phpg is committed to protecting the privacy and personal data of every player on our platform. This Privacy Policy explains what personal information phpg collects, why we collect it, how it is used and protected, and what rights you have under the Philippines Data Privacy Act of 2012.
A plain-English summary of our core commitments before you read the full policy below.
phpg collects personal data strictly for defined purposes: account management, identity verification, payment processing, regulatory compliance, and responsible gaming. We do not collect data speculatively or sell player data to third-party advertisers.
All personal data held by phpg is protected using 256-bit AES encryption at rest and TLS 1.3 in transit. Access to player data within phpg is restricted to authorized personnel on a strict need-to-know basis, enforced through role-based access controls.
phpg's data practices are designed to comply with Republic Act No. 10173, the Data Privacy Act of 2012, and the implementing rules issued by the National Privacy Commission (NPC) of the Philippines. You have enforceable rights under this law.
phpg shares your data only with licensed payment processors, KYC verification partners, and regulatory authorities as required by law. We do not share personal data with marketing brokers, data resellers, or unaffiliated third parties for commercial purposes.
You have the right to access, correct, object to, and in certain circumstances delete your personal data held by phpg. You can also withdraw marketing consent at any time. Requests are handled by phpg's Data Protection Officer within the statutory period.
In the unlikely event of a personal data breach that poses a real risk to you, phpg will notify affected players and the National Privacy Commission within the timeframes required under the Data Privacy Act and NPC guidelines.
1.1 This Privacy Policy describes how phpg ("we," "us," "our," or "phpg") collects, uses, discloses, stores, and protects personal data relating to individuals ("you," "your," or "Player") who register an account with, access, or otherwise interact with the phpg Platform at phpg.one.
1.2 phpg is operated under a license issued by the Philippine Amusement and Gaming Corporation (PAGCOR) and is subject to the data protection requirements applicable to PAGCOR-licensed operators. Our data processing practices are governed principally by the Republic Act No. 10173, the Data Privacy Act of 2012 (DPA), and its Implementing Rules and Regulations as issued and amended by the National Privacy Commission (NPC) of the Philippines.
1.3 By registering a phpg account or using any service on the phpg Platform, you acknowledge that you have read and understood this Privacy Policy and consent to the collection and processing of your personal data as described herein. If you do not agree to the terms of this Privacy Policy, you must not register for or use the phpg Platform.
1.4 This Privacy Policy should be read in conjunction with phpg's Terms & Conditions, available at phpg.one/terms-conditions, and phpg's Responsible Gaming Policy, available at phpg.one/responsible-gaming.
3.1 phpg collects personal data that is necessary, adequate, and relevant to the purposes described in Section 5 of this Policy. The following table sets out the categories of personal data phpg processes:
| Category | Examples | Purpose(s) |
|---|---|---|
| Identity Data | Full legal name, date of birth, nationality, government ID number and type (e.g., Philippine national ID, passport, driver's license) | Account registration, KYC, age verification, AML compliance |
| Contact Data | Email address, Philippine mobile number, residential address | Account communication, OTP delivery, support, regulatory correspondence |
| Financial Data | Payment method details (GCash registered number, Maya account, bank name and account holder name), deposit and withdrawal records | Payment processing, withdrawal verification, AML monitoring, financial reconciliation |
| Technical Data | IP address, device type, browser type and version, operating system, screen resolution, session timestamps | Security monitoring, fraud prevention, platform optimization, geolocation compliance |
| Usage Data | Games played, wager amounts, session duration, win/loss records, game category preferences, bonus usage history | Responsible gaming monitoring, account management, analytics, personalized experience |
| KYC Documentation | Scanned or photographed copies of government-issued ID, proof of address documents, payment method ownership evidence | Identity verification, age verification, AML compliance, regulatory audit |
| Communications Data | Records of live chat conversations, email correspondence, and support ticket content | Customer support, dispute resolution, compliance documentation |
| Marketing Preferences | Opt-in/opt-out status for promotional emails, SMS notifications, and in-platform messages | Delivering or suppressing marketing communications per your preferences |
3.2 phpg does not collect biometric data, health data, or political opinions as part of its standard account management process. Where collection of sensitive personal information is required for regulatory purposes (e.g., source-of-funds declarations), such data is handled with heightened security measures and used only for the stated regulatory purpose.
