Cansly --- Privacy Policy & Cookie Policy
This Policy is part of and incorporates the Cansly Terms of Service in full. This policy clarifies how Cansly disclose, collect and secure your Personal Data. (Personal Data means any information relating to an individual, such as name, parents' names, identification number, mobile number, financial data, location data or any other similar online identifier; or any physical, physiological, genetic, biometric, psychological, financial data of an individual, or any such element that helps to identify an individual as determined by regulations). It is issued under the Personal Data Protection Act, 2026 and the National Data Governance Act, 2026 (which establishes the National Data Governance Authority ("NDGA") as the data-protection regulator), together with the Cyber Security Act, 2026, the Consumer Rights Protection Act, 2009, the Digital Commerce Operation Guidelines, 2021, and other applicable laws. Certain provisions of the Personal Data Protection Act, 2026 has not come into force and the same shall be applicable and complied with as and when it is enforced.
1. Introduction and scope
-
This Privacy Policy and Cookie Policy ("Policy") explains how Cansly Digital ("Cansly", "we", "us", "our") collects, uses, stores, shares and protects Personal Data when you use the Cansly website, storefront, vendor panel, mobile applications, APIs and related services (the "Platform").
-
Cansly is an intermediary peer-to-peer digital marketplace and is not the seller of any Product. This Policy covers only processing carried out by Cansly as a data controller. It does not cover independent processing by Vendors, PSPs or other third parties under their own policies, for which Cansly is not responsible.
-
We will only collect information where it is necessary for us to do so and we will only collect information if it is relevant to our dealings with you. Therefore, this Privacy Policy sets out the ways in which Cansly collect, use and disclose information in connection with its operation of the Platform including personal information about platform visitors and representatives and employees of buyers and sellers. This Privacy Policy also applies to use of our Platform through a mobile device. We will only keep your information for as long as we are either required to by law or as is relevant for the purposes for which it was collected. You can visit the website and browse without having to provide personal details. During your visit to the website, you remain anonymous and at no time can we identify you unless you have an account on the website and log on with your user name and password.
-
By creating an account, accessing or using the Platform, you confirm you have read and understood this Policy and consent to the processing it describes where consent is the applicable basis. If you do not agree, you must not use the Platform.
-
This Policy forms part of, and must be read together with, our Terms of Service, Buyer Policy, Vendor Policy and Refund Policy.
2. What data we collect
-
Our website may collect various pieces of required information as part of the buying and selling process of the desired product using the website. If you are a Seller, we will also ask you to provide details about the goods and products that you intend to sell via the platform and details about your sales/transactions. If you are a Buyer, we will also ask you to provide details or preferences about the goods and products that you may be interested in buying via the platform and any details or preferences relevant to your purchases.
-
In order to to create and maintain an Account, Users may be required to provide certain information necessary for identification, verification, compliance, security, and the provision of services through the Platform.
3. Identification data:
For Buyers, such information may include, without limitation, the Buyer's name, address, contact number, email address, national identification details, payment and transaction information, location data, online identifiers, Know Your Customer (KYC) documentation, and any other information reasonably required to verify the Buyer's identity, process transactions, prevent fraud, or comply with applicable laws and regulatory requirements. Where required by law or for enhanced verification purposes,
For Vendors, Cansly may collect, in addition to the information set out for Buyers, information relating to the Vendor's business, including its legal name, trading name, registered address, incorporation or registration documents, trade licence, tax identification information, bank account details, payout account details (i.e. bKash, Nagad, Rocket number, or bank account details), authorisations, permits, and any other documents or information reasonably required to verify the legitimacy and operation of the Vendor's business. Such information may be stored in masked form with only the last digits visible in interfaces.
-
Account and profile data: For both Vendors and Buyers, Cansly may collect and maintain account and profile information, including usernames, encrypted or hashed passwords, notification preferences, linked devices and sessions, store settings, subscription tier and verification status, and other information necessary for account administration, security and service/product delivery.
