🔒 Data Protection — Effective 1 January 2026

phppone Privacy Policy

This Privacy Policy explains how phppone collects, processes, stores, and protects the personal information of Players and visitors on the phppone platform. We are committed to handling your data lawfully, transparently, and in accordance with the Philippine Data Privacy Act of 2012 (Republic Act No. 10173) and relevant PAGCOR data governance requirements.

Last updated: 1 January 2026  ·  Applies to all phppone services accessible at phppone.app

How phppone Approaches Your Personal Data

These six cards summarise phppone's core data protection commitments. They do not replace the full Privacy Policy below — please read the complete document.

Data Collected Only as Needed

phppone collects personal data strictly for purposes related to account registration, identity verification, payment processing, legal compliance, and platform improvement. We do not collect data we have no reason to hold, and we do not retain it longer than necessary.

Encrypted and Secured Storage

All personal data stored by phppone is protected using industry-standard encryption. Sensitive fields — including passwords, payment card references, and government ID numbers — are stored using irreversible hashing or tokenisation. phppone conducts regular security audits on its data infrastructure.

Your Rights Under Philippine Law

As a Filipino data subject, you have rights under RA 10173 — including the right to access your personal data, correct inaccuracies, object to processing, and request deletion where legally permitted. phppone honours all data subject requests within 15 business days.

Limited Third-Party Sharing

phppone shares your personal data only with trusted service providers who support platform operations — payment processors, identity verification partners, and fraud prevention services — under strict data processing agreements. We do not sell your data to third parties.

Cookies and Session Data

phppone uses cookies and similar technologies to maintain your login session, remember preferences, and improve platform performance. You may manage or decline non-essential cookies through your browser settings. Essential cookies required for login and security cannot be disabled.

Marketing Opt-Out Available

phppone sends promotional communications only to Players who have opted in during registration or subsequently through account settings. You may unsubscribe from marketing emails or SMS at any time via your account notification preferences without affecting your access to the platform.

Section 01

Data Controller

phppone is the data controller responsible for the personal information collected from Players and visitors through the phppone platform at phppone.app. As data controller, phppone determines the purposes for which and the means by which personal data is processed.

phppone processes personal data in compliance with Republic Act No. 10173, the Data Privacy Act of 2012 of the Philippines, its implementing rules and regulations, and the applicable data governance requirements of the Philippine Amusement and Gaming Corporation (PAGCOR). All data processing activities are conducted within the framework established by the National Privacy Commission (NPC) of the Philippines.

Contact for data matters: All data subject requests, privacy concerns, and inquiries relating to this Policy should be directed to the phppone Data Protection Officer at [email protected] with the subject line "Data Privacy Request." Requests are acknowledged within two (2) business days and resolved within fifteen (15) business days.
Section 02

What Personal Data phppone Collects

phppone collects personal data across several categories depending on your interaction with the platform. The table below summarises the categories of data collected and the primary purpose of each.

Data Category Examples Primary Purpose
Identity Data Full legal name, date of birth, nationality, government ID number and type Account registration, KYC age and identity verification, PAGCOR compliance
Contact Data Email address, Philippine mobile number, residential address Account communication, OTP delivery, withdrawal confirmations, support
Financial Data GCash number, PayMaya account, bank account name and number (BDO, BPI, Metrobank) Deposit processing, withdrawal routing, fraud prevention
Account & Gaming Data Username, transaction history, bet history, session durations, game preferences Account management, responsible gaming monitoring, bonus eligibility
Technical Data IP address, device type, browser type and version, operating system, time zone Fraud detection, geolocation compliance, session security
KYC Documentation Copies of government-issued Philippine ID, proof of address, selfie images where required Identity verification, PAGCOR compliance, anti-money laundering
Communications Data Live chat transcripts, email correspondence with phppone support Dispute resolution, training, quality assurance, legal record-keeping

phppone does not collect sensitive personal information as defined under RA 10173 — such as biometric data, religious or political views, or health data — except where a Player voluntarily discloses health information in the context of requesting a responsible gaming accommodation (e.g., self-exclusion based on a problem gaming concern).

Section 03

How phppone Collects Your Data

phppone collects personal data through the following means:

  • Direct collection: Information you provide when you register for a phppone account, complete KYC verification, make deposits or withdrawals, contact support, or participate in promotions.
  • Automated collection: Technical data collected automatically when you access the phppone platform, including IP address, device identifiers, session tokens, and cookies placed during browsing and gameplay.
  • Third-party sources: Identity verification data returned by phppone's KYC and fraud-screening partners when processing your submitted documents; payment status data received from GCash, PayMaya, and banking partners during transaction processing.
  • Publicly available sources: In limited circumstances and where legally permitted, phppone may cross-reference publicly available records to verify account information or investigate suspected fraud.
Section 04

Legal Bases for Processing Personal Data

phppone processes personal data on the following legal bases under RA 10173 and its implementing rules:

