Our Privacy Commitments at a Glance
These highlights summarise the most important aspects of how phpiso handles your data. They are not a substitute for reading the full Policy below.
Data Privacy Act Compliance
phpiso processes all personal data in accordance with Republic Act No. 10173, the Data Privacy Act of 2012 of the Philippines, and its Implementing Rules and Regulations. Your personal data is handled lawfully, fairly, and transparently.
256-Bit Encrypted Storage
All personal and financial data held by phpiso is stored using AES-256 encryption at rest and transmitted over TLS-encrypted connections. The same security standard applied by BPI, BDO, and UnionBank for their online banking platforms.
No Sale of Personal Data
phpiso does not sell, rent, or trade your personal data to third parties for their own marketing purposes. Data is shared with service providers only where strictly necessary to deliver the services you use on the Platform.
Your Rights Are Enforceable
As a data subject under Philippine law, you have the right to access, correct, delete, and object to the processing of your personal data held by phpiso. These rights can be exercised at any time through the account settings panel or by contacting our Data Protection Officer.
Defined Retention Periods
phpiso retains personal data only for as long as necessary for the purposes for which it was collected, or as required by applicable Philippine law including anti-money laundering record-keeping obligations. Retention periods for each data category are specified in this Policy.
Breach Notification
In the event of a personal data breach that is likely to result in risk to your rights and freedoms, phpiso will notify you and the National Privacy Commission (NPC) of the Philippines within the timeframes required under applicable data protection regulations.
Important Notice: This Privacy Policy constitutes a legally binding statement by phpiso regarding the collection and processing of your personal data. By creating a phpiso account or using the Platform in any capacity, you acknowledge that you have read this Policy and consent to the data practices described herein, to the extent consent is the applicable legal basis for processing.
1 Introduction & Scope
This Privacy Policy ("Policy") describes how phpiso ("we", "us", "our") collects, uses, stores, discloses, and protects personal information obtained from individuals ("you", "Player", "Data Subject") who access or use the phpiso online gaming platform available at phpiso.cam (the "Platform").
This Policy applies to all personal data processed by phpiso in connection with your use of the Platform, including data collected during account registration, identity verification, financial transactions, gameplay, customer support interactions, and use of any promotional features.
This Policy should be read alongside the phpiso Terms & Conditions, which are available at phpiso.cam/terms-conditions. Together, these documents govern your relationship with the Platform.
This Policy does not apply to third-party websites, applications, or services that may be linked from the Platform. phpiso is not responsible for the privacy practices of those third parties and encourages you to review their privacy policies independently.
2 Data Controller
phpiso acts as the Data Controller in respect of personal data collected through the Platform. As Data Controller, phpiso determines the purposes and means by which your personal data is processed, and is responsible for ensuring that such processing is lawful, fair, transparent, and compliant with applicable data protection legislation, including Republic Act No. 10173 (Data Privacy Act of 2012) of the Philippines.
Where phpiso engages third-party service providers to process data on its behalf, such parties act as Data Processors and are bound by contractual obligations requiring them to process personal data only on documented instructions from phpiso and in compliance with applicable law.
Contact details for the phpiso Data Protection Officer (DPO) are set out in Section 15 of this Policy.
3 Data We Collect
phpiso collects the following categories of personal data in connection with your use of the Platform:
3.1 Identity & Registration Data
- Full legal name as it appears on a Philippine government-issued identification document
- Date of birth (for age verification — players must be 21+)
- Registered Philippine mobile number
- Email address (if provided during registration)
- Username and encrypted account password
- Profile photograph (if voluntarily provided)
3.2 Identity Verification (KYC) Data
- Government-issued photo identification (Philippine passport, UMID, PhilSys National ID, Driver's License, PRC ID, SSS ID, or equivalent)
- Proof of address documentation where required
- Source-of-funds documentation where applicable under anti-money laundering obligations
- Facial biometric data captured during liveness verification, where applicable
3.3 Financial Data
- GCash mobile number and account reference
- Maya account reference
- Philippine bank account details (BPI, BDO, UnionBank, or other supported institutions) where used for transactions
- Transaction history including deposit amounts, withdrawal amounts, dates, and reference numbers
- Cryptocurrency wallet addresses where applicable (USDT, Coins.ph)
3.4 Gaming & Behavioural Data
- Game session history, including titles played, wager amounts, win/loss outcomes, and session duration
- Sports betting selections, odds accepted, and settlement outcomes
- Bonus activation and wagering progress data
- Responsible gaming tool settings (deposit limits, session limits, self-exclusion status)
3.5 Technical & Device Data
- IP address at login and during active sessions
- Device type, operating system, browser type and version
- Device identifiers (device ID, advertising ID where applicable)
- Geographic location data derived from IP address
- Session timestamps and duration logs
3.6 Communications Data
- Live chat transcripts with customer support
- Email correspondence with phpiso
- Records of SMS communications sent to your registered mobile number
- Records of complaint submissions and their resolution
4 How We Collect Your Data
phpiso collects personal data through the following channels:
- Directly from you — when you register an account, complete identity verification, make a deposit or withdrawal request, contact customer support, participate in a promotion, or update your account settings.
