Data Privacy · NPC Compliant · RA 10173

philwin Privacy Policy

This Privacy Policy explains how philwin collects, uses, stores, and protects your personal data when you use our platform. We are committed to handling your information responsibly and transparently, in full compliance with the Republic Act No. 10173 (Data Privacy Act of 2012) and the regulations of the National Privacy Commission of the Philippines.

Effective Date: 1 January 2026 Last Updated: 1 January 2026 Jurisdiction: Philippines Regulator: NPC & PAGCOR

How philwin Protects
Your Personal Information

🔒 Core Commitment
RA 10173 Compliance

philwin processes all personal data strictly in accordance with Republic Act No. 10173 — the Data Privacy Act of 2012 — and the implementing rules and issuances of the National Privacy Commission (NPC) of the Philippines. Your data rights are legally protected.

🔐 Security
256-Bit SSL Encryption

All data transmitted between your device and philwin's servers is protected using 256-bit SSL/TLS encryption — the same standard used by Philippine banks. Sensitive data at rest, including payment details and identity documents, is stored using industry-standard encryption protocols.

No Data Selling

philwin does not sell, rent, or trade your personal data to third parties for their marketing purposes. Any sharing of data with third parties is limited strictly to what is necessary for platform operation, legal compliance, or service delivery — and only with parties under binding data processing agreements.

Your Rights Under RA 10173

As a data subject under Philippine law, you have the right to access, correct, delete, and object to the processing of your personal data. philwin provides clear mechanisms for exercising each of these rights, detailed fully in this Privacy Policy.

Minimal Collection
Data Minimization

philwin collects only the personal data that is genuinely necessary for the purposes stated in this Policy. We do not request data beyond what is required for account management, legal compliance, or service delivery. Unnecessary data is not retained beyond its required period.

PAGCOR & AML Compliance

As a PAGCOR-licensed operator, philwin is legally required to verify player identities and maintain transaction records under the Anti-Money Laundering Act (RA 9160). Data collected for these purposes is handled under strict regulatory frameworks and retention schedules.

Effective 1 January 2026. This Privacy Policy supersedes all prior versions. Continued use of philwin after this date constitutes acceptance of this Policy.
1

Introduction

philwin ("philwin," "we," "us," or "our") operates the online gaming platform accessible at philwin.one. We are a PAGCOR-licensed online casino and sportsbook serving Filipino players across the Philippines. This Privacy Policy ("Policy") describes how philwin collects, uses, discloses, stores, and protects your personal information when you access or use our Platform, create an account, make a transaction, or otherwise interact with our services.

This Policy is issued in compliance with Republic Act No. 10173, otherwise known as the Data Privacy Act of 2012 ("DPA"), its Implementing Rules and Regulations ("IRR"), and the applicable issuances of the National Privacy Commission (NPC) of the Philippines. philwin is registered as a personal information controller with the NPC as required under applicable regulations.

By registering an account on philwin or using any part of the Platform, you acknowledge that you have read and understood this Privacy Policy and consent to the collection and use of your personal data as described herein. If you do not agree to this Policy, please do not register or continue using the Platform.

This Policy should be read together with philwin's Terms and Conditions, which govern your overall use of the Platform and are incorporated herein by reference.

2

Data Controller Information

For the purposes of the Data Privacy Act of 2012 and this Policy, philwin acts as the Personal Information Controller (PIC) in respect of the personal data it collects from players and website visitors. As PIC, philwin determines the purposes for which and the means by which personal data is processed.

Where philwin engages third-party service providers — such as payment processors, KYC verification services, and game technology providers — to process personal data on its behalf, those third parties act as Personal Information Processors (PIPs) and are bound by contractual data processing agreements that require them to maintain the same standards of data protection required under Philippine law.

philwin has designated a Data Protection Officer (DPO) as required by NPC regulations. The DPO oversees philwin's data protection program, ensures compliance with the DPA, and serves as the primary point of contact for data subjects exercising their rights. Contact details for the DPO are provided in Section 15 of this Policy.

