1. Introduction
phwin9 ("phwin9," "we," "us," or "our") operates an online gaming and entertainment platform accessible at phwin9.app, designed for Filipino players across the Philippines — from Manila and Makati to Cebu, Davao, and Quezon City. We are committed to protecting the personal information of every player who registers and uses the phwin9 platform.
This Privacy Policy ("Policy") describes how phwin9 collects, uses, stores, shares, and protects personal data in connection with your use of the phwin9 website, mobile applications, and all associated services (collectively, the "Platform"). It also describes the rights you have over your personal data and how you can exercise those rights.
This Policy applies to all registered players, visitors to the phwin9 website, and any individual whose personal data phwin9 processes in connection with the Platform. Please read this Policy carefully. If you do not agree with the practices described herein, you should not use the phwin9 Platform.
This Policy should be read alongside the phwin9 Terms & Conditions, which govern your use of the Platform as a whole.
2. Data Controller
For the purposes of the Data Privacy Act of 2012, phwin9 acts as the Personal Information Controller (PIC) in respect of the personal data it collects and processes through the Platform. This means phwin9 determines the purposes and means of processing your personal data.
Where phwin9 engages third-party service providers to process personal data on its behalf — such as payment processors, identity verification providers, or cloud infrastructure providers — those parties act as Personal Information Processors (PIPs) and are contractually bound to process data only in accordance with phwin9's instructions and applicable Philippine data privacy law.
If you have any questions about how phwin9 handles your personal data, or if you wish to exercise any of your data subject rights, please contact our Data Protection Officer (DPO) using the details provided in Section 14 of this Policy.
3. Data We Collect
phwin9 collects personal data that is necessary, adequate, and not excessive in relation to the purposes for which it is collected. The categories of personal data we collect are described below.
3.1 Data You Provide Directly
- Registration data: Full legal name, date of birth, gender, Philippine mobile number, email address, and chosen username and password;
- Identity verification (KYC) data: Government-issued ID number and type, ID document images, selfie photographs for liveness verification, and proof of address documents;
- Payment data: GCash mobile number, PayMaya/Maya account details, bank account details (BPI, BDO, Metrobank, UnionBank, Landbank, PNB, Security Bank), and debit card details (card number, expiry, and cardholder name — stored in tokenized form only);
- Communications data: Messages, complaints, and support requests submitted to phwin9 customer support via live chat or email.
3.2 Data Collected Automatically
- Device and technical data: IP address, device type, operating system, browser type and version, screen resolution, and device identifiers;
- Usage data: Pages visited, games played, session duration, click patterns, and navigation paths within the Platform;
- Transaction data: Deposit and withdrawal history, bet history, game results, bonus usage, and account balance history;
- Geolocation data: Approximate location derived from IP address, used to verify geographic eligibility.
3.3 Data from Third Parties
- Identity verification providers: Results of automated identity and age verification checks;
- Payment processors: Transaction confirmation and fraud screening results;
- Regulatory bodies: Information shared by PAGCOR or other Philippine regulatory authorities in connection with compliance obligations.
3.4 Summary Table
| Data Category | Examples | Source |
|---|---|---|
| Identity Data | Name, date of birth, government ID | You / KYC provider |
| Contact Data | Email, mobile number | You |
| Financial Data | GCash number, bank account, debit card token | You / Payment processor |
| Technical Data | IP address, device ID, browser | Automatically collected |
| Usage Data | Games played, session logs, bet history | Automatically collected |
| Communications Data | Support chat transcripts, emails | You |
4. How We Use Your Data
phwin9 uses your personal data only for the purposes described below. We do not use your data for any purpose that is incompatible with the original purpose for which it was collected without your prior consent.
- Account creation and management: To register your phwin9 account, verify your identity, and manage your player profile;
- Service delivery: To provide access to games, process deposits and withdrawals, and deliver the core features of the phwin9 Platform;
- KYC and age verification: To verify that you are 21 years of age or older and to comply with PAGCOR's player identification requirements;
- Anti-money laundering (AML) compliance: To screen transactions, monitor for suspicious activity, and comply with the Anti-Money Laundering Act (AMLA) of the Philippines and its amendments;
- Fraud prevention and security: To detect, investigate, and prevent fraudulent activity, unauthorized account access, and other security threats;
- Customer support: To respond to your inquiries, resolve disputes, and improve the quality of our support services;
- Responsible gaming: To monitor gaming patterns, enforce deposit limits and self-exclusion requests, and identify players who may be at risk of problem gambling;
- Marketing and promotions: To send you promotional offers, bonus notifications, and platform updates — subject to your communication preferences and applicable opt-out rights;
- Platform improvement: To analyze usage patterns, conduct A/B testing, and improve the features, performance, and user experience of the phwin9 Platform;
- Legal compliance: To comply with applicable Philippine laws, regulatory requirements, court orders, and lawful requests from government authorities.