-
Transaction data: Cansly may collect and maintain records relating to transactions conducted through the Platform, including orders placed or fulfilled, products and products variants, pricing information, fees, commissions, coupons, subscriptions (Cansly Plus / Cansly Pro), boosts, withdrawals, payment references and gateway transaction identifiers, refund and dispute records, balance and ledger entries, reviews, ratings and other transaction-related information.
-
Device and technical data: Cansly may collect technical information relating to the devices and systems used to access the Platform, including device fingerprints, browser fingerprints, device and browser type, operating system details, hardware characteristics and other technical identifiers. Such information may be collected during account registration, login, transactions and other interactions within the Platform for security, fraud prevention, analytics and operational purposes.
-
IP address and connection data: Cansly may collect and retain information relating to users' IP address (logged on every login and transaction), connection metadata, network information, and VPN/proxy detection signals or similar technologies, for security, fraud prevention, regulatory compliance, and operational purposes.
-
Location data: Cansly may collect and process approximate geographic location information derived from IP addresses and other technical signals for the purposes of fraud detection account security, compliance with applicable laws and regulations, enforcement of geographic restrictions, and the detection of suspicious or anomalous account activity. Cansly does not collect precise GPS location unless you explicitly enable it on a mobile device.
-
Communications data: Cansly may collect, monitor, review, filter, and retain communications exchanged through the Platform, including messages exchanged between Buyers and Vendors, dispute-related communications, support tickets, and the content and metadata of those communications. Such communications may be processed for fraud prevention, security, dispute resolution, customer support, quality assurance, compliance with applicable laws, and the enforcement of Cansly's Terms and Policies.
-
Usage and analytics data: Cansly may collect information relating to the manner in which Users interact with the Platform, including pages viewed, searches, clicks, time on page, referral source and similar interaction data collected through cookies and similar technologies. Such information may be used for analytics, service improvement, security, marketing, and operational purposes
-
Sensitive Personal Data: Cansly does not intentionally collect special categories of sensitive personal data (as defined under section 2(21) of Personal Data Protection Act, 2026) . Please do not submit such data.
-
Cansly may, in connection with any campaign, promotion, competition, giveaway, event, marketing activity, testimonial, leaderboard, or other activity conducted through or in relation to the Platform, display, publish, or otherwise use your name, username, profile information, store name, profile image, or other information associated with your account to identify you as a participant, winner, vendor, buyer, reviewer, or user of the Platform, unless prohibited by applicable law or where you have exercised any applicable right to object.
-
Cansly may, subject to obtaining your consent, send you emails about new products and other updates. If you prefer not to receive any marketing communications from us, you can opt out at any time. You may not use our products for any illegal or unauthorized purpose nor may you, in the use of the website, violate any laws in your jurisdiction (including but not limited to copyright laws). We may pass your name and address on to a third party in order to make delivery of the product to you (for example to our courier or supplier). You must only submit to us the information which is accurate and not misleading and you must keep it up to date and inform us of changes.
-
Cansly assumes no liability for misuse of any information, including but not limited to, passwords, financial information, address, IP addresses, usernames, contact information, unless such misuse in the fault of Cansly.
3. How we collect data
3.1 Data may be collected when any vendor or buyer register an account, complete Vendor KYC requirements, create listings, place or fulfil Orders, fill in custom checkout fields, subscribe to services, request withdrawals, send messages, initiate or respond to disputes, contact customer support, or submit reviews and feedback and by doing any of the above, you expressly, knowingly and voluntarily, consent to collection of data in line with section 5 of Personal Data Protection Act, 2026
-
When you access or use the platform, Cansly may automatically collect certain information, including device information, browser information, IP addresses, location data, cookie data, and usage information through Cansly's servers, logging systems, fraud-detection mechanisms, cookies, and similar technologies.
-
Cansly may obtain certain personal data from third parties, including Payment Service Providers such as Moneybag, authorized international payment gateways for payment status and references, fraud-prevention and IP/VPN intelligence sources, hosting, storage and infrastructure providers, other Users (e.g. a dispute counterparty or reviewer); and public sources or authorities where lawful and necessary.
