1. Privacy Commitment & Scope
At M1 Finance 365, data privacy and financial confidentiality are fundamental pillars of our technology architecture. This Privacy Policy details our operational practices regarding the collection, processing, protection, and retention of user data.
We do not sell, rent, or monetize your personal or financial data to third-party advertisers. All information collected is strictly utilized to operate your digital wallet, verify transactions, enforce account security, and deliver investment management services.
2. Information We Collect
We collect only the minimum required information to provide secure financial management:
- Account Registration Data: Full name, primary email address, password hash, and optional referral code.
- Verification Data: Cryptographic SHA-256 hashed One-Time Passwords (OTPs), timestamp of email verification, and verification status.
- Financial & Wallet Data: Available balance, locked investment amounts, withdrawal queues, deposit transaction references, and payment method details (e.g. EasyPaisa or JazzCash account title and number for payouts).
- Technical & Session Data: IP address, browser type, device metadata, session tokens, and security audit log entries.
3. Authentication & Credential Storage
We employ industry-standard cryptographic safeguards for credential storage:
- Bcrypt Password Hashing: Plaintext passwords are never stored in our database. Passwords are hashed server-side using 12 rounds of salted bcrypt before database persistence.
- JWT Sessions: Authenticated sessions use signed JSON Web Tokens stored in secure HTTP-only cookies (
SameSite=Lax), mitigating Cross-Site Scripting (XSS) risks. - Single-Use OTP Hashes: Verification OTPs are salted and hashed with purpose identifiers (
REGISTRATION:andPASSWORD_RESET:) and stored exclusively as SHA-256 digests.
4. Financial & Transaction Data Processing
Every financial event (deposit, investment lock, daily ROI accrual, withdrawal request, principal return) is recorded in an immutable ledger with before-and-after balance snapshots. Financial records are strictly separated from marketing or communication layers.
6. Secure Cookies, Session Lifecycles & Telemetry
M1 Finance 365 utilizes strictly essential, encrypted, server-side cookies required for institutional session integrity, multi-factor authentication, and Cross-Site Request Forgery (CSRF) mitigation. We do not sell user data, deploy third-party advertising cookies, or track browsing activity across third-party websites.
| Cookie Identifier | Category | Attributes | Lifespan | Purpose |
|---|---|---|---|---|
| aura_auth_session | Essential Auth | HttpOnly; Secure; SameSite=Lax | 7 Days (User) / 4 Hours (Admin) | Encrypted JWT session state & role authorization |
| aura_admin_2fa_pending | Security 2FA | HttpOnly; Secure; SameSite=Lax | 5 Minutes | Temporary state between password verification and TOTP confirmation |
Authentication cookies are never accessible to client-side JavaScript (document.cookie). Upon logging out or triggering account security version updates (e.g. password change, 2FA reset), all active session cookies are permanently invalidated and purged from browser storage.
7. Third-Party Payment Gateway Providers
When executing automated deposits via EasyPaisa or JazzCash, payment processing is routed through encrypted gateway APIs. Communication is verified via HMAC-SHA256 signatures over secure TLS. User financial secrets (such as PINs or OTPs on payment apps) are handled directly by the provider and never pass through or get stored on M1 Finance 365 servers.
9. Data Retention & Ledger Immutability
In compliance with financial integrity requirements, transaction ledgers, audit logs, and deposit/withdrawal records are retained permanently to ensure financial consistency and prevent duplicate claims. User profiles may be marked inactive, but financial ledger history is preserved.
10. User Rights & Data Access
You have the right to review your personal profile data, update your security credentials, and request an export of your transaction history directly through your User Panel.