- Automatically during Platform use — through server logs, session tracking, and cookies when you access and interact with the Platform. See Section 10 for full details on our cookie practices.
- From payment service providers — GCash, Maya, BPI, BDO, UnionBank, and other payment processors may share transaction confirmation data with phpiso necessary to verify and process your financial requests.
- From identity verification service providers — phpiso may engage third-party KYC and anti-money laundering service providers who verify identity documentation and provide verification outcomes.
- From fraud prevention and security services — Technical risk signals, device fingerprinting data, and fraud scoring outputs from security service providers used to protect the integrity of the Platform.
5 How We Use Your Data
phpiso uses your personal data for the following purposes:
| Purpose | Data Categories Used |
|---|---|
| Account registration & management | Identity, registration, technical data |
| Age & identity verification (KYC) | Identity, KYC documentation |
| Processing deposits & withdrawals | Identity, financial, KYC data |
| Delivering gaming services | Identity, gaming & behavioural data |
| Fraud prevention & AML compliance | Identity, financial, technical, KYC data |
| Customer support | Identity, communications data |
| Responsible gaming monitoring | Gaming, behavioural, identity data |
| Sending transactional communications (SMS, email) | Identity, registration, communications data |
| Platform security & abuse prevention | Technical, device, identity data |
| Legal & regulatory compliance | All categories as required |
| Service improvement & analytics | Gaming, technical, behavioural (anonymised) |
| Marketing communications (with consent) | Identity, registration, gaming preferences |
Marketing Communications: phpiso will only send promotional SMS messages, emails, or in-platform notifications for marketing purposes where you have provided explicit consent to receive such communications. You may withdraw consent at any time by updating your notification preferences in account settings or by contacting customer support.
6 Legal Bases for Processing
Under Republic Act No. 10173 (Data Privacy Act of 2012) and its Implementing Rules, phpiso processes personal data on the following legal bases:
- Contractual necessity — Processing required to perform the contract between you and phpiso (i.e., delivering gaming services, processing transactions, managing your account).
- Legal obligation — Processing required to comply with applicable Philippine laws, including RA 9160 (Anti-Money Laundering Act), RA 10927 (amendments to the AMLA relating to casinos), and regulations issued by relevant government authorities.
- Legitimate interests — Processing for fraud prevention, security, Platform improvement, and responsible gaming monitoring, where such interests are not overridden by your fundamental rights and freedoms.
- Consent — Processing for marketing communications and certain optional data collection activities, where you have provided freely given, specific, informed, and unambiguous consent. You may withdraw consent at any time without affecting the lawfulness of processing before withdrawal.
7 Sharing Your Personal Data
phpiso does not sell your personal data. We share your data only with the following categories of recipients, and only to the extent necessary for the specified purpose:
- Payment processors — GCash, Maya, BPI, BDO, UnionBank, 7-Eleven Cliqq, and cryptocurrency processors, for the purpose of executing financial transactions you initiate.
- Identity verification providers — Third-party KYC and AML service providers engaged to verify identity documentation and screen against watchlists.
- Game providers — JILI, Pragmatic Play, PG Soft, and other licensed game providers may receive your player identifier and gaming session data necessary to deliver games and resolve disputes.
