This Privacy Policy explains how phpg collects, uses, stores, and protects your personal information. It is written in plain language wherever possible while meeting the requirements of the Philippine Data Privacy Act of 2012 (Republic Act No. 10173) and PAGCOR's player data obligations.
These summaries highlight phpg's approach to your privacy. The full legal text in each numbered section below governs in all cases — please read the complete policy for your specific questions.
phpg collects personal data that is strictly necessary to operate a PAGCOR-regulated gaming platform — your identity, contact details, payment information, and gaming activity. We do not collect data for its own sake or sell your information to third parties for marketing purposes.
All data transmitted between your device and phpg's servers is protected using 256-bit SSL/TLS encryption — the same standard used by Philippine banks and government payment systems. phpg's infrastructure undergoes regular third-party security audits, and access to personal data is restricted to authorised personnel on a need-to-know basis.
Under the Philippine Data Privacy Act, you have the right to access the personal data phpg holds about you, request corrections, and in certain circumstances, request its deletion. phpg provides clear processes for exercising each of these rights, detailed in Section 10 of this Policy.
phpg shares personal data only where necessary: with PAGCOR to satisfy regulatory reporting obligations, with KYC and payment processing partners to operate the platform, and with law enforcement when required by Philippine law. phpg does not sell, rent, or trade your personal data to advertisers or data brokers.
phpg retains your personal data for as long as your account is active and for the periods required by PAGCOR regulations and Philippine anti-money laundering law. Transaction records are retained for a minimum of five years as required by Republic Act No. 9160 (the Anti-Money Laundering Act). You may request account deletion once all regulatory retention periods have elapsed.
If phpg makes material changes to this Privacy Policy — changes that meaningfully affect how your data is collected, used, or shared — you will be notified via the email address registered on your phpg account at least seven (7) days before the changes take effect. Continued use of phpg after the effective date constitutes acceptance of the updated Policy.
1.1 This Privacy Policy ("Policy") is published by phpg ("phpg", "we", "us", "our"), the operator of the online gaming platform accessible at phpg.asia. phpg is regulated by the Philippine Amusement and Gaming Corporation (PAGCOR).
1.2 This Policy describes how phpg collects, uses, stores, discloses, and protects personal information relating to players and visitors to the phpg platform. It applies to all personal data processing activities conducted by phpg in connection with the operation of phpg.asia and its associated services.
1.3 By registering a phpg account, accessing the platform, or placing a wager, you acknowledge that you have read and understood this Policy and consent to the processing of your personal data as described herein, to the extent such consent is required under applicable Philippine law.
1.4 This Policy is incorporated by reference into phpg's Terms & Conditions. In the event of any conflict between this Policy and the Terms & Conditions, the Terms & Conditions shall prevail unless otherwise specified.
2.1 For the purposes of the Philippine Data Privacy Act of 2012 (Republic Act No. 10173) and its Implementing Rules and Regulations, phpg acts as the Personal Information Controller (PIC) in respect of personal data collected and processed through the phpg platform.
2.2 As Personal Information Controller, phpg is responsible for determining the purposes and means of processing your personal data, and for ensuring that such processing is conducted in a manner compliant with the Data Privacy Act and PAGCOR's applicable directives.
2.3 phpg has designated a Data Protection Officer (DPO) responsible for overseeing the platform's compliance with the Data Privacy Act. Contact details for the phpg DPO are provided in Section 17 of this Policy.
3.1 phpg collects the following categories of personal data in the course of operating its platform:
| Category | Data Elements | When Collected |
|---|---|---|
| Identity Data | Full legal name, date of birth, nationality, government ID number and type (UMID, PhilSys, passport, driver's license), selfie/photograph | KYC verification process |
| Contact Data | Philippine mobile number, email address, residential address | Account registration; KYC |
| Account Data | Username, hashed password, account creation date, account status, session history, login timestamps, device identifiers | Account registration and use |
| Financial Data | GCash account number, Maya account details, bank account details (BPI, BDO, Metrobank), deposit and withdrawal history, transaction amounts, currency, timestamps | Deposit and withdrawal transactions |
| Gaming Activity Data | Games played, bet amounts, win/loss records, session duration, game provider logs, bonus activation and completion records | Ongoing platform use |
| Technical Data | IP address, browser type and version, device type, operating system, screen resolution, referring URL, page navigation data | Automatic collection on platform access |
| Communications Data | Live chat transcripts, support ticket records, email correspondence, feedback submissions | When you contact phpg support |
| Responsible Gaming Data | Deposit limit settings, session reminder preferences, self-exclusion records, cooling-off period activations | When responsible gaming tools are used |
3.2 phpg does not collect sensitive personal information beyond what is strictly required for identity verification and PAGCOR regulatory compliance. phpg does not collect racial or ethnic origin data, political opinions, religious beliefs, health data, or biometric data beyond what is captured in government ID photographs submitted for KYC.
phpg collects personal data through the following methods:
Data you provide directly when: registering your phpg account; completing KYC verification by uploading government ID and a selfie; making a deposit or requesting a withdrawal; contacting phpg customer support via live chat or email; activating responsible gaming tools such as deposit limits or self-exclusion; or participating in phpg promotions and surveys.
