Reference

Check How xsona Handles Legal and Data Policies

We keep our legal framework straightforward so you know exactly where you stand. Access to xsona depends on your local law and eligible regions — our policies cover data use, account security, payment processing via bKash, Nagad, and Rocket, and how we handle your…

Region-Dependent AccessData Protection PracticesbKash, Nagad, Rocket PoliciesAccount Security TermsDispute Resolution Paths
xsona Check How xsona Handles Legal and Data Policies
POLICY CONTACT PATHS

Open a Policy Query Through These Channels

If you have a question about our legal terms, data handling, or account restrictions, reach us through any of the channels below. We handle policy-related queries with priority because they often involve account access or payment disputes. Provide your registered account details when you write so we can locate your records without delay.

Team online

Live Chat

Reach our policy support team through the live chat widget on any page. Describe your legal query or data request clearly, include your account username, and a team member will guide you through the relevant policy steps within the same conversation.

Email Support

Send policy or data queries to our support email. Include your registered account name and a clear description of what you need — account data export, deletion request, or dispute escalation. We respond to legal-category emails ahead of general queries.

Callback Request

Submit a callback form through your account settings if you prefer a voice conversation. Specify that your query relates to legal terms or data rights, and a team member familiar with those policies will contact you at the time slot you choose.

DATA AND SECURITY HANDLING

Explore How We Protect Your Account and Data

We handle personal data with care and keep our security practices visible so you can verify how your information is stored, used, and protected. Each area below explains a concrete part of our data and account security approach — from cookies to deletion rights. If anything is unclear, raise it through our policy contact paths above.

Data Collection Scope We collect only what your account requires: name, contact method, payment wallet identifier, and transaction history. We do not harvest device data beyond what is needed to deliver pages correctly on your phone or browser. Collection stops when you close your account.
Cookie Usage Our site uses cookies to maintain your login session and remember display preferences. We do not sell cookie data to third parties. You can clear cookies from your device at any time — this will log you out but will not affect your account balance or history.
Account Security Layers Your account is protected by a PIN you set during registration and an OTP sent to your registered mobile number for sensitive actions like withdrawal or password changes. We never ask for your PIN through chat or email — any such request is not from us.
Data Retention Period We retain your account and transaction data for the period required by applicable regulations in the regions where we operate. Once that period expires and your account is closed, we schedule data for permanent deletion within a defined cycle communicated in your closure confirmation.
Your Data Rights You can request a full export of your personal data, ask for correction of inaccurate details, or request deletion of your account and associated records. Submit these requests through our email or live chat policy channel — we process them within the timeframe stated in our privacy terms.
Who to Contact for Changes For any policy concern — access restriction, data correction, account dispute, or deletion — direct your request to our policy support channels. Include your account username, the specific right you are exercising, and any supporting detail so we can act without repeated back-and-forth.

Switch to Common Legal and Data Questions

Below are questions we receive from account holders about legal access, data rights, payment policies, and dispute steps. Each answer addresses the specific policy area — if your situation is not covered here, reach out through our support channels with your account details.

Yes. Access depends on your local law and eligible regions. When you create an account, you confirm that using the platform is permitted where you reside. We do not verify local legislation on your behalf — that responsibility is yours before you register.

We collect your name, mobile number or email, and the wallet identifier you use for bKash, Nagad, or Rocket deposits. Transaction records are stored against your account. We do not collect unnecessary device information beyond what is required to display pages correctly.

Send a data export request through our live chat or email support channel. Include your account username and state that you want a full data export. We compile and deliver the file within the timeframe described in our privacy terms, to your registered contact method.

You can request full account deletion at any time by contacting our policy support team. After verifying your identity through the OTP process, we close the account and schedule all associated data for permanent deletion once any regulatory retention period ends.

Raise a dispute through live chat or email, providing transaction details and your account username. We investigate the matter internally first. If our resolution does not satisfy you, the escalation path described in our full terms document applies — we outline next steps clearly in our response.

We notify you through your registered contact method and explain the steps for withdrawing any remaining balance. You are given a reasonable window to move funds back to your bKash, Nagad, or Rocket wallet before the account is restricted from further activity.

We do not sell your personal data. We share information only where required for payment processing through bKash, Nagad, or Rocket settlement systems, or where a legal obligation in an applicable jurisdiction compels disclosure. No marketing data is sold.

We notify active account holders through their registered contact method when material policy changes occur. A summary of what changed and the effective date is included. Continued use after the update date means you accept the revised terms.

Your account uses a PIN set during registration plus OTP verification for sensitive actions like withdrawals or password resets. We never request your PIN through chat or email. If you suspect unauthorised access, contact support immediately and we lock the account while investigating.

You must meet the minimum age requirement applicable in your region to hold an account. During registration or before your first withdrawal, we may ask for identity verification through a document upload step. Details of acceptable documents are shown in your account settings.