Reference

Check How We Handle Your Account and Data

We keep this page straightforward so you know exactly where you stand when you hold a cstar account. Your data, your wallet activity through bKash, Nagad or Rocket, your login history — all of it falls under policies we explain here.

Account data protectionWallet activity recordsEligibility by regionContact paths for requestsCookie and session handling
cstar Check How We Handle Your Account and Data
DATA AND ACCOUNT SECURITY

Explore How We Protect What Belongs to You

We handle your information with specific safeguards at every layer — from login to payment processing to long-term storage. Here is what that looks like in practice for anyone holding a cstar account and using bKash, Nagad or Rocket for transactions.

Encryption in Transit

Every connection between your device and our servers uses TLS encryption. Whether you are logging in from your phone browser or completing a Nagad transfer, the data moving between you and us cannot be read by anyone intercepting the connection. We enforce modern cipher suites and reject outdated protocols.

Cookie and Session Policy

We use cookies to maintain your login session and remember device preferences. No tracking cookies are shared with advertisers. Session tokens expire after inactivity, so if you leave your phone unlocked someone cannot resume your session hours later without re-authenticating through your PIN or OTP.

Account Verification

Before processing your first withdrawal via bKash, Rocket or bank transfer, we verify your identity. This means matching the name on your account to the wallet or bank account you withdraw to. It adds a step, but it stops someone else from draining your balance if your login is compromised.

Data Retention Rules

Transaction records are kept for the period required by applicable financial regulation. Once that window closes, records are either anonymised for aggregate reporting or permanently deleted. You can request early deletion of non-regulatory data through the contact paths on this page.

Access Logs

We log every login attempt, device change and major account action. You can view your own access history inside account settings. If you spot a login you do not recognise, flag it through live chat and we lock the account while we investigate — no questions asked until it is resolved.

Change Requests

You have the right to ask us to correct inaccurate personal data, update your contact details, or request a full copy of what we hold. Submit through the in-app form or email. We process corrections within a few business days and confirm once applied. Deletion requests follow the retention rules above.

POLICY CONTACT PATHS

Open a Channel When You Have Legal Questions

If something about our legal terms needs clarification, or you want to exercise a data right, reach us through the paths below. We handle legal and policy queries separately from general account support so your request reaches the right team quickly.

Live Chat Use the chat widget inside your account dashboard to raise a legal or data query. Tag your message as a policy request and the system routes it to the compliance queue rather than general support.
Email Send your request to the address listed in your account settings under the legal section. Include your account ID and a clear description of what you need — data copy, correction, deletion or a policy question.
In-App Request Form On mobile, open the menu, tap the legal section, and use the structured request form. It walks you through selecting the type of request — data access, rectification, erasure or general legal query — so nothing gets lost.

Switch to Answers on Common Policy Questions

Real questions from account holders about how our legal framework affects them. If yours is not here, use the contact paths above.

Yes. Access depends entirely on the laws applicable in your region. If your jurisdiction restricts or prohibits online platforms of this kind, you should not create or use an account. We do not override local regulation, and accounts found in prohibited regions may be closed.

We collect your name, contact details, date of birth and device information at registration. When you add a payment method like bKash or Nagad, we store the wallet identifier linked to your account. We do not store full payment credentials on our servers.

You can. Use the in-app request form or send an email to our policy team with your account ID. We compile the data package and deliver it to your registered email in a standard format. Turnaround depends on data volume but we aim to respond promptly.

Submit a deletion request through live chat or the in-app form. We erase all non-regulatory data. Transaction records required by financial regulation stay until their mandatory retention period ends, then they are removed. We confirm once deletion is complete.

We do not sell your data. We share information only where required: with payment processors like bKash, Nagad or Rocket to complete your transactions, and with authorities if served a lawful request. Marketing data is never passed to external advertisers.

If you relocate to a jurisdiction where access is not permitted, you should contact support to close your account and withdraw any remaining balance. Continuing to use the platform from a restricted region violates the terms and may result in account suspension.

Cookies maintain your login session and device preferences. We do not use advertising trackers. Session cookies expire after inactivity. You can clear cookies in your browser settings, but you will need to log in again and re-confirm your device on next visit.

Our terms are governed by the laws of the jurisdiction under which we are registered. Disputes fall under the courts of that jurisdiction unless your local consumer protection law provides additional rights. The applicable jurisdiction is stated in our full terms document.

Open the in-app form or email our policy team with the specific field you want corrected and the accurate information. We verify ownership of the account before making changes. Corrections typically apply within a few business days and you receive confirmation once done.

We store only the wallet identifier needed to process transactions — not your PIN or full credentials. That identifier is encrypted at rest and accessible only to our payment processing layer. If you change your wallet, the old identifier is purged from active records.