Reference

How mpalace Handles Your Personal Information

We collect only what we need to run your account, process payments through bKash, Nagad or Rocket, and keep your wallet secure.

Account Data ProtectionPayment Info HandlingYour Rights ExplainedCookie PracticesContact Paths
mpalace How mpalace Handles Your Personal Information
PRIVACY CONTACT PATHS

Reach Us About Your Data Concerns

If you have a question about how your information is stored, shared or deleted, we have several ways to connect. Our support channels handle privacy queries alongside general account help, and you can specify that your message relates to data handling so it reaches the right team quickly. We respond to privacy-related messages as a priority within our normal support queue.

Live Chat Open the chat widget from any page on our site. Let the agent know your query is about personal data or privacy, and they will route it to the data team. Available around the clock from your mobile or desktop browser.
Email Request Send a written privacy request to our support email. Include your registered phone number and a brief description of what you need — data summary, correction or deletion. We acknowledge receipt and follow up with next steps.
Account Settings Log in and head to your profile section. From there you can update personal details directly, toggle marketing preferences, and submit a formal data request through the built-in form without needing to open a separate chat.
DATA HANDLING PRACTICES

How We Protect and Manage Your Information

We treat your account data the same way we treat your balance — it belongs to you, and our job is to keep it safe while you use the platform. Below are the specific practices we follow across data storage, cookies, retention and access control. These apply whether you deposit through bKash, Nagad or Rocket, and whether you access us from a mobile browser or desktop.

Encryption at Rest

Your personal details and transaction history are stored using encryption protocols. Even if storage hardware were physically accessed, the data remains unreadable without our decryption keys, which are managed separately from database servers.

Cookie Usage

We use session cookies to keep you logged in and analytics cookies to understand how pages perform. No cookie stores your bKash PIN, Nagad credentials or wallet balance. You can clear cookies from your browser settings at any time without losing account data.

Account Security Layers

Each login attempt checks your device fingerprint against known patterns. If something looks unfamiliar — a new phone model or unusual IP — we send a verification step to your registered number before granting access to your wallet.

Data Retention Period

Active account data stays on our systems while you use the platform. If you close your account, we retain records only as long as local regulatory requirements demand, then permanently delete them from both primary and backup storage.

Third-Party Sharing Limits

Payment processors like bKash, Nagad or Rocket receive only the transaction amount and your wallet reference — never your full profile. We do not share browsing history, game preferences or support conversations with any external party.

How to Request Changes

You can ask us to correct, export or delete your personal data at any time. Log in, open your profile, and use the data request form — or contact live chat with your registered phone number. We process valid requests within a reasonable timeframe.

Common Questions About Your Data Rights

These are the privacy-related questions our support team receives most often. If your specific concern is not covered here, reach out through live chat or the data request form in your account settings. Answers below reflect our current practices and may be updated as regulations in eligible regions evolve.

We collect your full name, phone number, email address and date of birth. These verify your identity and link your bKash, Nagad or Rocket wallet to your account so deposits and withdrawals process without manual matching.

No. Payment authentication happens entirely within your bKash, Nagad or Rocket app. We receive a transaction confirmation from the provider but never see or store your PIN, password or wallet login details on our servers.

Yes. Log into your account, open the profile section and submit a data export request. We compile a summary of your stored personal details and transaction history, then deliver it to your registered email within a reasonable timeframe.

Open live chat or use the data request form in your profile settings. Specify that you want deletion. We honour the request where local law permits, though we may retain certain records if regulatory obligations in your region require it.

Only the payment processor handling your specific transaction receives limited data — your wallet reference and the amount. We do not sell, rent or share your profile, game history or support conversations with advertisers or unrelated third parties.

We use session cookies for login persistence and analytics cookies to track page performance. Neither type stores financial credentials. You can block or clear cookies through your browser settings — this will not erase your account data, only end your active session.

After account closure we retain records only for the period local regulations require. Once that obligation expires, your personal information is permanently removed from both primary databases and encrypted backups.

We encrypt stored data, separate decryption keys from databases, and verify each login against your known device fingerprint. Unfamiliar access attempts trigger a verification step sent to your registered phone number before the session can proceed.

We update this policy when our practices or regional requirements change. Updates are posted on this page with a revised date. For significant changes that affect your rights, we also send a notification to your registered email address.

Yes. Your specific rights — including data deletion, portability and correction — depend on local law and eligible regions. We apply the strongest applicable standard to your account based on where you access the platform from.