Reference

Browse Our Legal Framework Before You Open Your Account

We publish our legal position so you can read it before you fund anything. Access to glion depends on your local law and eligible regions — we spell out what applies to your account, your data, and how bKash, Nagad, or Rocket transactions are…

Account Data RightsbKash & Nagad ProcessingRegional Eligibility NoticeCookie & Retention PolicyDispute Channels
glion Browse Our Legal Framework Before You Open Your Account
HOW WE PROTECT YOUR DATA

Check How We Handle Security and Retention

We take a layered approach to protecting your account information and payment data. Below are the key practices that shape how your data moves through glion — from the moment you enter your bKash PIN to the point where old records are purged. Each practice is designed around the mobile-wallet reality of Bangladesh, not imported from a generic template.

Encryption Standards

All data in transit between your device and our servers travels through encrypted channels. Wallet references and personal identifiers are encrypted at rest too, meaning even internal access requires decryption keys held separately from production databases.

Cookie Management

We use session cookies for login state and preference cookies for language and layout. No advertising tracker is loaded without your consent. You can clear or block cookies through your mobile browser settings at any time without losing account access.

Account Security Layers

Your account is protected by OTP verification sent to your registered mobile number each time you log in from a new device. If three consecutive failed attempts occur, the account locks temporarily and you receive an SMS alert immediately.

Data Retention Period

We retain transaction records and personal data for as long as your account is active plus a wind-down period required by applicable rules. After that window, records are permanently deleted from our systems unless a legal hold applies.

Who to Contact for Changes

You can request correction of personal details, export of your stored data, or full deletion of your account profile. Direct these requests to the policy team through live chat or email — we act on verified requests and confirm completion to you.

Third-Party Data Sharing

We share data only with payment processors (bKash, Nagad, Rocket) to complete your transactions, and with infrastructure providers who host our servers under strict contractual obligations. No data is sold or passed to unrelated marketing parties.

REACH OUR POLICY TEAM

Open a Conversation About Any Legal Query

If you have a question about how your data is used, need to dispute a transaction, or want to understand regional eligibility, reach out through any of the channels below. Our policy team handles legal-related requests separately from general account help, so your query goes to the right desk.

Team online

Live Chat

Tap the chat icon inside your account dashboard. Legal queries are flagged and routed to the policy team, so you get a response from someone who handles data and compliance matters rather than general lobby support.

Email Channel

Send your legal query to our support email with the subject line including your account ID. We respond to data requests and dispute escalations within a reasonable timeframe, and you receive a confirmation that your message reached the policy queue.

Mobile Contact

Call or message via the number listed in your account settings. This channel works for urgent matters like account restriction notices or wallet-payment disputes where you need a same-day acknowledgement from the team.

Browse Answers to Common Policy and Data Queries

These are the questions our policy team receives most often from account holders in Bangladesh. Each answer is kept concise but covers the practical steps you can take.

We collect your name, mobile number, email, and the wallet reference used for your first deposit via bKash, Nagad, or Rocket. This data is used strictly for identity verification, transaction processing, and account communication.

Yes. Send a data-export request through live chat or email with your account ID. Once we verify your identity through OTP, we compile your records and deliver them in a standard file format within a reasonable processing window.

Contact the policy team via email or live chat and request full deletion. After OTP verification, we remove personal identifiers and transaction history from active systems. Residual backups are purged according to our retention schedule.

Yes. Access depends on your local law and eligible regions. We do not operate in jurisdictions where online account-based platforms are expressly prohibited. If your region's status changes, we notify you at the mobile number or email on file.

If a restriction is applied before your deposit clears into gameplay balance, the funds are returned to the originating wallet. If the deposit already cleared, remaining balance is processed for withdrawal back to your registered wallet after verification.

Session cookies maintain your login state. Preference cookies remember language and layout choices. We do not load advertising trackers without consent. You manage all cookie settings through your mobile or desktop browser preferences.

Reach the policy team through live chat, email, or phone. Describe the concern and include your account ID. We open an internal review and respond with findings and any corrective steps taken within a defined timeframe.

Only with payment processors — bKash, Nagad, Rocket — to complete transactions and with hosting providers under strict data-processing agreements. We never sell personal data or share it with unrelated marketing entities.

OTP verification is required for new-device logins. After three failed attempts the account locks and an SMS alert is sent to your registered number. All sessions are encrypted and inactive sessions expire automatically.

We retain records for the duration required by applicable regulations after account closure. Once that period ends, all personal identifiers and transaction logs are permanently removed from active databases and backup archives.