Back to Krak Bank

Privacy policy

Network activity disclosure ยท Updated October 8, 2026

This page explains the site's account and network activity reporting. There is no privacy-choice icon, consent dialog, automatic privacy popup, or inline activity notice. This policy remains available through standard links in the welcome and verification header and account navigation.

Site access and approximate location

When network reporting is active, visits and account requests can be recorded with the request's IP address, approximate city, region, and country, event time, and activity category. Authenticated activity also identifies the requesting account. These records help authorized administrators monitor site access, account operations, verification requests, and support activity.

The IP address and approximate location come from Netlify's trusted request context. We do not request GPS access or use external IP-lookup services. VPNs, proxies, shared networks, and mobile routing can make the location inaccurate or unavailable. Network location is not a person's precise physical location. Anonymous visit alerts are limited to one per IP address every five minutes; account-access alerts are limited to one per account every five minutes.

Telegram administrator access

Linked, authorized administrators can receive activity reports, including available IP and approximate-location details, through their private Telegram bot chats. They can also view account summaries and support conversations, reply to support messages, and perform confirmed, audited account-management actions. Telegram processes delivered messages on its own infrastructure.

Identity documents, selfies, private upload links, stored verification names and residential-address fields, passwords, passcodes, and provider credentials are not automatically forwarded to Telegram. Avoid entering sensitive identity information into support messages or custom notification text.

Storage and retention

Account and activity records are stored using Netlify Database; private identity uploads use Netlify Blobs. Network activity events and their delivery records are removed from the application database after seven days by the production cleanup job. Pending Telegram command payloads are removed after one day, and duplicate-update references after two days. Account, financial, verification, and audit records follow their separate retention rules rather than the seven-day network-event cleanup.

Deleting database records does not remove messages already delivered to Telegram. The site operator must separately manage Telegram chat and device access and retention. Previously queued reports can be delivered before they expire.

Browser privacy preferences

Network reporting does not require clicking an in-app consent button and does not set a new tracking cookie or cross-site identifier. Requests carrying Do Not Track or Global Privacy Control are excluded from network reporting. If you previously declined through the old privacy controls, that decline remains honored while the existing preference cookie is present. Essential account-operation notifications can still be sent without network details.

These preferences stop future network collection for applicable requests; they do not erase existing records or delivered messages. For questions about your data or requests concerning retained records, contact the site operator through account support.

Other service providers

Netlify hosts the site, its database, and private uploads. Netlify Identity handles authentication. Configured transactional email and device-push providers handle their respective account messages. Google Fonts supplies the site's typefaces and receives requests needed to load those resources. These services process the data needed to perform their functions.