4. Lawful basis and consent
-
By creating an account, accessing, or using the Platform, you acknowledge that you have read and understood this Policy and consent to the collection, use, disclosure, storage, and processing of your personal data as described herein where consent is the applicable. You further represent and warrant that you are at least 18 (Eighteen) years of age or otherwise have the legal capacity to enter into binding agreements under applicable law. Where we require your personal data for a specific purpose, including the provision of services, transaction processing, account administration, or compliance with legal obligations, you consent to such processing by voluntarily providing the relevant information. Where personal data is collected for optional purposes, including marketing communications, we will obtain your express consent or provide you with a clear opportunity to opt out.
-
Notwithstanding clause 4.1, and subject to the principles of usefulness, necessity, proportionality, and purpose limitation under applicable law, Cansly may process personal data without obtaining consent where such processing is necessary for the performance of a contract to which the Buyer or Vendor is a party, for taking steps at the request of the Buyer or Vendor prior to entering into a contract, for the establishment, exercise, or defence of legal rights or claims, for the protection of the vital interests of any person relating to life or health, for the implementation of legal rights relating to employment, labour, or social security matters, where the personal data has been voluntarily made public by the relevant data subject, or where withholding consent would likely result in harm to another person and the processing is reasonably necessary to prevent such harm.In the event that a Buyer or Vendor submits to Cansly any personal data relating to another individual, such Buyer or Vendor represents and warrants that they are duly authorised to provide such information and that all necessary consents and permissions have been obtained. The Buyer or Vendor shall bear all risks associated with such disclosure and shall indemnify and hold harmless Cansly from and against any claims, losses, liabilities, damages, costs, or expenses arising from any breach of this warranty.
The requirement to obtain consent from a data subject shall not apply where the processing of personal data is necessary in the interests of national security, defence, public order, or public interest; to comply with a lawful order of a court or competent authority; for the prevention, detection, investigation, or prosecution of criminal offences; for the prevention or detection of tax evasion; for public health, medical, or emergency purposes involving a threat to the life, health, or safety of any person; for the investigation of the misuse of public funds; for personal, recreational, or household purposes; for statistical, scientific, historical, or research purposes; or for publication in the public interest, journalism, archival, educational, artistic, or literary activities, to the extent permitted by applicable law.
5. Data sharing and third parties
- Any data stored or collected by Cansly may only be shared in the following circumstances:
a) To payment service providers such as Moneybag (a Bangladesh Bank-licensed PSP) processes local/BDT payments and holds buyer funds under its PSP payment-hold arrangement. Cansly never takes custody of customer payment funds and never stores card data; card processing occurs entirely on Moneybag's systems. International transactions are similarly processed exclusively through designated third-party payment service providers.
Limited data may be shared between a Buyer and Vendor as necessary to complete and support an Order such as custom fields, messages or dispute submissions.
b)
c) To infrastructure and service providers for hosting, AWS S3-compatible storage, databases, caching, email/SMS delivery, fraud-intelligence and analytics providers processing data on Cansly's behalf under confidentiality and data-processing terms.
d) For legal, regulatory and protective disclosures Cansly may disclose data to courts, regulators (including the DNCRP and the National Data Governance Authority (NDGA)), law enforcement, tax authorities, payment networks and advisers where we believe in good faith that disclosure is required by law, necessary to comply with legal process, or necessary to investigate fraud, enforce our agreements, contest a chargeback, recover amounts owed, or protect the rights, property or safety of Cansly, our Users or the public.
e) In a merger, acquisition, financing, reorganisation, sale of assets or insolvency, personal data may be transferred as part of the transaction, subject to this Policy.
