Privacy Policy
Effective / Last revised: 26 August 2026
No account, KYC document, session or user-specific private data is rendered on this public policy page.
1. Introduction
One Click Service (OCS) provides account, service, recruitment, CV, identity-verification and related workflows through its website, APIs and supported applications. This Policy explains responsible information handling without promising absolute security or overriding applicable law.
2. Information We Collect
OCS collects information you provide, records created to deliver a requested service, and limited technical and security information generated during use. Collection is limited to stated service, contractual, security or legal purposes.
3. Account & Registration Information
Registration may include name, account type, email, mobile, password hash, language and acceptance of the applicable Terms and Privacy Policy. OCS records policy version, timestamp, account identifier and relevant request context as consent evidence.
4. Email and Mobile Number
Email and, only when an approved SMS provider is configured, mobile numbers support verification, recovery and important notices. OTPs expire, have resend and attempt limits, are single-use and are not returned by APIs.
5. KYC & Identity Verification Data
OCS may process verified contacts, legal name, birth date, nationality, residence and issuing country, document type, protected and masked document values, expiry details, private images, status, risk flags and review records. KYC information is not public.
6. National ID / NID
For Bangladesh identity checks, OCS may accept an NID image and required attributes. The number is stored as a protected comparison value and masked display value; after submission interfaces must not show the full NID.
7. Passport Information
Passport processing may include legal name, birth date, nationality, issuing country, issue and expiry dates, a masked number and private document images. Displays use a form such as ******1234, never the complete number.
8. Driving Licence Information
Where appropriate, a driving licence may be processed as government identity using the same restricted upload, masking, malware-scanning, authorization and review controls.
9. Face / Selfie / Liveness Verification
Automated face matching or liveness is used only when an approved provider is configured and required notice or consent is provided. Until then OCS uses manual review and does not describe a normal photo upload as a successful liveness check.
10. Uploaded Documents
KYC and service files use private storage, generated references, size and signature validation and malware scanning. Access requires authentication plus owner or authorized compliance permission; files are not placed in unrestricted public directories.
11. Security Questions
OCS does not currently use traditional personal security questions or ask for answers such as a mother's maiden name. Any future comparison-only answer must use a one-way protected representation and never be returned or logged in plaintext.
12. OCS Security Code
The separate OCS Security Code is a secret credential: strongly hashed, never redisplayed after creation, never emailed or logged in plaintext, attempt-limited and temporarily locked after repeated failures. Recovery requires a verified flow.
13. Payment & Transaction Information
OCS may process provider, reference, amount, currency, status and timestamps. Payment credentials are handled by an approved provider only when activated; disabled providers are not presented as live and full card secrets are not required in ordinary OCS records.
14. Device and Browser Information
Browser type, user agent, language, operating environment and request identifiers may be processed for compatibility, fraud prevention, support and security monitoring.
15. IP Address and Security Logs
IP and security events may support rate limiting, authentication protection, consent evidence, audit and incident investigation. OCS does not intentionally log passwords, OTPs, session tokens, full document numbers or security codes.
16. Cookies and Session Information
Authentication uses secure server-issued cookies that are HttpOnly, Secure in production, SameSite protected and site-scoped. Normal login uses a browser-session cookie; selected Remember Me may persist for its stated period. Logout revokes the server record and clears the cookie.
17. Location Information
With permission, coordinates may be processed server-side only to resolve city, country, timezone and weather context. Precise coordinates are not displayed or kept as location history; necessary city-level data may be saved. Saved/coarse, IP-approximate and configured Dhaka fallbacks may apply.
18. Recruitment / Job Application Data
Applications may include a consented CV snapshot, cover letter, recruiter, status, interview, offer and visa workflow. Recruiter access is restricted to the relevant application and authorized organization.
19. CV / Resume Information
Master CV data may include profile, education, employment, skills, certificates, languages and an optional photo. Submitted snapshots remain associated with that application and are not silently changed when the live profile is edited.