5. Legal Basis for Processing
Under the Data Privacy Act of 2012, phwin9 processes your personal data on the following legal bases:
- Contractual necessity: Processing required to perform the contract between you and phwin9 — including account registration, game access, and payment processing;
- Legal obligation: Processing required to comply with applicable Philippine laws, including PAGCOR regulations, the Anti-Money Laundering Act, and the Data Privacy Act itself;
- Legitimate interests: Processing necessary for phwin9's legitimate business interests, including fraud prevention, platform security, and service improvement — where those interests are not overridden by your rights and freedoms;
- Consent: Processing based on your freely given, specific, informed, and unambiguous consent — primarily for direct marketing communications. You may withdraw consent at any time without affecting the lawfulness of prior processing.
6. Data Sharing & Disclosure
phwin9 does not sell, rent, or trade your personal data to third parties for their own marketing purposes. We share your personal data only in the circumstances described below, and only to the extent necessary for the stated purpose.
6.1 Service Providers (Personal Information Processors)
phwin9 engages trusted third-party service providers to assist in operating the Platform. These providers process personal data solely on phwin9's instructions and are bound by data processing agreements that require them to maintain appropriate security measures and comply with the Data Privacy Act of 2012. Categories of service providers include:
- Payment processors: GCash, PayMaya/Maya, and banking partners (BPI, BDO, Metrobank, UnionBank, Landbank, PNB, Security Bank) for deposit and withdrawal processing;
- Identity verification providers: Third-party KYC and age verification platforms used to confirm player identity and age eligibility;
- Cloud infrastructure providers: Hosting and data storage services that maintain the technical infrastructure of the phwin9 Platform;
- Customer support platforms: Live chat and ticketing systems used to manage player support interactions;
- Analytics providers: Tools used to analyze Platform usage and improve user experience, operating on anonymized or pseudonymized data where possible.
6.2 Regulatory and Legal Disclosures
phwin9 may disclose your personal data to the following authorities where required by law or in response to a lawful request:
- Philippine Amusement and Gaming Corporation (PAGCOR);
- Anti-Money Laundering Council (AMLC) of the Philippines;
- National Privacy Commission (NPC);
- Philippine law enforcement agencies, courts, or other government bodies acting under lawful authority.
6.3 Business Transfers
In the event of a merger, acquisition, restructuring, or sale of all or part of phwin9's business, your personal data may be transferred to the acquiring entity as part of that transaction. phwin9 will notify affected players via email or in-platform notification prior to any such transfer and will ensure that the receiving entity is bound by privacy obligations no less protective than those set out in this Policy.
6.4 No Sale of Personal Data
phwin9 does not and will not sell your personal data to data brokers, advertisers, or any other third party for commercial gain. This commitment applies regardless of any future changes to phwin9's business model.
7. Cookies & Tracking Technologies
7.1 What Are Cookies
Cookies are small text files placed on your device when you visit the phwin9 Platform. They allow phwin9 to recognize your device, remember your preferences, and collect information about how you use the Platform. phwin9 also uses similar tracking technologies such as web beacons, pixel tags, and local storage objects.
7.2 Types of Cookies We Use
| Cookie Type | Purpose | Duration |
|---|---|---|
| Strictly Necessary | Session management, login authentication, security tokens | Session |
| Functional | Language preferences, game settings, UI customization | Up to 12 months |
| Analytics | Page views, session duration, feature usage (anonymized) | Up to 24 months |
| Marketing | Promotion tracking, bonus attribution, campaign performance | Up to 30 days |
7.3 Managing Cookies
You can control and manage cookies through your browser settings. Most browsers allow you to refuse cookies, delete existing cookies, or be notified when a new cookie is set. Please note that disabling strictly necessary cookies may affect the functionality of the phwin9 Platform, including your ability to log in and access games.
For analytics and marketing cookies, you may opt out at any time by adjusting your cookie preferences via the cookie consent banner displayed on your first visit to the Platform.
8. Data Retention
phwin9 retains your personal data only for as long as necessary to fulfill the purposes for which it was collected, or as required by applicable Philippine law. The following retention periods apply:
- Account and identity data: Retained for the duration of your account and for a minimum of five (5) years after account closure, in compliance with PAGCOR record-keeping requirements and the Anti-Money Laundering Act;
- Transaction and financial data: Retained for a minimum of five (5) years from the date of each transaction, as required by AMLC regulations;
- KYC documents: Retained for a minimum of five (5) years after the end of the business relationship, or longer if required by a regulatory investigation;
- Customer support records: Retained for three (3) years from the date of the last interaction;
- Marketing data: Retained until you withdraw consent or opt out of marketing communications, after which it is deleted within 30 days;
- Technical and usage logs: Retained for up to twelve (12) months for security and performance monitoring purposes.
When personal data is no longer required, phwin9 will securely delete or anonymize it in accordance with industry-standard data destruction procedures.