- IT infrastructure and security providers — Cloud hosting, cybersecurity, and fraud prevention service providers operating under contractual data processing agreements with phpiso.
- Regulatory and law enforcement authorities — The National Privacy Commission (NPC), Anti-Money Laundering Council (AMLC), and other relevant Philippine government authorities, where disclosure is required by law, court order, or regulatory mandate.
- Professional advisors — Legal counsel, auditors, and accountants, under confidentiality obligations, where access is necessary for the provision of professional services to phpiso.
All third-party service providers who process personal data on behalf of phpiso are contractually required to implement appropriate technical and organisational security measures and to process data solely on documented instructions from phpiso, consistent with applicable Philippine data protection law.
8 International Data Transfers
Some of the third-party service providers engaged by phpiso may be located in countries outside the Philippines. Where personal data is transferred to a country that does not offer an equivalent level of data protection to that provided under Philippine law, phpiso will implement appropriate safeguards to protect your data.
Safeguards used for international transfers include:
- Contractual clauses that require the recipient to protect personal data to standards consistent with the Data Privacy Act of 2012.
- Adequacy determinations where the NPC has recognised a recipient country as providing adequate data protection.
- Binding corporate rules where the recipient is part of a corporate group with approved intra-group data transfer policies.
You may request information about the specific safeguards applicable to any international transfer of your personal data by contacting the phpiso DPO as set out in Section 15.
9 Data Retention
phpiso retains personal data for no longer than is necessary for the purposes described in this Policy, subject to any longer retention periods required by applicable Philippine law:
| Data Category | Retention Period | Basis |
|---|---|---|
| Account & identity data | Duration of account + 5 years post-closure | AML legal obligation (RA 9160) |
| KYC documentation | Duration of account + 5 years post-closure | AML legal obligation |
| Financial transaction records | Duration of account + 5 years post-closure | AML & tax compliance |
| Game session history | Duration of account + 2 years post-closure | Dispute resolution, contractual |
| Customer support communications | 3 years from last interaction | Legitimate interests |
| Technical & device logs | 12 months from collection | Security & fraud prevention |
| Marketing consent records | Until consent withdrawn + 3 years | Legal compliance |
Following the expiry of the applicable retention period, personal data will be securely deleted or anonymised in accordance with phpiso's data destruction procedures.
10 Cookies & Tracking Technologies
10.1 What Are Cookies
Cookies are small text files stored on your device when you visit the phpiso Platform. They allow the Platform to recognise your device, maintain your session state, and collect information about how you interact with the site.
10.2 Types of Cookies Used by phpiso
- Strictly Necessary Cookies — Essential for the Platform to function. These include session authentication cookies that keep you logged in during your visit. These cannot be disabled without breaking the Platform.
- Functional Cookies — Remember your preferences such as language settings, preferred game categories, and responsible gaming tool configurations.
- Analytical Cookies — Collect anonymised data about how players use the Platform to help us improve performance, identify popular game categories, and optimise the user experience.
- Security Cookies — Support fraud detection, device fingerprinting for suspicious login detection, and session integrity verification.
10.3 Managing Cookies
You may configure your browser to block or delete cookies. Note that disabling strictly necessary cookies will impair or prevent your ability to log in and use the phpiso Platform. Instructions for managing cookies are available in your browser's help documentation.
11 Your Data Subject Rights
Under the Data Privacy Act of 2012 (RA 10173), you have the following rights with respect to your personal data held by phpiso:
Right to Be Informed
The right to be informed of the existence, nature, and purpose of the processing of your personal data — fulfilled by this Privacy Policy and any supplementary notices provided at collection points.
Right of Access
The right to request a copy of the personal data phpiso holds about you, including information on the purposes of processing, categories of data, and recipients with whom data has been shared.
Right to Correction
The right to request correction of inaccurate or incomplete personal data. You may update basic account information (name, mobile number) directly in account settings; for KYC data corrections, contact support with supporting documentation.
Right to Erasure / Blocking
The right to request deletion or blocking of your personal data where it is no longer necessary, consent has been withdrawn, or processing is unlawful — subject to phpiso's legal retention obligations under AML and tax regulations.