20. Student / University / Visa Information
Education, university, migration and visa services may require academic records, certificates, passport or sponsor details, offers, admissions and authority decisions according to the selected service and provider.
21. Medical or Other Sensitive Service Information
Medical, insurance, legal or other sensitive services may require information relevant to that request. Access and sharing are limited to the user, authorized staff and selected approved provider; OCS does not create medical diagnoses.
22. How OCS Uses Personal Information
OCS uses information to secure accounts, deliver requested services, verify identity, manage applications and documents, communicate, support users, prevent fraud, process provider-dependent transactions, audit and meet lawful obligations.
23. Legal Basis / Consent
Processing may rely on requested service performance, contract steps, explicit consent, legitimate security and operational needs, or applicable legal and regulatory duties. Jurisdiction-specific rights apply only where the relevant law applies.
24. Identity and Fraud Prevention
OCS compares protected identity attributes, reviews status and risk indicators, applies rate limits and records security actions to reduce impersonation, duplicate identity use, abuse and fraud.
25. KYC Requirement for Financial Transactions
Identity verification may be mandatory for regulated, high-risk or international activity. Configured KYC levels are enforced server-side; insufficient, rejected, blocked or review-required profiles are securely denied even if client UI is altered.
27. Service Providers / Processors
Processors may include hosting, infrastructure, malware scanning, email, configured SMS, payment, storage, weather/geocoding and approved identity providers. Provider-dependent functions remain unavailable or manual until configured and approved.
29. International Data Transfers
International services and global processors may handle information outside the user's country. OCS seeks purpose limitation, access controls and appropriate contractual or organizational safeguards, while legal protections may differ by jurisdiction.
30. Data Storage and Retention
Records are retained only as reasonably needed for account, service, dispute, fraud prevention, audit, backup and applicable legal or regulatory purposes. Retention varies by record; expired data is deleted, anonymized or access-restricted under approved procedures.
31. Account Closure and Data Deletion
Closure does not erase records required for active services, law, security, fraud prevention, payment reconciliation, disputes or audit integrity. Remaining data is restricted and removed when the applicable need ends.
32. User Privacy Rights
Subject to applicable law and verified identity, users may request processing information, access, correction, permitted deletion, restriction, objection, consent withdrawal or review. Requests may be limited for law, another person's rights, security or fraud prevention.
33. Access / Correction / Update
Supported profile fields can be updated by the user or through OCS support. Identity documents and immutable application snapshots may require a new verified submission rather than direct overwriting.
34. Consent Withdrawal
Consent may be withdrawn for optional future processing. Withdrawal does not invalidate earlier lawful processing and may stop a service requiring that information; required legal, security and audit records may remain.
36. Children's / Minor Users' Privacy
Education or family services may concern a minor. A parent, guardian or authorized adult is required where applicable; OCS does not knowingly invite a child to independently submit KYC or financial credentials contrary to law.
37. Security Measures
OCS uses safeguards designed to protect data: HTTPS/TLS, Secure and HttpOnly cookies, SameSite, server authorization, RBAC, applicable origin/CSRF checks, validation, parameterized database access, rate limits, OTP expiry and limits, hashing, session revocation, malware scanning, audit logs and least privilege.
38. Data Breach Handling
OCS investigates suspected incidents, limits exposure, preserves necessary evidence, restores safe operation and notifies affected persons or authorities where required by applicable law and assessed risk, without exposing additional secrets.
39. Third-Party Websites
External airlines, embassies, universities, government services and providers control their own sites and privacy practices. Review their policies before sharing information; this OCS Policy does not govern them.
40. Policy Updates
OCS may update this Policy as services, providers, law or security practices change. Version and last-updated date are shown. Material changes may require renewed notice or consent; historical consent records are not silently rewritten.
41. Contact / Privacy Requests
Use the OCS Contact or Support page for access, correction, consent or deletion requests. Never send passwords, OTPs, security codes or full identity numbers in ordinary support messages. OCS may verify identity before acting.