Privacy Policy
BeeNoor · Last updated August 2026
1. What we collect
When you register
- Your name, email address and mobile number.
- Your password, stored only as a one-way hash — we cannot read it, and neither can anyone with database access.
- The referral code you signed up with, if any.
- The IP address the registration came from.
From your device, when you use the app
- A random identifier generated by the app itself. It is not your phone number, IMEI, advertising ID or any hardware serial.
- Device make and model, operating-system version and app version.
- Your IP address and the time you last used the app.
- A push-notification token, if you enable notifications.
When you transact
- Amounts, dates and the running balance of every transaction.
- For deposits: the sender name, sending account and payment reference you provide, and any payment screenshot you upload.
- For withdrawals: the payout account name and number you give us.
Sign-in records
- Successful and failed sign-in attempts, with the time, IP address and device.
2. Why we collect it
- To run your account — process purchases, credit distributions, pay withdrawals and show you your history.
- To keep the platform honest — the device identifier is how we enforce one account per person and stop the same phone claiming the same bonus repeatedly. Without it, bonus farming would be trivial and would come out of genuine members' returns.
- To secure your account — sign-in records let us detect and investigate unauthorised access.
- To meet legal obligations — financial records must be retained.
- To contact you — service messages, and password resets you request.
3. Who can see it
Your data is not sold, rented or shared for marketing. It is accessible only to:
- Our own staff, limited by role — support staff can help with your account but cannot move money, and every administrative action is recorded in an audit trail.
- Our hosting and email providers, who process data on our instructions in order to run the service.
- Law enforcement or regulators, where we are legally required to disclose.
Other members cannot see your contact details. Someone who referred you sees your name, when you joined, whether you have activated, and how much you have invested — never your email address, your phone number or your transaction history.
4. How long we keep it
- Financial records — kept permanently. The transaction ledger cannot be edited or deleted, by anyone, including us: a correction is made by adding a compensating entry, never by rewriting history. This is what makes your balance auditable.
- Account details — kept while your account is open, and afterwards for as long as the law requires.
- Device and sign-in records — kept while needed to prevent fraud and secure accounts.
- Payment screenshots — kept with the deposit they belong to.
5. Your choices
- See your data — your profile, transactions, deposits, withdrawals and team are all visible in the app at any time.
- Correct it — you can update your name, email and phone yourself. Changing your email or phone clears its verified status until you confirm the new one.
- Ask for a copy, or for deletion — email us. We will delete what we are not legally required to keep, and tell you plainly what must be retained and why.
- Turn off notifications — in your device settings.
Your referral link cannot be changed, and who referred you cannot be changed after signup — both are permanently attached to commission payments that have already been made.
6. How it is protected
- The whole site and app are served over encrypted HTTPS connections.
- Passwords are stored as one-way hashes and are never recoverable, displayed or emailed.
- Sign-in tokens are shown once and stored in your device's encrypted storage.
- Staff access is limited by role, and every administrative action is logged with who did it and when.
- Databases are not reachable from the public internet.
No system is perfectly secure. If a breach affects your data, we will tell you.
7. Cookies
The website uses one cookie to keep you signed in and one to protect forms against cross-site request forgery. Both are strictly necessary for the site to work. There are no advertising, analytics or third-party tracking cookies. The mobile app uses no cookies at all — it authenticates with a token.
8. Children
The platform is not for anyone under 18. We do not knowingly collect data from children. If you believe a child has registered, tell us and we will remove the account.
9. Changes
If this policy changes, the date at the top changes with it, and material changes are notified in the app before they take effect.
Privacy questions, data requests and deletion requests: support@beenoor.com