Data Privacy · NPC Compliant · RA 10173
This Privacy Policy explains how philwin collects, uses, stores, and protects your personal data when you use our platform. We are committed to handling your information responsibly and transparently, in full compliance with the Republic Act No. 10173 (Data Privacy Act of 2012) and the regulations of the National Privacy Commission of the Philippines.
philwin processes all personal data strictly in accordance with Republic Act No. 10173 — the Data Privacy Act of 2012 — and the implementing rules and issuances of the National Privacy Commission (NPC) of the Philippines. Your data rights are legally protected.
All data transmitted between your device and philwin's servers is protected using 256-bit SSL/TLS encryption — the same standard used by Philippine banks. Sensitive data at rest, including payment details and identity documents, is stored using industry-standard encryption protocols.
philwin does not sell, rent, or trade your personal data to third parties for their marketing purposes. Any sharing of data with third parties is limited strictly to what is necessary for platform operation, legal compliance, or service delivery — and only with parties under binding data processing agreements.
As a data subject under Philippine law, you have the right to access, correct, delete, and object to the processing of your personal data. philwin provides clear mechanisms for exercising each of these rights, detailed fully in this Privacy Policy.
philwin collects only the personal data that is genuinely necessary for the purposes stated in this Policy. We do not request data beyond what is required for account management, legal compliance, or service delivery. Unnecessary data is not retained beyond its required period.
As a PAGCOR-licensed operator, philwin is legally required to verify player identities and maintain transaction records under the Anti-Money Laundering Act (RA 9160). Data collected for these purposes is handled under strict regulatory frameworks and retention schedules.
philwin ("philwin," "we," "us," or "our") operates the online gaming platform accessible at philwin.one. We are a PAGCOR-licensed online casino and sportsbook serving Filipino players across the Philippines. This Privacy Policy ("Policy") describes how philwin collects, uses, discloses, stores, and protects your personal information when you access or use our Platform, create an account, make a transaction, or otherwise interact with our services.
This Policy is issued in compliance with Republic Act No. 10173, otherwise known as the Data Privacy Act of 2012 ("DPA"), its Implementing Rules and Regulations ("IRR"), and the applicable issuances of the National Privacy Commission (NPC) of the Philippines. philwin is registered as a personal information controller with the NPC as required under applicable regulations.
This Policy should be read together with philwin's Terms and Conditions, which govern your overall use of the Platform and are incorporated herein by reference.
For the purposes of the Data Privacy Act of 2012 and this Policy, philwin acts as the Personal Information Controller (PIC) in respect of the personal data it collects from players and website visitors. As PIC, philwin determines the purposes for which and the means by which personal data is processed.
Where philwin engages third-party service providers — such as payment processors, KYC verification services, and game technology providers — to process personal data on its behalf, those third parties act as Personal Information Processors (PIPs) and are bound by contractual data processing agreements that require them to maintain the same standards of data protection required under Philippine law.
philwin has designated a Data Protection Officer (DPO) as required by NPC regulations. The DPO oversees philwin's data protection program, ensures compliance with the DPA, and serves as the primary point of contact for data subjects exercising their rights. Contact details for the DPO are provided in Section 15 of this Policy.
philwin collects personal data only to the extent necessary for the lawful purposes described in this Policy. The categories of personal data we collect include:
| Category | Examples | When Collected |
|---|---|---|
| Identity Data | Full name, date of birth, gender, nationality, government ID numbers (UMID, PhilSys, passport, driver's license) | Registration & KYC verification |
| Contact Data | Mobile number (+63 format), email address, residential address | Registration |
| Financial Data | GCash / Maya account reference, bank account identifiers (for withdrawal verification), transaction amounts and timestamps | Deposits, withdrawals, KYC |
| Technical Data | IP address, device type, browser, operating system, session tokens, login timestamps | Platform access |
| Usage Data | Games played, bets placed, bet amounts, win/loss history, session duration, feature interactions | Ongoing platform use |
| Verification Documents | Scanned or photographed copies of government-issued IDs, selfies or liveness verification images | KYC process |
| Communications Data | Live chat transcripts, email correspondence, support ticket content | When you contact support |
| Responsible Gaming Data | Self-imposed limits, cooling-off or self-exclusion elections, problem gambling indicators | When tools are used |
philwin collects personal data through the following means:
philwin processes your personal data for the following purposes:
Under the Data Privacy Act of 2012, philwin relies on the following lawful bases for processing your personal data:
philwin does not sell your personal data to third parties. We share personal data only in the circumstances described below, and only to the extent strictly necessary:
philwin retains personal data only for as long as is necessary to fulfil the purposes for which it was collected, or as required by applicable law. The following general retention periods apply:
| Data Category | Retention Period | Basis |
|---|---|---|
| Account and identity data | Duration of account + 5 years after closure | PAGCOR license, AML Act |
| Transaction and financial data | 5 years from transaction date | RA 9160 (AML Act), BIR requirements |
| KYC documents | 5 years from account closure | PAGCOR and AMLC requirements |
| Customer support communications | 3 years from last interaction | Legitimate interests (dispute resolution) |
| Technical and usage data | 13 months from collection | Security, analytics |
| Marketing preferences | Until consent withdrawn or account closed | Consent |
| Self-exclusion records | Indefinitely (or as specified in request) | Player protection obligation |
Upon expiry of the applicable retention period, personal data is securely deleted or anonymized in accordance with NPC guidance on data disposal. Where data cannot be immediately deleted due to legal hold requirements, it is segregated and access-restricted pending lawful disposal.
