Reference

Explore How superrich Protects Your Privacy

We built our privacy practices around the same principle as our payment flow — keep it direct, keep it clear, keep you in control.

Encrypted TransfersAccount ControlData TransparencyWallet PrivacySession Security
superrich Explore How superrich Protects Your Privacy
SIX PRIVACY FEATURES

Explore Six Elements Defining Our Privacy

These six visible features shape how your data experience feels across the platform — from login through to withdrawal confirmation.

OTP Verification Layer Every login and sensitive action triggers a one-time code sent to your registered number. This blocks unauthorised access even if someone knows your password. The code expires quickly, and failed attempts lock the action temporarily for your protection.
Encrypted Wallet Connections When you link bKash, Nagad, or Rocket to your account, the reference is encrypted both in transit and at rest. We never display your full wallet number in the interface — only a masked version — so screen-sharing or screenshots do not expose your payment details.
Activity Log Visibility Check your own login history and recent actions from account settings. If you spot a session you do not recognise — unfamiliar device, odd time — flag it immediately. This self-service visibility means you catch potential issues before we even need to intervene.
Consent-Based Communication We only send messages you opted into. Promotional notifications require your explicit consent, and you can revoke it anytime from settings. Transactional messages — deposit confirmations, OTP codes — are functional, not marketing. We respect the boundary between necessary and optional.
Anonymised Analytics When we analyse platform usage patterns to improve the experience, data is aggregated and anonymised. Your individual behaviour is not tied to your identity in our analytics pipeline. We see trends across thousands of sessions, not what you personally did last Tuesday.
Secure Account Closure Decide to leave and we make closing clean. Personal identifiers are removed from active systems. Outstanding balances follow our withdrawal process via your chosen payment method. Once complete, your data footprint on superrich shrinks to only what retention law requires.
PRIVACY HELP PATHS

Open a Privacy Query Anytime

If something about your data feels wrong — an unfamiliar login location, a payment you did not initiate, or a question about what we store — reach us through these channels.

Live Chat Privacy Requests Use the live chat widget to flag a privacy concern. Agents can freeze suspicious activity on your account within the same conversation, then escalate to our data team if you need a full audit of recent access events tied to…
Email Data Requests Send a data export or deletion request via email. We acknowledge within one business day and process the request according to our stated timeline.
Account Security Lockdown If you suspect someone accessed your account without permission, request an immediate lockdown through support. We disable login, freeze pending withdrawals, and require fresh OTP verification before restoring access. This keeps your Nagad or Rocket-linked wallet safe while we investigate.
superrich Browse Our Full Privacy Approach

Browse Our Full Privacy Approach

When you open an account with us, we collect only what we need to verify your identity and process your deposits and withdrawals through bKash, Nagad, or Rocket. We do not sell your information to third parties, and we do not share wallet transaction details outside of what is required to complete your payment. Your login credentials are hashed — we cannot

read your password even internally. Session tokens expire after periods of inactivity, and every API call between your device and our servers runs through SSL encryption. If you access superrich from a mobile browser, the same protections apply as on desktop. We store minimal personal data: your phone number or email for verification, your chosen payment method reference, and your account activity

logs. Those logs help us detect unauthorised access attempts on your behalf. You can request a copy of your stored data or ask us to delete your account entirely through our support channels. Availability of services depends on your local law and eligible regions.

PRIVACY ON MOBILE

Switch Devices Without Losing Protection

Privacy does not weaken when you move from desktop to your Android browser. Your session inherits the same encryption, the same token expiry, and the same internal access rules regardless of screen size. If you log in on mobile using your bKash-linked number, authentication still runs through our OTP verification flow — no shortcuts, no stored plain-text tokens on your device. Returning users get the same encrypted handshake every single time. We do not cache sensitive data locally on your phone, so even if you lose the device, your account stays locked behind your credentials and OTP step.

OTP on Every Login
No Local Data Cache
Same SSL on Mobile
Session Auto-Expire
superrich mobile gaming
DATA INTEGRITY SIGNALS

Discover How We Verify Our Privacy Standards

We do not ask you to take our word for it. These are the operational practices that keep your data handled properly across our platform.

SSL Across All Pages

Every page on superrich — lobby, account settings, deposit flow, withdrawal confirmation — runs SSL. There is no unencrypted version of the site. Your browser padlock confirms this on every visit, whether you are browsing slots or updating your Rocket payment reference.

Hashed Credentials

Passwords are hashed using modern one-way algorithms before storage. Even if our database were accessed externally, your actual password would remain unreadable. We never store or transmit credentials in plain text, and password reset flows use time-limited OTP codes sent to your registered contact.

Payment Data Isolation

Your bKash, Nagad, or Rocket account references are stored separately from your profile data. The systems that handle deposits do not have access to your login credentials, and vice versa. This compartmentalisation means a breach in one layer does not expose everything.

Regular Access Audits

Internal access logs are reviewed periodically. Any anomalous access pattern — an employee viewing accounts outside their assigned queue, or bulk data pulls — triggers an automatic flag. We investigate every flag and take action where needed to maintain your privacy expectations.

Minimal Data Collection

We ask for only what the account and payment process requires: contact detail for OTP, payment method reference for deposits and withdrawals, and activity logs for security. We do not harvest browsing behaviour across other sites or build advertising profiles from your gameplay patterns.