Technical and usage data collected automatically when you access phpg.asia, including IP address, device identifiers, browser characteristics, and page interaction data collected through server logs and session tracking technology. This data is collected whether or not you are logged in to a phpg account.
phpg may receive personal data from third-party sources including: payment processors (GCash, Maya, BPI, BDO, and others) when you make transactions; KYC verification providers used to validate identity documents; fraud detection services; and regulatory databases maintained by PAGCOR.
5.1 phpg uses your personal data for the following specific, legitimate purposes:
5.2 phpg does not use your personal data for purposes incompatible with those listed above without first obtaining your explicit consent or as otherwise permitted by the Data Privacy Act.
6.1 phpg processes your personal data on the following legal grounds under the Philippine Data Privacy Act of 2012:
7.1 phpg does not sell, rent, or trade your personal data to third parties. phpg shares personal data with third parties only in the following circumstances:
phpg is required to share player data with PAGCOR as part of its licensing obligations, including transaction reporting, audit cooperation, and player dispute investigations. phpg may also be required to disclose personal data to the Anti-Money Laundering Council (AMLC) and other Philippine government bodies pursuant to applicable law.
phpg shares the minimum necessary personal and financial data with payment processors (GCash, Maya, banks, and other accepted payment platforms) to facilitate your deposits and withdrawals. These providers are contractually bound to use your data only for payment processing purposes.
phpg uses third-party identity verification services to process KYC submissions. These partners receive your identity documents and photographs solely for the purpose of identity verification and are bound by strict data processing agreements.
When you play a game hosted by a third-party provider (such as JILI, Pragmatic Play, or Evolution Gaming), minimal session data is shared with that provider to facilitate game access and result recording. Game providers do not receive your financial or identity data.
phpg will disclose personal data to Philippine law enforcement authorities where required by a valid court order, subpoena, or other lawful process, or where phpg believes in good faith that disclosure is necessary to prevent or investigate criminal activity.
8.1 Some of phpg's third-party service providers — including certain game providers and cloud infrastructure partners — may process personal data outside the Philippines. Where such transfers occur, phpg ensures that adequate safeguards are in place, consistent with the requirements of the Philippine Data Privacy Act and the National Privacy Commission's guidelines on cross-border data transfers.
8.2 Cross-border transfers of personal data by phpg are limited to: (a) providers in countries with equivalent data protection standards; or (b) providers who have entered into data processing agreements incorporating standard contractual clauses acceptable under Philippine law.
8.3 phpg does not transfer KYC documents or government ID data outside the Philippines except to the extent strictly necessary for identity verification services operating under contractual data protection obligations.
9.1 phpg retains your personal data for as long as your phpg account is active and, after account closure, for the periods required by applicable Philippine law and PAGCOR regulations:
9.2 Upon expiry of the applicable retention period, phpg will securely delete or anonymise your personal data. Anonymised, aggregated data (from which individual players cannot be identified) may be retained indefinitely for platform analytics purposes.
10.1 Under the Philippine Data Privacy Act of 2012 and its Implementing Rules and Regulations, you have the following rights in respect of your personal data held by phpg:
Request a copy of the personal data phpg holds about you, and information about how it is processed.
Request correction of inaccurate or incomplete personal data phpg holds about you.
Request deletion of your personal data, where retention is no longer necessary and no legal obligation requires continued storage.
Object to the processing of your personal data for direct marketing or where processing is based on phpg's legitimate interests.
Receive a copy of your personal data in a structured, commonly used, machine-readable format where technically feasible.
Seek indemnity for damages sustained as a result of inaccurate, incomplete, outdated, false, or unlawfully obtained personal data, subject to applicable law.
10.2 How to Exercise Your Rights. To exercise any of the rights described above, contact phpg's Data Protection Officer at the email address stated in Section 17. phpg will respond to verified requests within fifteen (15) business days. Where requests are complex or numerous, phpg may extend this period by an additional thirty (30) days with prior notice.
