Reference

Browse Our Privacy Commitments

We wrote this policy so you know exactly what happens with your information from the moment you open an account through braja.

Data Collection ClarityPayment Info HandlingAccount Security PracticesCookie TransparencyDeletion Rights
braja Browse Our Privacy Commitments
DATA HANDLING DETAIL

Check How We Protect and Process Data

We break our privacy practices into clear areas so you can find exactly what concerns you. Each item below addresses a specific part of how your information moves through braja — from the cookies on your device to the retention schedule governing old records.

Cookies and Tracking

We use session cookies to keep you logged in and analytics cookies to understand which lobby sections load slowly. You can clear or block cookies through your browser settings — doing so may log you out but will not delete your account data on our servers.

Account Security Layers

Your login is protected by OTP verification sent to the mobile number on file. If you access from a new device, we trigger an additional confirmation step. Password resets also require OTP confirmation before any credential change takes effect.

Payment Data Isolation

When you deposit via bKash, Nagad, or Rocket, we store the transaction reference and amount but never your wallet PIN or full mobile money credentials. Payment processors handle the sensitive authentication — we receive only a success or failure confirmation.

Data Retention Schedule

Active account data stays on our systems while you use the platform. If your account is inactive for a prolonged period, we notify you before archiving. After archiving, records are held only as long as regulations in your eligible region require, then permanently deleted.

Third-Party Sharing Limits

We share data only with entities directly involved in delivering the service to you: payment gateways, identity verification partners, and fraud monitoring systems. No advertising networks receive personally identifiable information from us without your explicit consent.

Your Rights and Requests

You can request a full export of your data, ask us to correct inaccuracies, or demand deletion of your account and records. Submit these through live chat, email, or the account settings panel. We aim to process requests promptly and confirm completion to you directly.

PRIVACY CONTACT PATHS

Open a Channel for Privacy Queries

If you have questions about how your data is used or want to make a formal request — access, correction, or deletion — reach us through these channels. Our support team handles privacy-related queries with the same priority as account issues, so you will not sit in a general queue waiting for a specialist.

Live Chat Head to the chat widget inside your account dashboard. Mention that your query is privacy-related and the agent will route it to the data team. Responses come back in the same chat window so you have a written record of everything discussed.
Email Support Send your request to our dedicated support email. Include the mobile number linked to your account and describe what data action you need. We respond to privacy emails and confirm receipt so you know it has landed with the correct team.
Account Settings Panel Inside your profile, the data section lets you download a copy of the information we hold. You can also toggle marketing communications off or request account closure directly from that screen without contacting an agent.

Switch to Common Privacy Questions

Below are the questions we hear most about data handling. Each answer stays specific to how braja processes information — if your question is not covered here, reach out through any of the contact paths listed above.

We collect your name, email, mobile number, and the payment method you link — whether that is bKash, Nagad, or Rocket. Device type and IP address are recorded automatically during each session to support security checks and improve platform performance on your specific device.

We store only the transaction reference and the amount processed. Your wallet PIN and full mobile money login are never saved on our systems. The payment provider handles all sensitive authentication steps, and we receive a confirmation status only after you approve the transfer.

Yes. Go to the data section inside your account settings and request an export. The file includes your profile details, transaction history, and communication logs. It is delivered in a standard format you can open on any device or share with a third party if needed.

You can submit a deletion request through live chat, email, or the account settings panel. Once confirmed, we remove your profile and anonymise transaction records. Any data required by regional regulation is retained only for the mandatory period before permanent deletion.

No. We do not sell or share personally identifiable data with advertising networks. Marketing communications from us can be toggled off in your account settings. Third-party access is limited strictly to payment processors and fraud-prevention partners involved in delivering the service.

We use session cookies that keep you logged in and analytics cookies that help us find slow-loading pages. You can block or clear cookies in your browser settings at any time. Blocking them may end your active session, but your stored account data remains unaffected on our servers.

After account closure, we retain records only for the period required by applicable regulations in your eligible region. Once that window expires, data is permanently deleted or fully anonymised. We notify you when the retention period begins so you have visibility over the timeline.

When you request a withdrawal, we match the registered mobile number and name against the linked bKash, Nagad, or Rocket account. An OTP is sent to your phone for confirmation. This step prevents unauthorised access and ensures funds reach the correct wallet every time.

No. Access is role-restricted. Support agents see only the information relevant to resolving your query, and payment staff access only transaction records. System administrators operate under audit logs that record every data access event for internal accountability.

We notify you through the email on file and display a notice inside your account dashboard. Changes take effect after a notice period, giving you time to review. If you disagree with an update, you can request account closure and data deletion before the new terms apply.