account, process your bKash, Nagad or Rocket transactions, and keep your wallet secure.

Account Data ProtectionPayment Info HandlingCookie TransparencyYour Rights ExplainedLocal Wallet Privacy
winking How winking Handles Your Personal Information
PRIVACY HELP

How to Reach Us About Your Data

If you have questions about your personal data or want to make a request — access, correction or deletion — reach out through any of these channels. Our support team handles privacy queries with the same priority as account issues, so you will not be waiting longer just because your question is about data rather than a deposit.

Team online

Live Chat

Open live chat from any page on the platform. Let the agent know your query is about personal data, and they will route you to the privacy handling queue. Available around the clock so you can raise a request whenever it suits you.

Email Request

Send a written data request to our support email. Include your registered phone number and a brief description of what you need — access, correction or deletion. We acknowledge receipt and respond with next steps within a reasonable timeframe.

Account Settings

Some data preferences can be managed directly from your account settings on mobile or desktop. You can update contact details, toggle marketing communications and review your active sessions without needing to contact support at all.

DATA HANDLING PRACTICES

How We Protect and Manage Your Information

Privacy is not a checkbox we tick once — it shapes how we build features, store records and respond when you ask questions about your data. Here is a closer look at the specific practices behind this policy, covering everything from encryption to how long we hold your transaction records.

Encrypted Storage

Personal details and transaction records sit behind encrypted layers both in transit and at rest. Your bKash, Nagad or Rocket references are stored separately from identity data, so a single breach point cannot expose everything at once.

Cookie Management

We use session cookies to keep you logged in and analytics cookies to understand page usage. No advertising trackers from third parties run on our pages. You can clear or block cookies from your browser settings without losing account access.

Account Security Layers

Login sessions are tied to your device fingerprint and IP range. If we detect access from an unfamiliar device, we trigger a verification step via your registered phone number before the session is granted.

Data Retention Periods

We keep active account data as long as your account is open. After closure, transaction records are retained only for the period required by applicable regulations in your jurisdiction, then permanently deleted from our systems.

Your Right to Access and Delete

You can request a copy of all personal data we hold on you, or ask us to delete it entirely. Deletion requests are processed after verifying your identity through your registered mobile number and confirming no pending transactions remain.

Third-Party Sharing Limits

We share data only with payment processors handling your bKash, Nagad or Rocket transfers and with fraud-prevention partners. No data goes to marketing firms or data brokers. Each partner operates under a data-processing agreement aligned with this policy.

Common Questions About Your Data on winking

We have gathered the questions our support team hears most about personal data, cookies, wallet privacy and account deletion. If your question is not covered here, reach out via live chat or email and we will answer directly.

We collect your name, email address, phone number and date of birth during registration. This is the minimum needed to verify your identity and set up your account wallet. We do not ask for national ID unless a specific verification step requires it.

No. We never store your mobile wallet PIN or full credentials. Transactions are processed through secure references — we hold only the transaction ID, amount and timestamp so your deposit and withdrawal history remains accurate inside your account.

Contact our support team via live chat or email and ask for a data access request. We will verify your identity through your registered phone number, then compile and deliver a readable copy of all personal data we hold on your account.

Yes. Submit a deletion request through live chat or email. We verify your identity first, confirm there are no pending transactions, then permanently remove your personal data. Some transaction records may be retained where legally required in your region.

We do not sell or share your personal data with advertisers or marketing companies. Data is shared only with payment processors for completing your bKash, Nagad or Rocket transactions, and with security partners for fraud prevention — nothing else.

We use session cookies to keep you logged in and analytics cookies to understand how pages are used. No third-party advertising trackers run here. You can block or clear cookies from your browser settings at any time without losing your account.

Active account transaction records stay available as long as your account is open. After account closure, we retain records only for the period required under applicable local regulations, then permanently delete them from our systems.

We check the device fingerprint and IP range against your usual patterns. If something looks unfamiliar, we trigger a verification step sent to your registered phone number before granting access — so even a leaked password alone is not enough.

Yes. Availability and data-processing rules depend on your local law and eligible regions. If regulations in your jurisdiction impose stricter requirements on how we handle data, those restrictions apply to your account automatically without you needing to request it.

Head to your account settings on mobile or desktop. You can update your email, phone number and communication preferences directly. Marketing messages can be toggled off from the notifications section, and the change applies immediately — no support ticket needed.