Cookie Policy
Our cookie policy uses the same data-minimisation principles described here — only cookies necessary for session management and fraud prevention are set by default.
At kklion, we are transparent about every piece of information we collect from your account and how we use it within supported regions of Pakistan. This policy sets...
When you open an account with kklion, we collect your name, contact details, and payment identifiers — including tokens associated with JazzCash, Easypaisa, SadaPay, and Raast transactions — solely to process your deposits, verify withdrawals, and maintain account security. We do not store full payment credentials on our servers; tokenised references are held under encryption. Your browsing behaviour on our platform is
logged in aggregate to improve page performance and session stability. We share data with third parties only where required by applicable law or to complete a payment instruction you have authorised. All processing is carried out where local law permits, and data is retained only for as long as your account remains active or as required by applicable record-keeping obligations.
Service availability is jurisdiction-dependent. Users are responsible for checking local law before access.
We have built our data practices around clear accountability, regular internal review, and the specific payment and identity flows used by accounts in Pakistan. Every claim in this policy reflects how our...
All personal data stored on kklion servers is encrypted using current industry-standard ciphers. Encryption keys are rotated on a scheduled basis and access is restricted to authorised personnel only.
JazzCash, Easypaisa, SadaPay, and Raast payment references are stored as one-way tokens. We cannot reconstruct your full payment credentials from the reference held in our database.
Internal access to personal data is role-based and logged. Any staff member querying account data outside a support ticket context triggers an automatic audit alert for review.
This privacy policy is reviewed on a scheduled cycle. When our data practices change, we update this page and notify affected account holders by email before the change takes effect.
We collect only the data fields required to operate your account, process your chosen payment method, and meet our legal obligations. Fields that serve no operational purpose are not collected.
You may request full deletion of your personal data at any time your account is closed. We will confirm deletion within the timeframe required by applicable law in supported regions.
Our cookie policy uses the same data-minimisation principles described here — only cookies necessary for session management and fraud prevention are set by default.
The terms of service reference this privacy policy directly. Any data-handling obligation mentioned in the terms is governed by the definitions and rights set out on this page.
Payment data handling described in our payment section is a subset of this policy. The same retention and encryption standards apply to JazzCash, Easypaisa, SadaPay, and Raast flows.
Security practices described on our account security page — two-factor authentication, login alerts — operate within the data framework this policy defines.
If you opt into promotional emails, that preference is stored and managed under the same consent framework this policy describes. You can withdraw consent at any time from your account settings.
Game studios whose content appears in our lobby receive only anonymised session identifiers, never your personal account data or payment details, consistent with this policy.
Chat and email transcripts with our support team are retained under the same schedule as account data and are subject to the same deletion rights described in this policy.
Our privacy framework is structured so you can find the section relevant to your question without reading the entire document. Each element below corresponds to a...
A clear list of every category of personal data we collect, from account registration fields through to device identifiers used for fraud detection on your session.
For each data category we name the legal basis — contract performance, legal obligation, or legitimate interest — so you understand why we hold each piece of information.
Specific retention periods for each data category, including the shorter window that applies once your account is closed and the longer window required by financial record-keeping rules.
A dedicated section covering your right to access, correct, port, restrict, and erase your data, with the exact steps to submit each type of request to our team.
A structured table of the third-party categories that may receive your data — payment processors, fraud-prevention services — and the safeguards applied to each transfer.
Details of how and when we notify you of material changes to this policy, including the notice period we commit to before any new data practice takes effect.