-
Cansly may pass your details to other companies affiliated with it only for the purpose of providing you better service. Cansly may somewhat pass your details to its agents and subcontractors to help in analyzing data and providing Cansly with marketing or customer service assistance. Cansly may also use third parties for assisting with delivering products to you and to help collect payments from you. In general, the third-party providers used by Cansly will only collect, use and disclose your information to the extent necessary to allow them to perform the services they provide to Cansly. Cansly may exchange information with third parties for the purposes of fraud protection and credit risk reduction. We may transfer our databases containing your personal information if we sell our business or part of it. However, we shall not sell or disclose or transfer your personal data to third parties without obtaining your prior consent unless this is necessary for the purposes set out in this Privacy Policy or unless we are required to do so by law. Thus, we may pass your details to our professional advisers, law enforcement agencies, insurers, government and regulatory and other organizations where we believe it is necessary to comply with applicable laws or to exercise, establish or defend our legal rights or protect your vital interests or those of any other person. We may also transfer your data to any other person with your consent to the disclosure.
-
The website may contain advertisements of third parties and links to other sites or frames of other sites. Please be aware that we are not responsible for the privacy practices or content of those third parties or other sites, nor for any third party to whom we transfer your data in accordance with our Privacy Policy. When you click on links on our store, they may direct you away from our site. We are not responsible for the privacy practices of other sites and encourage you to read their privacy statements. However, certain third-party service providers, such as payment gateways and other payment transaction processors, have their own privacy policies in respect to the information we are required to provide to them for your purchase-related transactions. For these providers, we recommend that you read their privacy policies so you can understand the manner in which your personal information will be handled by these providers.
-
In particular, remember that certain providers may be located in or have facilities that are located a different jurisdiction than either you or us. So if you elect to proceed with a transaction that involves the services of a third-party service provider, then your information may become subject to the laws of the jurisdiction(s) in which that service provider or its facilities are located.
-
Once you leave our store's website or are redirected to a third-party website or application, you are no longer governed by this Privacy Policy or our website's Terms and Conditions. We may receive personal information about you from third parties that are engaged by us to assist with providing verification services and conducting suitable money laundering and KYC (know-your-customer) checks on users. This may include your name, email address, company details and contact information.
6. Data retention and record keeping
-
Subject to any specific legal requirement providing for a longer retention period, Cansly shall maintain and preserve records relating to personal data processed through the Platform for a minimum period of 5 (Five) years from the date of collection, creation, completion of the relevant transaction, termination of the user relationship, or such other date as may be required under applicable law.
-
Personal data shall be retained only for as long as is reasonably necessary to fulfil the purposes for which it was collected, including the provision of services, account administration, transaction processing, fraud prevention, dispute resolution, security monitoring, legal compliance, audit requirements, and the establishment, exercise, or defence of legal claims.
-
Where retention of personal data is required by law, regulatory direction, court order, ongoing investigation, dispute resolution process, enforcement proceedings, taxation requirements, accounting obligations, anti-fraud measures, or other legitimate business purposes, Cansly may retain such personal data for a period exceeding the minimum retention period specified in this Policy.
-
Notwithstanding the foregoing, Cansly may retain personal data beyond the applicable retention period where such retention is necessary for reasons of public interest, scientific research, historical research, statistical purposes, archival purposes, or any other purpose permitted under applicable law, provided that appropriate technical, organisational, administrative, and security measures are implemented to protect the rights and freedoms of the relevant data subjects.
-
Upon expiry of the applicable retention period, and where retention is no longer required for any lawful purpose, Cansly shall securely delete, anonymise, aggregate, or otherwise dispose of the relevant personal data.
-
Nothing in this Policy shall require Cansly to delete or destroy information that it is required or permitted to retain under applicable law or for the establishment, exercise, or defence of legal rights and claims.
7. Data security measures
-
To ensure the protection of your personal information, our technical and security team will take reasonable precautions and follow the best practices of industry to make sure that your information is being prevented from unauthorized or unlawful access to or is not inappropriately lost, misused, accessed, disclosed, altered or destroyed. We use firewalls on our servers so that the data we collect through the website about your personal details are secured in the server. Occasionally, our security procedures may request you to provide proof of identity before we disclose your personal information to you. It is your sole responsibility for protecting against unauthorized access to your password and to your computer. If you provide us with your credit card information, the information is encrypted using secure socket layer technology (SSL). Although no method of transmission over the Internet or electronic storage is 100% secure, we follow all PCI-DSS requirements and implement additional generally accepted industry standards.