3

Personal Data We Collect

philwin collects personal data only to the extent necessary for the lawful purposes described in this Policy. The categories of personal data we collect include:

Category Examples When Collected
Identity Data Full name, date of birth, gender, nationality, government ID numbers (UMID, PhilSys, passport, driver's license) Registration & KYC verification
Contact Data Mobile number (+63 format), email address, residential address Registration
Financial Data GCash / Maya account reference, bank account identifiers (for withdrawal verification), transaction amounts and timestamps Deposits, withdrawals, KYC
Technical Data IP address, device type, browser, operating system, session tokens, login timestamps Platform access
Usage Data Games played, bets placed, bet amounts, win/loss history, session duration, feature interactions Ongoing platform use
Verification Documents Scanned or photographed copies of government-issued IDs, selfies or liveness verification images KYC process
Communications Data Live chat transcripts, email correspondence, support ticket content When you contact support
Responsible Gaming Data Self-imposed limits, cooling-off or self-exclusion elections, problem gambling indicators When tools are used
philwin does not collect sensitive personal information beyond what is strictly required for KYC compliance. We do not collect data on religious beliefs, political opinions, health records (outside responsible gaming context), or sexual orientation.
4

How We Collect Your Data

philwin collects personal data through the following means:

  1. Directly from you — when you register an account, complete KYC verification, make a deposit or withdrawal, submit a support request, participate in a promotion, or communicate with philwin through any channel.
  2. Automatically through technology — when you access the Platform, technical data such as your IP address, device information, browser type, and session activity is automatically recorded through cookies, server logs, and similar technologies. See Section 9 for more on cookies.
  3. From third-party service providers — philwin may receive data from KYC verification partners, payment processors, and fraud prevention services in the course of processing your transactions or verifying your identity. All such partners are bound by data processing agreements and applicable Philippine law.
  4. From publicly available sources — in limited circumstances for fraud prevention or regulatory compliance purposes, philwin may cross-reference data against publicly available Philippine government databases or watchlists (e.g., AMLC or PDEA-related compliance checks).
5

Purposes of Processing

philwin processes your personal data for the following purposes:

  • Account registration and management: Creating and maintaining your philwin account, verifying your identity, and managing your profile and preferences.
  • Age and eligibility verification: Confirming that you meet the mandatory 21+ age requirement under PAGCOR regulations before allowing access to gaming services.
  • Transaction processing: Processing deposits, withdrawals, and related financial transactions through GCash, Maya, BPI, BDO, and other supported payment methods.
  • KYC and anti-money laundering compliance: Fulfilling our legal obligations under Republic Act No. 9160 (Anti-Money Laundering Act) and PAGCOR's Know Your Customer requirements.
  • Fraud prevention and security: Detecting, investigating, and preventing fraudulent activity, account takeovers, and other security threats.
  • Platform operation and improvement: Analyzing usage patterns to improve game selection, platform performance, user experience, and technical reliability.
  • Customer support: Responding to inquiries, resolving disputes, and providing assistance through live chat, email, and other support channels.
  • Responsible gaming: Monitoring gaming behavior to identify potential problem gambling indicators, administering self-exclusion requests, and implementing player-elected limits in compliance with PAGCOR's responsible gaming framework.
  • Promotions and loyalty programs: Administering bonuses, cashback offers, VIP tier benefits, and other promotional activities — where you have not opted out of marketing communications.
  • Legal and regulatory compliance: Meeting our obligations under Philippine law, PAGCOR licensing conditions, NPC regulations, and responding to lawful requests from government authorities.
6

Legal Basis for Processing

Under the Data Privacy Act of 2012, philwin relies on the following lawful bases for processing your personal data:

  • Consent (Section 13(a), DPA): Where you have given your freely given, specific, informed, and unambiguous consent to processing — for example, for marketing communications or optional data collection beyond what is required for platform operation. You may withdraw consent at any time without affecting the lawfulness of prior processing.
  • Contractual necessity (Section 13(b), DPA): Processing necessary for the performance of the contract between you and philwin — specifically, to provide the gaming services you have registered for, process your transactions, and manage your account.
  • Legal obligation (Section 13(c), DPA): Processing required to comply with Philippine law, including PAGCOR licensing requirements, the Anti-Money Laundering Act, the Data Privacy Act itself, and tax obligations.
  • Legitimate interests (Section 13(f), DPA): Processing necessary for the legitimate interests of philwin or third parties — including fraud prevention, platform security, and service improvement — where such interests are not overridden by your rights and freedoms as a data subject.
7

Sharing Your Personal Data

philwin does not sell your personal data to third parties. We share personal data only in the circumstances described below, and only to the extent strictly necessary:

  • Payment processors: GCash (GXI), Maya, GrabPay, BPI, BDO, Metrobank, and other payment service providers receive transaction data necessary to process deposits and withdrawals.
  • KYC and identity verification providers: Third-party identity verification services receive identity documents and biometric data for KYC compliance purposes. All providers are bound by NPC-compliant data processing agreements.
  • Game technology providers: Game Providers (such as JILI, PG Soft, and Evolution) receive a technical player identifier and session data necessary to deliver games. No sensitive personal data is shared with Game Providers beyond what is technically necessary.
  • Regulatory authorities: PAGCOR, the Anti-Money Laundering Council (AMLC), the National Privacy Commission (NPC), the Bureau of Internal Revenue (BIR), and other competent Philippine government authorities may receive data where legally required or pursuant to a valid legal order.
  • Fraud prevention services: Industry fraud prevention networks may receive limited transactional and identity data where necessary to protect philwin and its players from fraud and financial crime.
  • Professional advisors: Legal counsel, auditors, and other professional service providers may access personal data under obligations of professional confidentiality where necessary to obtain advice or conduct audits.
All third-party recipients of personal data are required to maintain appropriate technical and organizational security measures and to process data only for the specified purpose and in accordance with applicable Philippine data protection law.
8

Data Retention

philwin retains personal data only for as long as is necessary to fulfil the purposes for which it was collected, or as required by applicable law. The following general retention periods apply:

Data Category Retention Period Basis
Account and identity data Duration of account + 5 years after closure PAGCOR license, AML Act
Transaction and financial data 5 years from transaction date RA 9160 (AML Act), BIR requirements
KYC documents 5 years from account closure PAGCOR and AMLC requirements
Customer support communications 3 years from last interaction Legitimate interests (dispute resolution)
Technical and usage data 13 months from collection Security, analytics
Marketing preferences Until consent withdrawn or account closed Consent
Self-exclusion records Indefinitely (or as specified in request) Player protection obligation

Upon expiry of the applicable retention period, personal data is securely deleted or anonymized in accordance with NPC guidance on data disposal. Where data cannot be immediately deleted due to legal hold requirements, it is segregated and access-restricted pending lawful disposal.

9

Cookies & Tracking Technologies

philwin uses cookies and similar tracking technologies — including session tokens, local storage, and analytics pixels — to operate the Platform, maintain session security, and analyze user behavior for service improvement purposes.

The following types of cookies are used on the philwin Platform:

  • Strictly Necessary Cookies: Essential for platform functionality, including maintaining your login session, load balancing, and security features. These cannot be disabled without impairing core platform functionality.
  • Functional Cookies: Store your language, game, and display preferences to provide a personalized experience across sessions.
  • Analytics Cookies: Used to understand how players interact with the Platform — including which games are played, how long sessions last, and which features are used most. Data is aggregated and pseudonymized.
  • Security Cookies: Used for fraud detection, bot prevention, and account security, including session integrity validation and suspicious activity detection.

philwin does not use third-party advertising or behavioral tracking cookies for the purpose of serving targeted advertising on external websites. You may manage cookie preferences through your browser settings. Note that disabling strictly necessary cookies may prevent access to some Platform features.

10

Security Measures

philwin implements appropriate technical and organizational measures to protect your personal data against unauthorized access, disclosure, alteration, loss, or destruction. Our security measures include, but are not limited to:

  • Encryption in transit: All data exchanged between your device and philwin's servers is encrypted using TLS 1.2 or higher (256-bit SSL).
  • Encryption at rest: Sensitive data — including identity documents, payment references, and authentication credentials — is encrypted at rest using AES-256 or equivalent standards.
  • Access controls: Access to personal data is restricted on a strict need-to-know basis. philwin staff access is controlled through role-based permissions, multi-factor authentication, and comprehensive audit logging.
  • Two-factor authentication (2FA): philwin offers SMS-based OTP as a second authentication factor for all player accounts. Players are strongly encouraged to enable 2FA.
  • Intrusion detection and monitoring: philwin employs 24/7 automated monitoring for anomalous activity, potential data breaches, and unauthorized system access attempts.
  • Regular security assessments: philwin conducts regular vulnerability assessments and penetration testing of its platform infrastructure.
  • Data breach procedures: In the event of a personal data breach, philwin will notify the NPC and affected data subjects within the timeframes prescribed by the DPA and NPC regulations, where required by law.
Your Role in Security: While philwin takes all reasonable technical precautions, the security of your account also depends on your actions. Use a strong, unique password, enable 2FA, and never share your login credentials with anyone. Report any suspected unauthorized account activity to philwin support immediately.
11

Your Rights as a Data Subject

Under the Data Privacy Act of 2012, you have the following rights in relation to your personal data held by philwin. philwin will respond to all valid rights requests within the timeframes prescribed by NPC regulations:

Right to Access

Request a copy of the personal data philwin holds about you and information on how it is being processed.