4.1 phpg collects personal data through the following means:
5.1 phpg processes your personal data for the following defined purposes:
5.2 phpg will not use your personal data for any purpose that is incompatible with the purposes listed above without obtaining your separate consent or as otherwise permitted by applicable law.
6.1 Under the Data Privacy Act of 2012, phpg relies on the following legal bases for processing your personal data:
6.2 Where phpg relies on consent as the legal basis, you have the right to withdraw that consent at any time by contacting the phpg DPO at [email protected] or updating your communication preferences in your Account settings. Withdrawal of consent will not affect the lawfulness of any processing that occurred prior to withdrawal.
7.1 phpg shares your personal data only with the categories of recipients described below, and only to the extent necessary for the stated purpose:
7.2 phpg does not sell, rent, or trade your personal data to any third party for marketing purposes. phpg does not share personal data with social media platforms, advertising networks, or data brokers.
8.1 phpg retains personal data for as long as necessary to fulfil the purpose for which it was collected, subject to the minimum retention periods required under applicable law. The following general retention periods apply:
| Data Category | Retention Period | Basis |
|---|---|---|
| Account and Identity Records | 5 years after account closure | PAGCOR licensing requirements; AML Act (RA 9160) |
| KYC Documentation | 5 years after account closure | AML Act (RA 9160) as amended by RA 10365 |
| Financial Transaction Records | 5 years from date of transaction | AML Act; PAGCOR record-keeping requirements |
| Gameplay and Session Records | 3 years from date of session | PAGCOR licensing; dispute resolution; responsible gaming |
| Support Communications | 3 years from date of communication | Dispute resolution; legal proceedings |
| Marketing Preferences | Until consent is withdrawn or account is closed | Consent; contractual |
| Cookie and Technical Data | Up to 13 months from collection | Platform analytics; fraud prevention |
8.2 Where the purpose for which data was collected ceases to apply and there is no legal obligation requiring further retention, phpg will securely delete or irreversibly anonymize the relevant personal data. Anonymized, aggregated data from which individuals cannot be identified may be retained indefinitely for analytics purposes.
9.1 phpg implements appropriate technical and organizational security measures to protect personal data against unauthorized access, accidental loss, destruction, alteration, or disclosure. These measures include:
9.2 Notwithstanding the above, no security system is impenetrable. In the event of a personal data breach that creates a real risk of serious harm to affected individuals, phpg will notify the National Privacy Commission and affected Players within 72 hours of becoming aware of the breach, as required under NPC Circular No. 16-03.
10.1 The phpg Platform uses cookies and similar tracking technologies (including local storage and session tokens) to ensure the Platform functions correctly, to maintain your authenticated session, and to support analytics and fraud prevention.
10.2 phpg uses the following categories of cookies:
10.3 phpg does not use third-party advertising cookies or allow advertising networks to set cookies through the phpg Platform. phpg does not engage in cross-site tracking or behavioral profiling for marketing purposes.
10.4 You may manage cookie preferences through your browser settings. However, disabling strictly necessary cookies will prevent you from accessing your phpg account. phpg's cookie consent banner, displayed on first access to the Platform, allows you to manage non-essential cookie categories.
11.1 As a data subject under the Data Privacy Act of 2012, you have the following rights with respect to your personal data held by phpg. To exercise any of these rights, submit your request to [email protected] with the subject line "Data Subject Rights Request." phpg will respond within 15 business days of receiving a valid request.
You may request confirmation of whether phpg holds personal data about you, and a copy of that data, along with information about how it is being processed.
You may request correction of any inaccurate or incomplete personal data held by phpg. Some corrections may require re-verification of your identity documents.
You may request deletion of your personal data where it is no longer necessary for the purposes collected and no legal obligation requires its retention. Regulatory retention requirements may limit this right.
You may object to phpg processing your personal data based on legitimate interests, including for marketing purposes. We will cease such processing unless we can demonstrate compelling legitimate grounds.
Where processing is based on consent or contract and carried out by automated means, you may request a machine-readable copy of your personal data for transfer to another service.
You may request that phpg restrict processing of your personal data in certain circumstances, such as while a correction request is being assessed or an objection is under consideration.
