Reference

How joyaapp Handles Your Personal Information

This privacy policy covers what data we collect when you open an account, make a deposit through bKash, Nagad or Rocket, and use our lobby — and how we keep that data secure.

Account data protectedbKash, Nagad, Rocket payment data handled securelyNo third-party data salesYou can request your dataRetention limits apply
joyaapp How joyaapp Handles Your Personal Information
PRIVACY CONTACT PATHS

How to Reach Us About Your Data

If you want to request a copy of your data, ask us to delete your account records, or raise a concern about how we handle your information, our support team is the right starting point. You can reach us through the channels below. For account-specific queries, have your registered mobile number or email address ready so we can verify your identity before sharing or changing any data.

Live Chat Open the chat icon from any page in your account. Identify yourself with your registered email or mobile number to start a data request.
Email Support Send your privacy request to our support email. Include your account username and the specific action you need — access, correction or deletion.
Account Help Centre Log into your account and go to the Help section. You can submit a formal data request form directly from your account dashboard.
DATA HANDLING PRACTICES

How We Protect and Manage Your Account Data

We apply SSL encryption across every page of joyaapp — including the deposit flow when you send through bKash, Nagad or Rocket — so your session data travels encrypted from your device to our servers. Account passwords are hashed and never stored in plain text. We run periodic access reviews to make sure only authorised staff can reach account records, and we log every internal access event for audit purposes.

Cookies and Tracking

We use session cookies to keep you logged in and preference cookies to remember your lobby settings. You can clear cookies via your browser, but this will log you out and reset your display preferences.

Data Retention

We keep your account data for as long as your account is active and for a period after closure, as required by the payment processors we work with and applicable compliance obligations.

Account Security

Every login triggers an OTP sent to your registered mobile number. If you see a login you do not recognise, contact us immediately through live chat and we will lock the account while we investigate.

Your Right to Correction

If your registered name, email or mobile number is incorrect, you can request a correction through support. We will verify your identity first before updating any account detail.

Common Questions About Your Privacy on joyaapp

These questions cover what Bangladesh account holders most often ask about how we handle personal data, wallet information and account records. If your question is not here, reach us through live chat or email support.

No. We never store your wallet PIN. When you deposit via bKash, Nagad or Rocket, the PIN is entered in your wallet app directly. We only receive the transaction reference number.

Yes. Submit a data access request through live chat or email support. Verify your identity with your registered mobile number and we will compile and send your account data.

We retain account records for a period after closure to meet our payment processor obligations and internal audit requirements. The exact period depends on the type of data involved.

Only authorised joyaapp staff with a verified operational need. We share transaction data with our payment processors — bKash, Nagad, Rocket — but not with unrelated third parties or advertisers.

Contact support via live chat or email and submit a deletion request. We will verify your identity, close your account if it is still active, and remove personal data within the retention window.

How this policy applies depends on your local law and the eligible regions where joyaapp operates. Check your local regulations to confirm whether access and data rights apply to you.
Reference

Privacy Policy

Service availability depends on eligible regions and local law. Users should check local rules before opening an account.

Access may be available only where local law permits.