9. Data Security
phwin9 implements a comprehensive set of technical and organizational security measures to protect your personal data against unauthorized access, disclosure, alteration, loss, or destruction. These measures include:
- Encryption in transit: All data transmitted between your device and the phwin9 Platform is encrypted using TLS 1.2 or higher;
- Encryption at rest: Sensitive personal data, including payment details and identity documents, is encrypted at rest using AES-256 encryption;
- Access controls: Access to personal data is restricted to phwin9 personnel and authorized service providers on a strict need-to-know basis, enforced through role-based access controls and multi-factor authentication;
- Payment tokenization: Debit card details are never stored in raw form — they are immediately tokenized by our payment processor and only the token is retained by phwin9;
- Security monitoring: phwin9 operates continuous security monitoring, intrusion detection systems, and regular vulnerability assessments to identify and address potential threats;
- Staff training: All phwin9 personnel with access to personal data receive regular data privacy and security training.
10. Your Data Subject Rights
Under the Data Privacy Act of 2012, you have the following rights in relation to your personal data held by phwin9. To exercise any of these rights, please contact our Data Protection Officer using the details in Section 14.
- Right to be informed: The right to be notified of how your personal data is collected and processed — which this Privacy Policy fulfills;
- Right of access: The right to request a copy of the personal data phwin9 holds about you, along with information about how it is being used;
- Right to rectification: The right to request correction of any inaccurate or incomplete personal data phwin9 holds about you;
- Right to erasure: The right to request deletion of your personal data where it is no longer necessary for the purpose for which it was collected, subject to phwin9's legal retention obligations;
- Right to object: The right to object to the processing of your personal data for direct marketing purposes or where processing is based on legitimate interests;
- Right to data portability: The right to receive your personal data in a structured, commonly used, and machine-readable format, and to transmit it to another controller where technically feasible;
- Right to lodge a complaint: The right to file a complaint with the National Privacy Commission (NPC) of the Philippines if you believe phwin9 has violated your data privacy rights.
phwin9 will respond to all data subject rights requests within fifteen (15) business days of receipt. In complex cases, this period may be extended by a further fifteen (15) business days, with prior notification to you.
Please note that certain rights may be limited where phwin9 is required to retain or process your data to comply with a legal obligation — for example, AML record-keeping requirements that override a deletion request.
11. Children's Privacy and Age Restriction
The phwin9 Platform is strictly intended for individuals who are twenty-one (21) years of age or older, in accordance with Philippine gaming law as administered by PAGCOR. phwin9 does not knowingly collect personal data from individuals under the age of 21.
If phwin9 discovers or is notified that it has inadvertently collected personal data from a person under the age of 21, it will immediately suspend the associated account, delete the personal data in question, and return any deposited funds to the originating payment method after deducting any winnings derived from gameplay.
If you are a parent or guardian and believe that your child under the age of 21 has registered an account with phwin9, please contact our Data Protection Officer immediately using the contact details in Section 14 of this Policy.
Gambling is addictive. Know when to stop.
12. Cross-Border Data Transfers
phwin9 primarily stores and processes personal data within the Philippines. However, some of our third-party service providers — including cloud infrastructure and analytics providers — may process data in other jurisdictions.
Where personal data is transferred outside the Philippines, phwin9 ensures that appropriate safeguards are in place to protect your data to a standard equivalent to that required under the Data Privacy Act of 2012. These safeguards may include:
- Standard contractual clauses approved by the National Privacy Commission;
- Binding corporate rules where the recipient is part of a corporate group with an approved privacy framework;
- Transfers to jurisdictions recognized by the NPC as providing an adequate level of data protection.
You may request information about the specific safeguards in place for any cross-border transfer of your personal data by contacting our Data Protection Officer.
13. Changes to This Privacy Policy
phwin9 reserves the right to update or amend this Privacy Policy at any time to reflect changes in our data processing practices, applicable law, or regulatory requirements. When material changes are made, phwin9 will notify registered players by:
- Sending a notification to your registered email address at least seven (7) days before the changes take effect; and/or
- Displaying a prominent notice on the phwin9 Platform upon your next login.
The "Last Updated" date at the top of this Policy will always reflect the date of the most recent revision. Your continued use of the phwin9 Platform after the effective date of any amendment constitutes your acceptance of the revised Privacy Policy.
If you do not agree with any changes to this Policy, you must stop using the Platform and may request account closure by contacting phwin9 customer support.
14. Contact & Complaints
If you have any questions, concerns, or requests relating to this Privacy Policy or phwin9's handling of your personal data, please contact our Data Protection Officer:
- Data Protection Officer: phwin9 DPO
- Email: [email protected]
- General Support: [email protected]
- Live Chat: Available 24/7 via the phwin9 Platform
- Response Time: phwin9 aims to acknowledge all privacy-related inquiries within 48 hours and resolve them within 15 business days.
If you are not satisfied with phwin9's response to your privacy concern, you have the right to lodge a complaint with the National Privacy Commission (NPC) of the Philippines, which is the supervisory authority responsible for enforcing the Data Privacy Act of 2012.