Right to Object
The right to object to processing of your personal data for direct marketing purposes at any time. You may also object to processing based on legitimate interests, subject to phpiso's overriding legitimate grounds for continued processing.
Right to Data Portability
The right to receive a copy of your personal data in a structured, commonly used, machine-readable format, and to transmit that data to another controller where technically feasible.
Right Against Automated Decision-Making
The right not to be subject to decisions based solely on automated processing that produce legal effects or similarly significant effects on you, without human review involvement.
Exercising Your Rights: To exercise any of these rights, contact the phpiso Data Protection Officer as described in Section 15. phpiso will respond to data subject requests within thirty (30) calendar days of receipt. Where a request is complex or numerous, phpiso may extend this period by a further thirty (30) days, notifying you of the extension and its reasons.
12 Children's Privacy
The phpiso Platform is strictly intended for adults aged 21 years and above. phpiso does not knowingly collect personal data from individuals under the age of 21. Age verification is conducted as part of the registration and KYC process to enforce this restriction.
If phpiso becomes aware that personal data has been collected from an individual under the age of 21 without appropriate verification having detected this, the relevant account will be immediately suspended, any funds returned, and the associated personal data deleted or blocked in accordance with applicable law.
If you have reason to believe that a minor has created a phpiso account, please notify us immediately at the contact details in Section 15 so that appropriate action can be taken without delay.
13 Security Measures
phpiso implements the following technical and organisational security measures to protect your personal data against unauthorised access, disclosure, alteration, or destruction:
- Encryption at rest: All stored personal and financial data is encrypted using AES-256, the same standard used by Philippine banks for customer data storage.
- Encryption in transit: All data transmitted between your device and phpiso servers is protected by TLS 1.2 or higher.
- Access controls: Personal data is accessible only to phpiso staff who require it for their specific job function, governed by role-based access control policies.
- Two-factor authentication: phpiso internal systems require multi-factor authentication for all staff access to systems containing personal data.
- Security audits: Regular vulnerability assessments and penetration testing are conducted by independent security specialists.
- Incident response: phpiso maintains a documented incident response procedure for personal data breaches, including NPC notification obligations.
- Staff training: All phpiso personnel with access to personal data receive regular data protection training.
While phpiso implements robust security measures, no system is completely immune to security risks. We encourage you to protect your account by using a strong, unique password, enabling two-factor authentication, and never sharing your login credentials with any third party.
14 Policy Updates
phpiso may update this Privacy Policy from time to time to reflect changes in our data processing practices, applicable Philippine law, or regulatory guidance from the National Privacy Commission.
Where changes are material, phpiso will notify you through one or more of the following channels prior to the changes taking effect: a notice displayed on the Platform upon login, an SMS to your registered Philippine mobile number, or an email to your registered address (where provided).
Your continued use of the Platform following the effective date of an updated Policy constitutes acceptance of the revised terms. The "Last Updated" date at the top of this Policy reflects when the most recent revision took effect.
Current Effective Date: This Privacy Policy is effective as of January 1, 2026 and supersedes all prior versions of the phpiso Privacy Policy.
15 Contact & Data Protection Officer
phpiso has appointed a Data Protection Officer (DPO) responsible for overseeing compliance with this Policy and applicable data protection law. You may contact the DPO for any privacy-related enquiry, data subject rights request, or complaint:
- Data Protection Officer — phpiso
- Email: [email protected] (subject line: "DPO / Privacy Enquiry")
- Live Chat: Available 24/7 via the Platform — select "Privacy & Data" as your enquiry category
If you are not satisfied with phpiso's response to a privacy complaint, you have the right to lodge a complaint with the National Privacy Commission (NPC) of the Philippines, which is the supervisory authority responsible for enforcing the Data Privacy Act of 2012.
NPC Contact: The National Privacy Commission of the Philippines can be reached through its official government portal. phpiso encourages players to first contact our DPO before escalating to the NPC, as we are committed to resolving privacy concerns directly and promptly.
Your Data Is Protected. Your Games Are Waiting.
phpiso takes your privacy as seriously as your gameplay. Encrypted, compliant, and built around Filipino data protection law — your personal information is handled the right way, so you can focus on the games. 21+ only.
21+ only. Please play responsibly. Visit our Responsible Gaming page for support tools and resources.