-
Any record of any data retained by Cansly shall be preserved in the same manner and method in which it was first created, transmitted or received or in a manner and method that reflects the manner in which the data was created, transmitted or received.
8. Cookies & tracking technologies
-
We use cookies and similar technologies (including local storage, session identifiers, pixels and device/browser fingerprinting) to operate, secure and improve the Platform. We use both first-party and third-party technologies.
-
We rely on strictly necessary and security/fraud-prevention technologies on the basis of legitimate interests and the necessity of operating the Platform. For analytics and marketing technologies we rely on your consent, which you may give or withdraw through our cookie controls. We only use cookies for your convenience in using the website (for example to remember who you are when you want to amend your shopping cart without having to re-enter your email address) and not for obtaining or using any other information about you (for example targeted advertising). Your browser can be set to not accept cookies, but this would restrict your use of the website such as not being able to perform the "add to cart" functionality on the Platform.
-
To find out more information about cookies, go to https://www.allaboutcookies.org/ and go to https://www.allaboutcookies.org/manage-cookies/ to find out about removing cookies from your browser.Cookie categories & how to manage them
| Category | Purpose | Retention Period |
|---|---|---|
| Strictly necessary cookies | These cookies are essential for the operation of the Platform and enable core functions such as user authentication, session management, shopping cart functionality, checkout processes, load balancing, and security tokens. Without these cookies, certain parts of the Platform may not function properly or may become inaccessible. | Session duration to minimum 5 (Five) years |
| Security and fraud prevention | These help protect the Platform, its Users, and transactions from fraud, abuse, unauthorised access, automated attacks, and other security threats. They may collect information such as device characteristics, device or browser fingerprints, IP addresses, VPN or proxy indicators, abuse and bot detection, geo-restriction and other security-related signals. | Minimum 5 (Five) years |
| Functional and preference cookies | These cookies remember your preferences and settings, such as language selection, display preferences, notification settings, and other customisations, to provide a more personalised and convenient user experience. | Up to 5 years |
| Analytics and performance cookies | These cookies help us understand how Users interact with the Platform by collecting information about visits, page views, navigation patterns, and feature usage. The information is used to monitor performance, improve functionality, identify technical issues, and enhance the overall user experience. | Up to 5 years |
| Marketing and promotional cookies | These cookies may be used to measure the effectiveness of marketing campaigns, provide relevant promotional content, and understand the performance of advertisements and promotional activities. | Up to 5 years |
You may manage or disable non-essential cookies through the cookie controls/preference tools or through your browser settings. Please note that restricting or disabling strictly necessary cookies or security-related technologies may affect the functionality, performance, or accessibility of certain features of the Platform. Further, we do not currently respond to "Do Not Track" signals transmitted by web browsers, as there is currently no universally accepted industry standard governing such signals.
8. Your rights
9.1 Subject to the Personal Data Protection Act, 2026 and other applicable laws, and subject to verification of your identity, you may have the right to request access to the personal data processed by Cansly. Upon receipt of a valid request, Cansly may provide you with a copy of your personal data in a concise, intelligible and commonly used format, together with information relating to the summary of personal data processed, the purposes of processing, the activities undertaken in relation to such data, the categories of recipients with whom the data has been shared, the applicable retention periods, the source of the data where it was not collected directly from you, safeguards applied to any cross-border transfers, information relating to any automated decision-making processes, and such other information as may be required by applicable law. Where applicable, Cansly may arrange the data processed to be directly transferred to another data controller by using the Federated Interoperable Ecosystem.
9.2 Upon a valid request, Cansly may provide a copy of the personal data processed by it together with information identifying all other persons, data controllers or data processors with whom such personal data has been shared, to the extent required under applicable law and subject to any legal restrictions.