philwin uses cookies and similar tracking technologies — including session tokens, local storage, and analytics pixels — to operate the Platform, maintain session security, and analyze user behavior for service improvement purposes.
The following types of cookies are used on the philwin Platform:
philwin does not use third-party advertising or behavioral tracking cookies for the purpose of serving targeted advertising on external websites. You may manage cookie preferences through your browser settings. Note that disabling strictly necessary cookies may prevent access to some Platform features.
philwin implements appropriate technical and organizational measures to protect your personal data against unauthorized access, disclosure, alteration, loss, or destruction. Our security measures include, but are not limited to:
Under the Data Privacy Act of 2012, you have the following rights in relation to your personal data held by philwin. philwin will respond to all valid rights requests within the timeframes prescribed by NPC regulations:
Request a copy of the personal data philwin holds about you and information on how it is being processed.
Request correction of inaccurate or incomplete personal data in your philwin account.
Request deletion of personal data where it is no longer necessary for its original purpose, subject to legal retention obligations.
Object to processing based on legitimate interests or for direct marketing purposes at any time.
Receive a copy of data you provided to philwin in a structured, machine-readable format.
Withdraw consent to processing at any time, without affecting the lawfulness of prior processing based on that consent.
To exercise any of these rights, please contact philwin's Data Protection Officer via the contact details in Section 15. Requests will be acknowledged within five (5) business days and substantively responded to within fifteen (15) business days, extendable by a further fifteen (15) days for complex requests with prior notification. Identity verification will be required before processing any rights request to prevent unauthorized disclosure. If you are unsatisfied with philwin's response to your request, you have the right to lodge a complaint with the National Privacy Commission.
philwin is strictly an adults-only platform. In compliance with PAGCOR's mandatory minimum age requirement, the Platform is accessible only to individuals who are 21 years of age or older. philwin does not knowingly collect personal data from persons under 21 years of age.
Where philwin discovers or has reasonable grounds to suspect that an account has been registered by a person under 21 years of age, it will immediately suspend the account, cease processing the minor's personal data, delete such data to the extent not required to be retained for regulatory or legal compliance purposes, and report the matter to PAGCOR as required by our licensing obligations.
If you are the parent or legal guardian of a person you believe has registered on philwin while under 21 years of age, please contact philwin's Data Protection Officer immediately with the relevant account details.
Some of philwin's service providers — including cloud infrastructure providers and game technology companies — may process personal data in locations outside the Philippines. Where personal data is transferred outside the Philippines, philwin ensures that appropriate safeguards are in place to provide an equivalent level of data protection to that required under the DPA, including:
philwin will not transfer personal data to a country or territory that does not provide adequate data protection safeguards unless required by Philippine law or pursuant to your explicit consent with full awareness of the associated risks.
philwin reserves the right to update or amend this Privacy Policy from time to time to reflect changes in applicable law, NPC guidance, PAGCOR requirements, or our data processing practices. When material changes are made, philwin will notify registered players via their registered email address or through an on-Platform notification prior to the changes taking effect.
The updated Policy will be published on the Platform with a revised effective date. Continued use of the philwin Platform following the effective date of any revision constitutes your acceptance of the revised Policy. We encourage you to review this Policy periodically to stay informed about how we protect your personal data.
If a proposed change would materially alter how we use personal data collected under a prior consent, we will seek fresh consent from affected data subjects before the change takes effect.
For any questions, concerns, or requests relating to this Privacy Policy or the processing of your personal data by philwin, please contact our Data Protection Officer using the following channels:
This Privacy Policy was last reviewed and published on 1 January 2026. philwin is committed to transparency in how we handle your data and welcomes any questions you may have about our privacy practices.
philwin is built on a foundation of security, transparency, and PAGCOR-licensed accountability. Your personal data is protected by Philippine law, processed only for legitimate purposes, and never sold. Sign in and play with confidence — 21+ Filipino players only.