Skip to content
OwlstechBack to website

Privacy Policy

Last updated 8 October 2026

This policy explains what Owlstech collects when you use our website, your account, the Owlstech eKYC subscription and its demo app, and how we use it.

Software you run on your own servers

When a business runs Owlstech eKYC on its own servers, the NID images, selfies and results in that deployment stay with that business. The server needs no connection to us, and we do not receive that data. The business that runs it decides how it is used; ask that business about its privacy policy.

What we collect

  • Account: your name, email address, a hash of your password (never the password itself) and whether your email is verified.
  • Subscriptions: the plans you book, payment references, the receipts you upload, our review notes and your subscription dates.
  • Licences and deliveries: your licence identity, expiry date and software versions, and the history of your deliveries. App keys are generated during the build and are not stored in our database.
  • Messages: what you send us by email.
  • Technical data: your IP address and request details, which our servers and network provider process to deliver and protect the website.

Cookies

We use one cookie to keep you signed in. It expires when your session ends. We do not use advertising or analytics cookies.

The demo app and demo server

  • The demo app sends the NID card photos and selfies you take to our demo server so it can show you the results.
  • The demo server processes photos in memory. It does not keep the photos or the text it reads from them.
  • For a liveness check, it keeps the face measurements it needs (not photos) only until the check expires, within an hour. It keeps one-way fingerprints of the camera frames for 24 hours so the same frames cannot be reused.
  • To apply the demo's usage limit, it counts requests per network address in memory for the limit period.
  • Use the demo only with your own NID card and face, or with the permission of the person shown.

How we use information

We do not sell personal information or use it for advertising. We use it only:

  • to run your account and sign you in;
  • to process bookings and confirm payments;
  • to generate your licence and deliver the software;
  • to send account, payment, subscription and licence renewal emails;
  • to keep the service secure and prevent abuse;
  • to meet our legal and accounting obligations.

Service providers

We share information only with providers that help us run the service, and only as far as they need it. They may process it outside Bangladesh.

  • MongoDB Atlas stores our website database.
  • Brevo delivers our emails.
  • Cloudflare carries traffic to our website and demo server.
  • GitHub builds your software deliveries. It receives the name on your account and your licence dates, which are written into your licence.
  • Google Drive stores delivery files and the demo app privately in our own account. Files are never shared publicly, and you do not need a Google account.

How long we keep it

  • Account details: while your account exists.
  • Sign-in sessions, password reset and email verification links: until they expire, from minutes to a day.
  • Delivery files: deleted from storage after seven days. Delivery history and licence records stay with your account, so we can renew your licence.
  • Bookings and payment receipts: as long as we need them for accounting and the law.

Security

We use HTTPS, store passwords only as hashes, keep delivery files private, and limit access to the people who run the service.

Your choices

You can change your name on your profile page. To get a copy of your information, correct it or delete your account, email [email protected]. We may need to keep some records, such as payments, when the law requires it.

Children

Our service is for businesses and is not intended for anyone under 18.

Changes

We may update this policy. The date at the top shows the latest version.

Contact

Questions about your privacy: [email protected].