9.3 To exercise any of your rights under this Section, you may submit a request to legal@cansly.net. Cansly may require reasonable proof of identity before processing any request and shall respond within 15 (Fifteen) working days.10.4 The rights set out above are not absolute and may be restricted, delayed or refused where permitted or required by applicable law including where disclosure would prejudice national security, public order, the prevention, detection, investigation, or prosecution of criminal offences, ongoing legal proceedings, regulatory investigations, the rights and freedoms of third parties, or where Cansly is otherwise legally prohibited from providing the requested information. In such circumstances, Cansly may take such action as may be required by applicable law or the directions of the competent authority10.5 You may withdraw your consent to the processing of personal data, object to certain processing activities, request the cessation of automated decision-making or automated processing activities, or request the deletion of personal data where the purpose for processing no longer exists,
the processing is unlawful, or deletion is otherwise required by law. Cansly may, however, retain personal data where retention is necessary to comply with legal or regulatory obligations, for dispute resolution, fraud prevention, archival or preservation purposes, the establishment, exercise, or defence of legal claims, or for any other lawful purpose permitted under applicable law. Withdrawal of consent shall not affect the lawfulness of any processing carried out prior to such withdrawal10.6 If you have any concerns regarding the manner in which Cansly processes your personal data, you may contact us at legal@cansly.net. You may also submit a complaint to the National Data Governance Authority (NDGA) or any other competent authority having jurisdiction in accordance with applicable law.
9. International data transfers
10.1 Cross-Border Transfers:
- Where personal data is transferred outside Bangladesh, we apply safeguards required by applicable laws on both the jurisdictions concerned, including contractual protections, and observe the data-residency and cross-border-transfer requirements applicable to restricted personal data and Critical Information Infrastructure (CII) under the Personal Data Protection Act, 2026--- including the obligation, where applicable, to maintain a synchronised real-time copy of such data within Bangladesh --- as and when those provisions come into force.
11. Data breach notification procedure
11.1 We maintain procedures to detect, assess, contain and respond to personal-data breaches. If a breach occurs that is likely to result in a risk to affected individuals, we will, without undue delay and within the timeframes required by Applicable Law: investigate and contain the incident; notify the relevant authority where required; and notify affected users where the breach is likely to result in significant harm, describing the nature of the breach, likely consequences, and measures taken or recommended. Notifications may be made by email, in-Platform notice or other reasonable means. Our notification is not an admission of fault or liability.
12. Changes to this policy
-
We reserve the right to update this Privacy Policy at any time in response to changing legal, technical or business developments. Such changes and clarifications will take effect immediately upon their posting on the website. Once posted on the site, the new Privacy Policy will be effective immediately. Any changes will be communicated by us posting an amended Privacy Policy.
-
If any update involves material changes to this policy we will inform you immediately with the significance of the changes of the policy. We will obtain your consent to such material Privacy Policy changes if and where this is required by applicable data protection laws. If the business of Cansly is acquired or merged with another company, your information may be transferred to the new business owners so that the e-commerce platform may continue its services to you. Such transfer to the said actual or potential buyer (and its agents and advisers) in connection with the actual or proposed purchase, merger or acquisition of any part of our business, to the subject that the buyer must use your personal information only for the purposes disclosed in this Privacy Policy and not otherwise.
13. Governing Law, Disputes & Contact
13.1 This Policy is governed by the laws of Bangladesh. Any dispute relating to it is subject to the mandatory internal process, class-action waiver, fee-shifting and six-month limitation period in Section 19 of the Terms, save that nothing in these Terms limits a non-excludable statutory right, including a complaint to the National Data Governance Authority (NDGA) or DNCRP.
13.2 Contact details of Data Protection Officer:Cansly Digital
1211/1/CHA/F, East Jurain, Faridabad, Kadamtali, Dhaka-1204, Bangladesh
Privacy / DPO / Legal notices: **legal@cansly.net**
Support: **support@cansly.net**
Phone: **+880 1601-400668**
The Data Protection Officer also serves as Cansly's compliance contact under the Digital Commerce Operation Guidelines and coordinates with the DNCRP on consumer complaints.
*This Policy is the property of Cansly Digital. All rights reserved.*