Right to Rectification

Request correction of inaccurate or incomplete personal data in your philwin account.

Right to Erasure

Request deletion of personal data where it is no longer necessary for its original purpose, subject to legal retention obligations.

Right to Object

Object to processing based on legitimate interests or for direct marketing purposes at any time.

Right to Portability

Receive a copy of data you provided to philwin in a structured, machine-readable format.

Right to Withdraw Consent

Withdraw consent to processing at any time, without affecting the lawfulness of prior processing based on that consent.

To exercise any of these rights, please contact philwin's Data Protection Officer via the contact details in Section 15. Requests will be acknowledged within five (5) business days and substantively responded to within fifteen (15) business days, extendable by a further fifteen (15) days for complex requests with prior notification. Identity verification will be required before processing any rights request to prevent unauthorized disclosure. If you are unsatisfied with philwin's response to your request, you have the right to lodge a complaint with the National Privacy Commission.

12

Children's Privacy

philwin is strictly an adults-only platform. In compliance with PAGCOR's mandatory minimum age requirement, the Platform is accessible only to individuals who are 21 years of age or older. philwin does not knowingly collect personal data from persons under 21 years of age.

Where philwin discovers or has reasonable grounds to suspect that an account has been registered by a person under 21 years of age, it will immediately suspend the account, cease processing the minor's personal data, delete such data to the extent not required to be retained for regulatory or legal compliance purposes, and report the matter to PAGCOR as required by our licensing obligations.

If you are the parent or legal guardian of a person you believe has registered on philwin while under 21 years of age, please contact philwin's Data Protection Officer immediately with the relevant account details.

13

Cross-Border Data Transfers

Some of philwin's service providers — including cloud infrastructure providers and game technology companies — may process personal data in locations outside the Philippines. Where personal data is transferred outside the Philippines, philwin ensures that appropriate safeguards are in place to provide an equivalent level of data protection to that required under the DPA, including:

  • Contractual clauses that impose DPA-equivalent data protection obligations on the recipient.
  • Processing only by recipients located in countries or jurisdictions that have been recognized by the NPC as providing adequate data protection standards.
  • Other appropriate safeguards approved by the NPC for cross-border transfers.

philwin will not transfer personal data to a country or territory that does not provide adequate data protection safeguards unless required by Philippine law or pursuant to your explicit consent with full awareness of the associated risks.

14

Changes to This Privacy Policy

philwin reserves the right to update or amend this Privacy Policy from time to time to reflect changes in applicable law, NPC guidance, PAGCOR requirements, or our data processing practices. When material changes are made, philwin will notify registered players via their registered email address or through an on-Platform notification prior to the changes taking effect.

The updated Policy will be published on the Platform with a revised effective date. Continued use of the philwin Platform following the effective date of any revision constitutes your acceptance of the revised Policy. We encourage you to review this Policy periodically to stay informed about how we protect your personal data.

If a proposed change would materially alter how we use personal data collected under a prior consent, we will seek fresh consent from affected data subjects before the change takes effect.

15

Contact & Data Protection Officer

For any questions, concerns, or requests relating to this Privacy Policy or the processing of your personal data by philwin, please contact our Data Protection Officer using the following channels:

DPO Email
Mark subject: "Privacy / DPO Request"
Live Chat Support
24/7 inside the Platform
For urgent account security matters
Response Time
Within 5 business days
For all formal privacy requests
Regulator
National Privacy Commission (NPC)
Philippines — for unresolved complaints

This Privacy Policy was last reviewed and published on 1 January 2026. philwin is committed to transparency in how we handle your data and welcomes any questions you may have about our privacy practices.

Your Data Is Safe at philwin.
So Is Your Game.

philwin is built on a foundation of security, transparency, and PAGCOR-licensed accountability. Your personal data is protected by Philippine law, processed only for legitimate purposes, and never sold. Sign in and play with confidence — 21+ Filipino players only.

PAGCOR Licensed NPC Compliant 256-bit SSL 21+ Only