11.2 phpg will not charge a fee for processing data subject rights requests unless a request is manifestly unfounded or excessive, in which case phpg may charge a reasonable administrative fee or decline to act on the request, explaining our reasons.
11.3 If you are not satisfied with phpg's response to your data rights request, you have the right to lodge a complaint with the National Privacy Commission of the Philippines.
12.1 phpg does not knowingly collect, use, or retain personal data from individuals below the age of 21. Our registration process includes date-of-birth collection and age verification as a mandatory step, supplemented by KYC document review.
12.2 If a parent or guardian believes that their child below 21 has registered an account with phpg or submitted personal data to the Platform without appropriate authorization, they should contact phpg immediately at [email protected]. phpg will promptly investigate, close any such account, and permanently delete all associated personal data.
13.1 phpg's primary data processing infrastructure is hosted in servers located in the Philippines or in jurisdictions with equivalent data protection standards. Some data processing activities — including game session management by international game studios and KYC verification services — may involve transfer of personal data to recipients outside the Philippines.
13.2 Where personal data is transferred outside the Philippines, phpg ensures that appropriate safeguards are in place as required under the Data Privacy Act of 2012, including:
13.3 By using the phpg Platform and accepting this Privacy Policy, you consent to the transfer of your personal data as described in this Section, subject to the safeguards described above.
14.1 phpg will send you marketing communications — including promotional emails, bonus announcements, and new game alerts — only where you have explicitly opted in to receiving such communications at the time of registration or through your Account settings.
14.2 You may opt out of receiving marketing communications from phpg at any time by:
14.3 Opting out of marketing communications will not affect your ability to use the phpg Platform or receive transactional messages — such as deposit confirmations, withdrawal status updates, account security alerts, and KYC verification requests — that are necessary for the operation of your account.
14.4 phpg does not share your contact details with third-party marketing organizations for the purpose of direct marketing to you on behalf of those organizations.
15.1 The phpg Platform may, from time to time, contain references to or integrations with third-party services — such as game content delivered by external studios — that may have their own privacy policies. phpg is not responsible for the data practices of third-party services, and this Privacy Policy applies only to personal data processed by phpg in connection with the phpg Platform.
15.2 phpg encourages Players to review the privacy policies of any third-party services they interact with. Where a game session is conducted within a third-party game studio's iframe embedded in the phpg Platform, the game studio's own data processing for gameplay purposes is governed by that studio's privacy policy, not this Policy.
16.1 phpg reserves the right to update or revise this Privacy Policy from time to time to reflect changes in our data processing practices, applicable law, regulatory requirements, or the features of the phpg Platform.
16.2 Material changes to this Privacy Policy — meaning changes that significantly affect your rights or phpg's data processing activities — will be communicated to you via email to your registered email address and/or through a prominent notice on the phpg Platform at least 7 days before the revised policy takes effect.
16.3 Minor revisions — including formatting corrections, clarifications, and updates to reflect new payment methods or game providers that do not alter the substance of phpg's data practices — may be published without advance notice.
16.4 The current version of this Privacy Policy is always accessible at phpg.one/privacy-policy. The "Last Revised" date at the top of this Policy reflects the date on which the most recent substantive revision was made. Your continued use of the phpg Platform after the effective date of a revised Privacy Policy constitutes your acceptance of the revised terms.
17.1 phpg has designated a Data Protection Officer (DPO) responsible for overseeing compliance with the Data Privacy Act of 2012 and this Privacy Policy. If you have any questions, concerns, or requests relating to your personal data or this Privacy Policy, you may contact the phpg DPO using the details below:
17.2 phpg will acknowledge receipt of data rights requests and DPO inquiries within 3 business days and will provide a substantive response within 15 business days of receiving a valid, complete request. Complex requests may require additional time; phpg will notify you of any extension and its reason.
17.3 This Privacy Policy is governed by the laws of the Republic of the Philippines. Any disputes relating to this Policy that are not resolved through the phpg complaints process may be submitted to the National Privacy Commission or to the courts of the Philippines with competent jurisdiction.
Your data is protected. Your account is encrypted. Your privacy is respected. Explore phpg — the Philippines' PAGCOR-regulated online casino built for Filipino players.
21+ only. Gambling involves risk. Please play responsibly. phpg is regulated by PAGCOR.