10.3 Identity Verification. To protect your privacy, phpg will require identity verification before processing any data rights request. This is to ensure that personal data is not disclosed to, amended by, or deleted at the request of an unauthorised person.
10.4 Regulatory Escalation. If you are not satisfied with phpg's response to a data rights request, you have the right to lodge a complaint with the National Privacy Commission of the Philippines.
11.1 phpg uses cookies and similar tracking technologies on its platform. Cookies are small text files stored on your device that allow phpg to recognise your browser, maintain your login session, and improve your experience on the platform.
11.3 phpg does not use third-party advertising cookies or tracking pixels that would share your browsing data with advertising networks. phpg's cookies are limited to operational and security purposes.
11.4 You may manage cookie preferences through your browser's settings. Note that disabling strictly necessary cookies will impair phpg's functionality and may prevent you from accessing your account or playing games.
12.1 phpg's services are intended exclusively for adults aged 21 years and above, consistent with PAGCOR's minimum age requirement for online casino gaming in the Philippines. phpg does not knowingly collect personal data from persons under the age of 21.
12.2 If phpg becomes aware that personal data has been collected from a person under 21 years of age, that account will be immediately suspended, the data will be deleted in accordance with applicable law, and any balances associated with the underage account will be handled in accordance with PAGCOR's requirements.
12.3 If you believe that a person under 21 has registered a phpg account, please contact phpg's support team immediately at the contact details provided in Section 17.
13.1 phpg implements appropriate technical and organisational measures to protect your personal data against unauthorised access, alteration, disclosure, or destruction. These measures include:
13.2 Whilst phpg implements robust security measures, no internet-based platform can guarantee absolute security. You are responsible for maintaining the security of your own phpg login credentials, enabling two-factor authentication, and reporting any suspected unauthorised access to your account promptly.
14.1 In the event of a personal data breach that is likely to result in a risk to the rights and freedoms of affected players, phpg will comply with its notification obligations under the Philippine Data Privacy Act and the National Privacy Commission's Circular on Personal Data Breach Management.
14.2 Notification to Regulators: phpg will notify the National Privacy Commission within 72 hours of becoming aware of a breach that meets the threshold for mandatory notification, as specified under applicable NPC guidelines.
14.3 Notification to Affected Players: Where a breach poses a high risk to the rights and freedoms of specific players, phpg will notify those players directly via the email address on their registered account within a reasonable period following discovery, providing information about the nature of the breach, the data affected, the likely consequences, and the measures taken or proposed.
15.1 phpg's privacy practices are designed to comply with Republic Act No. 10173, the Data Privacy Act of 2012, and its Implementing Rules and Regulations issued by the National Privacy Commission. phpg has registered with the National Privacy Commission as a Personal Information Controller where required.
15.2 phpg has adopted a Privacy Management Programme consistent with the NPC's Privacy Management Programme Framework, covering privacy governance, privacy risk assessment, privacy impact assessments for new data processing activities, and staff privacy training.
15.3 In the event of any conflict between this Policy and the requirements of Republic Act No. 10173, the requirements of the Data Privacy Act shall prevail.
16.1 phpg reserves the right to update or amend this Privacy Policy at any time to reflect changes in its data processing practices, applicable law, or PAGCOR regulatory requirements. The current version of this Policy will always be accessible at phpg.asia/privacy-policy.
16.2 Material amendments — those that meaningfully alter how your personal data is collected, used, or shared — will be communicated to you via email at the address registered on your phpg account at least seven (7) days before the amended Policy takes effect.
16.3 Continued use of the phpg platform after the effective date of any amendment constitutes your acceptance of the revised Policy. If you do not accept the revised Policy, you must cease using phpg and may request account closure in accordance with phpg's Terms & Conditions.
17.1 For any privacy-related queries, data rights requests, or concerns regarding phpg's handling of your personal data, you may contact phpg's Data Protection Officer through the following channels:
17.2 phpg will acknowledge privacy enquiries within two (2) business days and aim to resolve them within fifteen (15) business days, consistent with the timelines required by the National Privacy Commission.
17.3 If you are not satisfied with phpg's response to a privacy complaint, you have the right to lodge a complaint directly with the National Privacy Commission of the Philippines.
Create your phpg account with confidence. Your personal data is protected under the Philippine Data Privacy Act, and your funds sit in PAGCOR-regulated segregated accounts. 700+ games await — from JILI slots to live baccarat.
Create Your phpg Account21+ Casino gaming is strictly for adults. PAGCOR-regulated. Play responsibly.