Reference

How gf66 Handles Your Personal Information

When you open an account with us, we collect only what we need to run your wallet, process bKash, Nagad, and Rocket transactions, and keep your account secure.

Account data protectionbKash, Nagad, Rocket transaction privacyYour right to access your dataClear data retention rules
gf66 How gf66 Handles Your Personal Information
HOW WE PROTECT IT

Data Handling, Cookies and Account Security

We apply multiple layers of protection to the information tied to your account. Cookies on our site are used for session management and to remember your login state; they are not used to build advertising profiles or share data with ad networks. You can clear cookies from your mobile browser at any time without losing your account. Our account security uses an OTP step during login from a new device, which means a one-time code is sent to your registered contact before access is granted. Data we are no longer required to retain is deleted on a rolling schedule.

Tokenised Payments

Every bKash, Nagad, and Rocket transaction is tokenised after confirmation. We never store raw wallet credentials or PIN details on our platform at any point.

Cookie Control

Session cookies keep you logged in on mobile. No third-party advertising cookies are placed. Clear them from your browser settings without affecting your account data.

OTP Account Access

Logging in from a new device triggers an OTP sent to your registered contact. This step prevents unauthorised access even if your password is compromised.

Retention Schedule

We keep data only as long as required to operate your account or meet legal obligations. When the retention period ends, records are deleted from our active systems.

PRIVACY CONTACT PATHS

Reach Us About Your Data

If you have a question about your personal data — what we hold, how long we keep it, or how to request a change — our support team handles privacy requests directly. Send your account details and your specific request through the channel that suits you, and we will respond as quickly as we can. All privacy queries are logged and tracked until they are resolved.

Team online

Live Chat

Open the live chat window inside your account dashboard to submit a privacy query. Our team picks up chat requests and responds with your account reference.

Email Support

Send a written data request to our support email address listed in your account settings. Include your registered contact detail so we can verify it is your account.

Account Help Centre

Log in, go to Account Settings, and use the Help Centre form to raise a data or privacy issue. Requests submitted there are tracked with a case number.

Common Questions About Your Privacy at gf66

Here are the questions we hear most often about how we manage your data. If your question is not covered, use the live chat or Help Centre form in your account settings to raise it directly with our support team.

We collect your name, contact detail, and payment method information — such as your bKash or Nagad registered number — plus device and session data needed to secure your account.

Wallet references are tokenised after each transaction is confirmed. Raw wallet numbers or PINs are never stored in plain text on our platform or servers at any time.

Yes. Submit a data access request through the Help Centre form in your account settings or by email. We will confirm what we hold and provide it in a readable format.

Send a deletion request via live chat or email with your account reference. We will remove data where no legal obligation requires us to keep it, subject to applicable local law.

We do not sell your data. We share it only to process your payment through a wallet provider like Rocket or Nagad, or where required by law in eligible regions.

We keep records for as long as needed to operate your account and meet any legal retention obligations. Once the retention period ends, data is deleted from our active systems.
Reference

Privacy Policy

Service availability depends on eligible regions and local law. Users should check local rules before opening an account.

Access may be available only where local law permits.