  • Contractual necessity: Processing required to register your phppone account, process deposits and withdrawals, manage gameplay, and fulfil obligations under the phppone Terms & Conditions.
  • Legal obligation: Processing required to comply with PAGCOR regulations, Philippine anti-money laundering law (AMLA), and other applicable legal and regulatory requirements — including KYC verification and transaction monitoring.
  • Legitimate interests: Processing carried out for fraud detection, platform security, responsible gaming monitoring, and abuse prevention, where phppone's interests do not override your rights.
  • Consent: Processing for marketing communications, optional platform personalisation, and any other purposes where phppone has specifically sought and received your consent at the point of collection.
Where processing is based on your consent, you have the right to withdraw that consent at any time by updating your account notification preferences or by contacting the phppone Data Protection Officer. Withdrawal of consent does not affect the lawfulness of processing carried out before the withdrawal.
Section 05

How phppone Uses Your Personal Data

phppone processes your personal data for the following specific purposes:

  • Creating, verifying, and maintaining your phppone account, including enforcing the one-account-per-player policy.
  • Processing deposits and withdrawals via GCash, PayMaya, BDO, BPI, Metrobank, and other supported payment channels.
  • Conducting KYC age verification and identity confirmation before processing your first withdrawal, in compliance with PAGCOR requirements.
  • Detecting, investigating, and preventing fraudulent transactions, multi-accounting, bonus abuse, and other prohibited activities.
  • Monitoring gameplay and account activity for responsible gaming purposes, including identifying Players who may be displaying indicators of problem gambling behaviour.
  • Complying with PAGCOR reporting requirements and Philippine anti-money laundering obligations, including transaction monitoring and suspicious activity reporting where required by law.
  • Communicating with you regarding account activity, withdrawal status, KYC requests, security alerts, and platform updates.
  • Sending promotional communications regarding phppone bonuses, new games, and events — only to Players who have opted in to marketing.
  • Improving and personalising the phppone platform based on aggregated and anonymised usage analytics.
  • Resolving disputes and providing customer support via live chat and email.
Section 06

How phppone Shares Your Personal Data

phppone does not sell your personal data to any third party. Your personal information is shared only in the following circumstances and with the following categories of recipients:

  • Payment processors: GCash (Mynt/Globe Fintech), Maya Philippines (PayMaya), BDO Unibank, Bank of the Philippine Islands (BPI), and Metrobank receive transaction data required to process deposits and withdrawals. These institutions are independently regulated under Philippine financial law.
  • Identity verification and fraud screening partners: Third-party KYC service providers receive copies of your submitted identification documents and associated personal data to perform identity verification and fraud risk assessments on phppone's behalf.
  • Game studio providers: Where you play third-party games on the phppone platform, your username, session tokens, and bet data are passed to the relevant licensed game provider's systems to facilitate gameplay. These providers operate under certified gaming licences and independent data processing agreements.
  • Regulatory authorities: PAGCOR and, where required by Philippine law, the Anti-Money Laundering Council (AMLC) and other competent authorities may receive personal data as required for regulatory oversight, reporting obligations, and law enforcement.
  • Legal and professional advisers: In connection with legal proceedings, dispute resolution, or compliance advice, phppone may share relevant personal data with legal counsel, auditors, or professional advisers, subject to confidentiality obligations.

All third-party data processors engaged by phppone are required to handle personal data in compliance with applicable Philippine privacy law and under written data processing agreements that restrict the use of your data to the purposes for which it was shared.

Section 07

Data Retention

phppone retains personal data for as long as is necessary to fulfil the purposes outlined in this Policy, subject to the following minimum retention periods:

Data Type Retention Period Basis
Account registration data Duration of account + 5 years post-closure PAGCOR regulatory requirement
KYC documents 5 years from submission date AMLA and PAGCOR compliance
Financial transaction records 5 years from transaction date AMLA / Philippine tax law
Gameplay and bet history 3 years from account closure or last activity Dispute resolution / regulatory reporting
Support communications 3 years from the date of communication Legitimate interests / dispute evidence
Marketing consent records Duration of consent + 3 years RA 10173 accountability obligation
Technical/log data 12 months from collection Security monitoring, fraud detection

Upon expiry of the applicable retention period, personal data is securely deleted or anonymised in accordance with phppone's internal data disposal procedures. Where deletion is not technically feasible within system infrastructure, data is isolated and restricted from further active processing pending scheduled deletion.

Section 08

Cookies & Tracking Technologies

phppone uses cookies and similar tracking technologies (such as local storage tokens and session identifiers) to operate the platform, maintain login sessions, apply your preferences, and support security functions.

phppone uses the following categories of cookies:

  • Essential cookies: Required for the phppone platform to function correctly. These include session management cookies that keep you logged in, security tokens that prevent cross-site request forgery, and load-balancing cookies. Essential cookies cannot be disabled without preventing access to the platform.
  • Functional cookies: Store your preferences such as language settings, displayed currency, and notification preferences so that the platform remembers your choices between sessions.
  • Analytics cookies: Used by phppone to understand aggregated platform usage patterns — such as which game categories are most visited and where players encounter navigation difficulties — in order to improve the platform. Analytics data is processed at the aggregate level and is not linked to individual Player identities for this purpose.
  • Security cookies: Used to detect and prevent fraudulent account access, including device fingerprinting components that identify known devices associated with your account.

