DATA PRIVACY & SECURITY PROTOCOL

Privacy Policy

How M1 Finance 365 collects, processes, protects, and retains your personal and financial information. Last Revised: August 2026.

1. Privacy Commitment & Scope

At M1 Finance 365, data privacy and financial confidentiality are fundamental pillars of our technology architecture. This Privacy Policy details our operational practices regarding the collection, processing, protection, and retention of user data.

We do not sell, rent, or monetize your personal or financial data to third-party advertisers. All information collected is strictly utilized to operate your digital wallet, verify transactions, enforce account security, and deliver investment management services.

2. Information We Collect

We collect only the minimum required information to provide secure financial management:

  • Account Registration Data: Full name, primary email address, password hash, and optional referral code.
  • Verification Data: Cryptographic SHA-256 hashed One-Time Passwords (OTPs), timestamp of email verification, and verification status.
  • Financial & Wallet Data: Available balance, locked investment amounts, withdrawal queues, deposit transaction references, and payment method details (e.g. EasyPaisa or JazzCash account title and number for payouts).
  • Technical & Session Data: IP address, browser type, device metadata, session tokens, and security audit log entries.

3. Authentication & Credential Storage

We employ industry-standard cryptographic safeguards for credential storage:

  • Bcrypt Password Hashing: Plaintext passwords are never stored in our database. Passwords are hashed server-side using 12 rounds of salted bcrypt before database persistence.
  • JWT Sessions: Authenticated sessions use signed JSON Web Tokens stored in secure HTTP-only cookies (SameSite=Lax), mitigating Cross-Site Scripting (XSS) risks.
  • Single-Use OTP Hashes: Verification OTPs are salted and hashed with purpose identifiers (REGISTRATION: and PASSWORD_RESET:) and stored exclusively as SHA-256 digests.

4. Financial & Transaction Data Processing

Every financial event (deposit, investment lock, daily ROI accrual, withdrawal request, principal return) is recorded in an immutable ledger with before-and-after balance snapshots. Financial records are strictly separated from marketing or communication layers.

6. Secure Cookies, Session Lifecycles & Telemetry

M1 Finance 365 utilizes strictly essential, encrypted, server-side cookies required for institutional session integrity, multi-factor authentication, and Cross-Site Request Forgery (CSRF) mitigation. We do not sell user data, deploy third-party advertising cookies, or track browsing activity across third-party websites.

Cookie IdentifierCategoryAttributesLifespanPurpose
aura_auth_sessionEssential AuthHttpOnly; Secure; SameSite=Lax7 Days (User) / 4 Hours (Admin)Encrypted JWT session state & role authorization
aura_admin_2fa_pendingSecurity 2FAHttpOnly; Secure; SameSite=Lax5 MinutesTemporary state between password verification and TOTP confirmation

Authentication cookies are never accessible to client-side JavaScript (document.cookie). Upon logging out or triggering account security version updates (e.g. password change, 2FA reset), all active session cookies are permanently invalidated and purged from browser storage.

7. Third-Party Payment Gateway Providers

When executing automated deposits via EasyPaisa or JazzCash, payment processing is routed through encrypted gateway APIs. Communication is verified via HMAC-SHA256 signatures over secure TLS. User financial secrets (such as PINs or OTPs on payment apps) are handled directly by the provider and never pass through or get stored on M1 Finance 365 servers.

9. Data Retention & Ledger Immutability

In compliance with financial integrity requirements, transaction ledgers, audit logs, and deposit/withdrawal records are retained permanently to ensure financial consistency and prevent duplicate claims. User profiles may be marked inactive, but financial ledger history is preserved.

10. User Rights & Data Access

You have the right to review your personal profile data, update your security credentials, and request an export of your transaction history directly through your User Panel.

Questions regarding data privacy?Contact Data Protection Support