Deletion on Request

Close your account and we remove personal identifiers from active systems. Transaction records may be retained where legally required, but your name, contact details, and wallet references are wiped from our operational databases. You can confirm deletion status through support at any point afterwards.

PRIVACY PILLARS

Check Out Three Core Privacy Protections

Each layer of our privacy framework addresses a different risk point — from the moment you enter your credentials to the second your withdrawal clears.

End-to-End Data Encryption
Every piece of data moving between your phone and our servers is encrypted using SSL protocols.
Internal Staff Access Limits
Our internal teams operate on a need-to-know basis. Support agents see only what they need to resolve your query — they cannot view your full payment history or stored credentials.
Your Right to Data Control
You can update, export, or delete your personal information at any point. Head to account settings to change your contact details, or reach support to request a full data export.
superrich mobile gaming
Google Play App Store

Browse Key Privacy Terms You Should Know

These definitions cover terms you will encounter throughout our privacy documentation and across your account settings.

01
What does SSL encryption mean?

SSL is a protocol that encrypts data travelling between your device and our servers. It prevents anyone sitting between you and us — on public WiFi, for instance — from reading your login details, payment references, or account activity during transmission.

02
What is a hashed password?

Hashing converts your password into a fixed-length string using a one-way algorithm. The original password cannot be recovered from the hash. When you log in, we hash your input and compare it to the stored hash — we never see or store the actual password.

03
What does OTP stand for?

OTP means one-time password. It is a short numeric code sent to your phone that expires after a brief window. We use it for login verification and sensitive account changes to confirm that the person acting is actually you, not someone with your password alone.

04
What is data minimisation?

Data minimisation means we collect only the information needed for a specific purpose. We do not ask for your full address if a phone number suffices for OTP delivery. The less data we hold, the less there is to protect — and the less exposure you face.

05
What does session expiry mean?

Session expiry automatically logs you out after a period of inactivity. This protects your account if you walk away from your phone or close a browser tab without logging out. You will need to re-authenticate with OTP when you return.

06
What is data compartmentalisation?

Compartmentalisation means storing different categories of your data in separate systems. Your bKash payment reference lives apart from your login credentials, and both live apart from your activity logs. A breach in one compartment does not automatically expose the others.

07
What does anonymised data mean?

Anonymised data has had all identifying details stripped out. When we analyse usage patterns to improve the platform, individual sessions are aggregated so no single record can be traced back to you. Your personal identity is not attached to analytics outputs.

08
What is an access audit?

An access audit reviews who internally accessed user data, when, and why. We log every instance of staff viewing account records and periodically check those logs for anomalies. This holds our own team accountable and ensures your information is only viewed for legitimate reasons.

09
What does consent-based communication mean?

It means we only contact you in ways you have agreed to. Promotional messages require your opt-in. You can withdraw consent from account settings at any time without affecting your access to the platform or your ability to deposit and withdraw through Nagad or Rocket.

10
What is a data export request?

A data export request asks us to provide you with a copy of all personal information we hold about you. We compile it into a structured format and deliver it through a secure channel. This gives you visibility into exactly what our systems store under your account.

Get Answers to Common Privacy Concerns

Real questions from real account holders about how their data is handled on superrich.

We collect your phone number or email for OTP verification, a payment method reference for bKash, Nagad, or Rocket transactions, and basic profile details you provide during registration. We do not ask for documents unless withdrawal verification requires it under applicable rules.

No. We do not sell, rent, or pass your personal information to advertisers or third-party marketing platforms. Data is shared only with payment processors to complete your transactions and with security providers to protect your account. Both operate under strict data handling agreements.

Contact our support team through live chat or email and request account closure with data deletion. We verify your identity through OTP, then remove personal identifiers from active systems. Retained transaction records where legally required are kept without your personal details attached.

Yes. Head to your account settings and check the activity section. It shows recent login timestamps, device types, and approximate locations. If anything looks unfamiliar — a device you do not own or a session at an odd hour — flag it to support immediately for investigation.

Your account and data remain stored securely. We do not delete inactive accounts without notice. If an extended inactivity period triggers our dormancy policy, we will contact you at your registered number or email before taking any action on the account or its associated data.

Never. Your payment references are visible only to you in masked form within your own account settings. Other users on the platform cannot see any part of your profile, payment details, or activity. Even support agents see only a partial reference when assisting you.

The same SSL encryption applies whether you are on WiFi, 4G, or patchy mobile data. We do not cache sensitive information locally on your device. If your connection drops mid-session, no data is left exposed — the encrypted tunnel simply closes, and you re-authenticate when connectivity returns.

We use functional cookies to maintain your login session and remember your language preference. We do not use third-party advertising cookies or cross-site tracking pixels. Analytics cookies are anonymised and do not tie browsing patterns to your personal identity or account details.

Yes. Go to your account notification settings and toggle off promotional communications. You will still receive transactional messages — OTP codes, deposit confirmations, withdrawal updates — because those are functional. Marketing messages stop immediately once you revoke consent.

Yes. Availability of our services and the specific data handling practices depend on your local law and eligible regions. We comply with applicable requirements in the jurisdictions where we operate and adjust retention and disclosure practices accordingly. Check our full policy for region-specific details.