Reference

Legal Framework at xnova

We set out our legal position clearly so you know exactly where you stand when you hold an account with us.

Account Holder RightsData TransparencyEligibility by RegionLocal Payment ContextPolicy Contact Path
xnova Legal Framework at xnova
DATA AND ACCOUNT HANDLING

How We Protect and Manage Your Information

We built our data practices around a simple principle: collect only what the account needs to function, protect it properly, and give you control over it. Here is how that breaks down across six areas that matter most when you hold an active account with us and transact through local mobile wallets.

Data We Collect We store your registration details, transaction records from bKash, Nagad, or Rocket payments, device fingerprints used for login verification, and your communication preferences. Nothing beyond what keeps your account secure and functional.
Cookie Usage Our site uses cookies for session management, remembering your login state, and understanding which lobby sections you visit most. We do not sell cookie data to third parties. You can clear them from your browser at any time without losing account access.
Account Security Layers Every login triggers a device check against your registered fingerprint. If we detect an unfamiliar device or location, we send an OTP to your registered phone number before granting access. Password resets also require phone verification.
Data Retention Period We retain your account data for as long as your account is active plus a wind-down period after closure to satisfy any outstanding transaction queries. After that window, personal identifiers are anonymised in our records.
Who to Contact For any data-related request — access, correction, deletion, or portability — reach our support team via live chat or the structured request form in your account settings. We acknowledge every request and provide a reference number.
How to Request Changes Submit a change request through your account help section. Specify whether you want data corrected, exported, or deleted. We process requests in the order received and confirm completion through the email linked to your account.
LEGAL SUPPORT PATHS

How to Reach Us About Legal Matters

If you have a legal query — whether it involves your data, your account status, or how regional eligibility affects you — we keep several contact paths open. Each route is staffed by people who understand the policy side, not just the technical side. Raise a question and expect a human response, not an automated loop.

Live Chat Open a live chat session directly from your account dashboard. Legal queries get routed to a policy-aware agent who can confirm what data we hold, explain terms changes, or escalate a formal request on your behalf.
Email Channel Send a written request via our support email for anything that needs a documented trail — data access requests, account closure confirmations, or dispute records. We respond with a reference number so you can track progress.
Account Help Section Inside your account settings you will find a dedicated help section where you can submit structured legal requests: data export, consent withdrawal, or eligibility queries. Each submission logs a timestamp for your records.

Common Legal and Policy Questions

These are the questions our support team handles most often around legal rights, data handling, and eligibility. Each answer reflects our current policy — if something changes, we update this section and flag it in your account notifications.

We store your name, email, phone number, device identifiers, and transaction history from bKash, Nagad, or Rocket deposits and withdrawals. We do not collect unnecessary personal information beyond what account security and payment processing require.

Yes. Submit a data access request through the help section inside your account settings. We compile a summary of your stored information — registration details, transaction logs, device records — and deliver it to your registered email with a reference number.

Open a deletion request through your account help section or via live chat. Once confirmed, we close your account and begin the data anonymisation process after any outstanding transactions are settled. You receive a confirmation email when complete.

It does. Access depends on your local law and the regions we currently serve. We do not claim availability everywhere — if your jurisdiction restricts the services we offer, your account access may be limited or unavailable. We notify you if your status changes.

Transaction details from your mobile wallet pass through our system for processing and record-keeping. We store transaction IDs, amounts, and timestamps. We do not store your wallet PIN or full wallet credentials — those remain with your payment provider.

When we update terms, we display the changes inside your account dashboard before they take effect. Your existing data is handled under the terms you agreed to at the time of collection unless the new terms specifically address retention or processing changes.

You can withdraw consent for non-essential processing — like marketing communications — at any time through your account settings. Core processing tied to account function and transaction records cannot be withdrawn while your account remains active.

We retain identifiable data for a defined wind-down period after account closure to address any pending transaction queries or disputes. Once that period ends, personal identifiers in your records are anonymised and cannot be linked back to you.

Reach our support team via live chat or email. Describe your concern and we will open a formal review under our internal data handling procedures. You receive a reference number and a response within the timeframe stated in your acknowledgment message.

We share data only where necessary for payment processing — with bKash, Nagad, or Rocket as applicable — and where required by legal obligation in the jurisdictions we operate in. We do not sell personal data to advertisers or unrelated third parties.