You may manage functional and analytics cookies through your browser's cookie settings. Clearing or blocking cookies may affect platform functionality, including your ability to remain logged in between browser sessions.

Section 09

Data Security Measures

phppone implements technical and organisational measures to protect personal data against unauthorised access, disclosure, alteration, and destruction. These measures include:

  • 256-bit SSL/TLS encryption applied to all data transmitted between your browser and phppone's servers, including login pages, deposit flows, and account settings.
  • At-rest encryption for all stored personal data, including KYC documents, financial references, and contact details.
  • Hashed and salted storage of account passwords — phppone does not store or transmit passwords in plain text at any point.
  • Role-based access controls limiting which phppone staff members can access which categories of personal data, restricted to the minimum necessary for their job functions.
  • Automated intrusion detection systems and real-time alerting for unusual access patterns or suspicious login behaviour.
  • Regular penetration testing and third-party security audits of phppone's data infrastructure.
  • Employee data privacy training for all staff who handle personal data as part of their role.

In the event of a personal data breach that is likely to result in risk to your rights, phppone will notify the National Privacy Commission (NPC) of the Philippines within 72 hours of becoming aware of the breach, and will notify affected data subjects without undue delay, in accordance with RA 10173's breach notification requirements.

Section 10

Your Rights as a Data Subject

Under the Philippine Data Privacy Act of 2012 (RA 10173), you have the following rights with respect to your personal data held by phppone:

Right to Access

Request a copy of the personal data phppone holds about you, the purposes for which it is processed, and the third parties with whom it has been shared.

Right to Rectification

Request correction of inaccurate or incomplete personal data. Account profile information may be updated directly through account settings.

Right to Erasure

Request deletion of your personal data where phppone no longer has a lawful basis to retain it. Note that regulatory retention obligations may prevent immediate deletion of some categories of data.

Right to Object

Object to the processing of your personal data for direct marketing purposes at any time. You may also object to processing based on legitimate interests, subject to phppone's ability to demonstrate compelling grounds.

Right to Data Portability

Request a structured, machine-readable copy of personal data you have provided to phppone, where processing is based on consent or contract.

Right to Withdraw Consent

Withdraw consent for any processing based on consent — including marketing communications — at any time, without affecting the lawfulness of prior processing.

To exercise any of the above rights, submit a written request to the phppone Data Protection Officer at [email protected] with the subject line "Data Subject Rights Request." Include your registered phppone username and a description of the right you wish to exercise. phppone may request identity verification before processing your request. Requests are responded to within 15 business days.

If you are not satisfied with phppone's response to your data subject request, you have the right to lodge a complaint with the National Privacy Commission of the Philippines.

Section 11

Children & Under-Age Players

The phppone platform is strictly restricted to individuals who are at least 21 years of age, in compliance with PAGCOR regulations. phppone does not knowingly collect personal data from individuals under the age of 21.

Age is a mandatory field at registration and is verified against government-issued identification during KYC. If phppone discovers or receives credible information that a Player is under the age of 21, the account will be closed immediately, all funds will be forfeited in accordance with the phppone Terms & Conditions, and any personal data collected from the under-age individual will be securely deleted unless retention is required by law.

If you believe an under-age individual has created a phppone account, please contact phppone support immediately at [email protected] with relevant details. phppone takes under-age access seriously and will act on credible reports without delay.
Section 12

Changes to This Privacy Policy

phppone may update this Privacy Policy from time to time to reflect changes in our data processing practices, regulatory requirements, or platform features. Material changes — those that affect how your personal data is used or your rights as a data subject — will be communicated to registered Players via email to the registered account address and via a platform notification, at least seven (7) days before the change takes effect.

Non-material changes (such as clarifications of existing practices, corrections of typographical errors, or updated contact details) may be made without prior notice and will be indicated by an updated "Last Updated" date at the top of this document.

Your continued use of the phppone platform following the effective date of any update to this Privacy Policy constitutes your acknowledgement of the revised Policy. If you have concerns about a change, contact the Data Protection Officer before the effective date.

Section 13

Contact the phppone Data Protection Officer

For all privacy-related matters, data subject requests, consent withdrawals, and questions about this Privacy Policy, please contact the phppone Data Protection Officer using the following channels:

  • Email: [email protected] — use subject line "Data Privacy Request" or "DPO Inquiry" for routing. Written responses are provided within 2 business days (acknowledgement) and 15 business days (resolution).
  • Live Chat: Available 24/7 on the phppone platform. For initial privacy queries, account notification changes, and marketing opt-outs, live chat is the fastest channel. Support is available in English and Filipino (Tagalog).
This Privacy Policy was last reviewed and updated on 1 January 2026. By using the phppone platform, you confirm that you have read this Privacy Policy and acknowledge phppone's data processing practices as described herein. This Policy is to be read alongside the phppone Terms & Conditions and Responsible Gaming policy.

Play with Confidence on phppone

PAGCOR-regulated, RA 10173-compliant, 256-bit encrypted, and built for Filipino players. Must be 21 or older to register.