Version 1.0

Privacy Policy

Effective 2026-09-19 · Last updated 2026-09-19

Trading as: MOSHIO'S PANNEL
Country: Bangladesh
Governing law: Bangladesh
Support: support@moshios.local
Phone: +8801000000000

1. Who we are

This policy describes how MOSHIO'S PANNEL processes personal data to operate the workspace. Legal name, address and complaint contacts appear only when configured by an administrator. If a field is blank, we have not claimed that identifier.

2. Data we actually process

Account: name, email, optional phone, country/timezone/language preferences, role, status.

Authentication: bcrypt password hashes (not the password itself), optional TOTP secret stored encrypted at rest with the application encryption key, hashed recovery codes, session token hashes, login event metadata including IP and user-agent when collected.

Orders and campaigns: service, target URL, quantity/budget, notes, objective, status, events.

Payments: method, amount, customer-submitted transaction references, verification status, and related audit events. Destination instructions are shown after sign-in.

Support: ticket subject, category, priority, message bodies, optional order/payment references you type.

Social connections: OAuth tokens and asset metadata when Meta (or another configured adapter) is connected. We do not collect Facebook/Instagram passwords.

Developer: API keys stored as hashes; the plaintext key is shown once at creation.

Technical logs needed to operate and secure the service.

3. Data we do not collect

We do not collect platform passwords. We do not currently operate a marketing pixel or non-essential analytics cookie on the public site. We do not claim to collect government ID numbers unless you later upload them as support proof — and there is no dedicated national-ID field in this software today.

4. Why we process data

To create and secure accounts, take and fulfil orders, verify deposits, prevent fraud and abuse, provide support, keep legally useful records, and improve reliability. Processing is limited to what the product needs to function.

5. Cookies and similar technologies

The essential cookie is msp_session: an httpOnly, SameSite=Lax session cookie used to keep you signed in. Theme preference uses localStorage via next-themes, not a marketing cookie.

There is no cookie banner because we do not currently set non-essential analytics or advertising cookies. If that changes, a real consent workflow will be added before those cookies are used.

6. Security

Passwords are hashed with bcrypt. Session tokens and API keys are stored hashed. TOTP secrets and some payment credentials are encrypted with AES-256-GCM when an APP_ENCRYPTION_KEY is configured. Transport encryption depends on the HTTPS configuration of the host — this application does not by itself make a public HTTP deployment 'encrypted in transit'.

We do not claim government certification or that data is encrypted in every state if the host is misconfigured.

7. Sharing

Staff with assigned roles can see customer records needed for support, payments and fulfilment. Configured providers receive only the order payload required to perform work. Payment gateways, if configured, receive payment data they need. We do not sell personal data.

We may disclose information if required by applicable Bangladesh law or to protect the service, users or the public.

8. Retention and location

Account, order, wallet and ticket records are kept while the account exists and thereafter as needed for security, accounting and dispute handling. Exact statutory retention periods for a registered business are a BUSINESS/LEGAL ACTION REQUIRED item for the operator.

Hosting location depends on where the operator deploys the application. Cross-border processing may occur if the host or a provider is outside Bangladesh; that is an operational choice, not something this software conceals or certifies.

9. Your rights and requests

You may request access or correction of account data via /support or the configured support email. Bangladesh Personal Data Protection Act, 2026 rights, complaint routes and any designated Data Protection Office obligations depend on the Act's commenced sections and any regulator that is actually established. Software cannot appoint a statutory Data Protection Officer for you.

Closing an account is handled by administrators; it is not a silent self-serve wipe of payment and order records that must be retained.

10. Minors

The workspace is intended for adult customers and organisations. Do not register a child. If you believe a child has an account, contact support so we can close it.

11. Incidents

Security incidents are investigated by operators. Statutory notification duties under the Personal Data Protection Act, 2026 or the Cyber Security Act, 2026 are BUSINESS/LEGAL ACTION REQUIRED — this application does not automatically notify a government authority.

12. Changes

This policy is versioned with an effective date and last-updated date. Material changes will be published on /privacy.