Reference

How We Handle Your Account Data

We collect only what's needed to run your Heybaj account — your mobile number, wallet details for bKash, Nagad or Rocket, and basic device details when you log in.

Account DataWallet RecordsCookie ControlsAccess Requests
Heybaj How We Handle Your Account Data
SECURITY IN PRACTICE

How We Protect And Store Account Data

Privacy isn't a static document for us — it's a handful of concrete habits baked into how the platform runs. Your login session is encrypted the moment you tap in from the app or a mobile browser, wallet numbers linked to bKash, Nagad or Rocket are masked in your account view, and we only keep transaction logs as long as support or verification checks might need them. If you want a setting changed, use the request line below and we'll walk you through it.

Data Handling

We store account and transaction details on secured servers and limit staff access to what's needed for support, verification and fraud checks — nothing more, nothing browsed for curiosity.

Cookies And Sessions

Cookies keep you logged in across a session and remember basic preferences like language; they don't track your activity across other unrelated sites once you close the tab.

Account Security Checks

Every login pairs your mobile number with device signals we already recognise; an unfamiliar device may trigger a one-time code before the wallet or profile page opens.

Retention And Change Requests

We keep records only as long as a support case, dispute or verification step might reasonably need them, and you can ask us to update or remove what's no longer required.

REACH OUR TEAM

Ask Us About Your Data

Got a question about something in your account that doesn't look right? Our support channels handle both everyday account issues and privacy-specific requests — you don't need a separate process for one or the other. Whether you reach us through the in-app chat, email, or the request form under settings, we ask for basic verification first, your registered mobile number or the wallet used to fund your account, before we share or change any stored data, so no one else can pull your details by pretending to be you.

Live Chat In Your Account Open the chat icon inside your Heybaj account and ask about any data point tied to your profile — a support agent can walk you through what's stored and how to change it.
Email Our Privacy Desk Write to privacy@Heybaj from the email or number linked to your account so we can confirm it's you before we act on a data or deletion request.
In-Account Request Form Use the request form under Account Settings to ask for a copy of your data, a correction, or removal of details we no longer need for verification.

Privacy Policy Questions You May Have

Here are the questions we get most often about how Heybaj handles your account data, your wallet details, and your rights around what's stored on file.

We collect your mobile number, the wallet details you use for bKash, Nagad or Rocket, device details, and basic login data like your IP address, mainly to verify you and process payments correctly.

We only pass wallet or transaction details to the payment provider needed to complete that deposit or withdrawal and to fraud-checking partners; we don't sell your data to advertisers.

Yes — send a request through the in-account form under Account Settings or email our privacy desk, and once we confirm it's really you, we'll share what's on file.

We hold transaction and login records only as long as needed for support cases, disputes or verification, then remove data that's no longer required for those purposes.

No — your account data and privacy preferences carry over whether you log in through the app or a mobile browser, since both connect to the same account profile.

Reach out through the request form in Account Settings or email privacy@Heybaj from your registered contact details, and we'll guide you through correction or removal depending on local law and eligible regions.
Reference

Privacy Policy

Service availability depends on eligible regions and local law. Users should check local rules before opening an account.

Access may be available only where local law permits.