Reference

How We Handle Your Privacy at sunstar

We collect only the information needed to run your account, process payments through bKash, Nagad and Rocket, and keep your sessions secure.

Account Data ProtectionPayment Info HandlingCookie TransparencyYour Rights ExplainedLocal Wallet Privacy
sunstar How We Handle Your Privacy at sunstar
PRIVACY HELP CHANNELS

How to Reach Us About Your Data

If you have questions about your personal information, want to request a copy of your data or ask for deletion, our support team handles privacy-related queries through three channels. We aim to acknowledge every privacy request promptly and resolve straightforward ones within a reasonable timeframe.

Live Chat Open the chat widget from any page on our mobile site or desktop browser. Tell the agent your request relates to privacy and they will route it to the data team directly, no need to repeat your question across departments.
Email Support Send your privacy query to our support email address. Include the phone number or email linked to your account so we can locate your records without asking follow-up questions. Expect a written acknowledgment confirming we received the request.
Account Settings Inside your account dashboard you can update contact details, change your linked bKash or Nagad wallet, or download a summary of data we hold. Changes save instantly and reflect across all devices where you are logged in.
DATA HANDLING PRACTICES

How We Protect and Manage Your Information

We built our data practices around transparency and minimal collection. Below are the specific ways we handle different aspects of your personal information — from cookies to account closure. Each item describes what happens, not just a promise, so you know exactly how your data moves through our systems.

Data Collection

We collect your name, phone number, email and wallet details at registration. During use, we log device type, IP address and session timestamps. We do not record browsing activity outside the sunstar platform or track you across other sites.

Cookie Usage

Cookies remember your login session and language preference so you do not re-authenticate on every visit. We use analytics cookies to measure page performance — these contain no personal identifiers. You can clear cookies from your browser settings at any time.

Account Security

Your password is stored as a one-way hash — we cannot read it, and neither can our engineers. Two-factor verification via SMS protects logins from new devices. Failed login attempts trigger temporary locks to prevent brute-force access to your wallet.

Data Retention

Active account data stays on file while you use the platform. If you close your account, personal identifiers are purged within a defined retention window unless local regulatory requirements mandate longer storage. Transaction records may be kept in anonymised form for audit purposes.

Third-Party Sharing

We share data only with payment processors (bKash, Nagad, Rocket gateways), hosting providers and fraud-prevention partners. Each receives the minimum fields needed for their function. We never sell or rent your personal details to advertisers or data brokers.

Your Rights and Requests

You may request access to all data we hold, correction of inaccurate records, or deletion of your account. Submit requests through live chat or email. We verify your identity before acting — typically by confirming the OTP sent to your registered phone number.

Common Questions About Your Data and Privacy

These are the questions our support team receives most often about data handling. Each answer explains what we do in practice so you can decide how to manage your information. If your question is not covered here, reach out through live chat or email and we will respond directly.

We collect your full name, phone number, email address and the wallet identifier you choose for deposits (bKash, Nagad or Rocket number). We also record your device type and IP address at the time of registration to help detect unauthorised access later.

Wallet numbers and transaction references are encrypted at rest using industry-standard protocols. We do not store your bKash, Nagad or Rocket PIN — those stay entirely within your mobile wallet app. Only the minimum reference data needed to match a deposit to your account is retained.

Yes. Open live chat or email our support team with the subject line referencing a data access request. After verifying your identity through an OTP sent to your registered phone number, we compile and send a readable summary of your stored records.

Submit a deletion request via live chat or email. Once verified, we remove personal identifiers from active systems within our standard retention window. Some anonymised transaction records may remain where local regulations require us to keep audit trails.

Only with the service providers needed to operate your account — payment gateway partners for bKash, Nagad and Rocket processing, hosting infrastructure, and fraud-detection tools. Each provider is contractually limited to the minimum data required for their specific function.

We use session cookies to keep you logged in and analytics cookies to measure page load speed. Neither type stores your name or wallet number. You can disable or clear cookies through your mobile browser settings, though this will log you out of active sessions.

Passwords are hashed so no one — including our team — can read them. Logins from new devices trigger SMS-based verification to your registered number. Repeated failed attempts lock the account temporarily to block brute-force attacks against your wallet.

Inactive accounts retain data for a defined period in case you return. After that window, or upon your explicit deletion request, personal identifiers are purged. Anonymised statistical records may persist for internal analytics but cannot be linked back to you.

The core data-handling practices described here apply across all access points. However, specific rights — such as deletion timelines or regulatory disclosures — depend on your local law and eligible regions. We note any jurisdiction-specific differences where relevant.

We post updates on this page with a revised effective date visible at the top. For material changes that affect how we use data already collected, we send a notification through your registered email or via in-app message so you can review before continuing.