This Privacy Policy explains what personal information phtttt Casino collects from you when you use phtttt.app, how that information is used and protected, who it may be shared with, and what rights you have under Philippine law. phtttt is committed to handling your personal data with transparency, security, and respect. If you have questions after reading this Policy, contact our Data Protection Officer at the details in Section 15.
1. Introduction & Scope
1.1 This Privacy Policy ("Policy") describes how phtttt Casino ("phtttt," "we," "us," "our") — operator of the online gaming platform at phtttt.app — collects, uses, stores, discloses, and otherwise processes personal data about individuals ("you," "Player," "User") who access or use the phtttt platform and related services.
1.2 This Policy applies to all personal data collected through phtttt.app, including data collected during account registration, identity verification, payment processing, customer support interactions, promotional activities, and any other use of phtttt's services.
1.3 This Policy is prepared and maintained in compliance with Republic Act No. 10173, also known as the Philippine Data Privacy Act of 2012 ("DPA"), its Implementing Rules and Regulations ("IRR"), and the issuances of the National Privacy Commission ("NPC").
1.4 By registering for a phtttt account or continuing to use the phtttt platform after the effective date of this Policy, you acknowledge that you have read and understood this Policy and consent to the collection and processing of your personal data as described herein.
1.5 This Policy should be read alongside the phtttt Terms & Conditions, which govern your use of the platform generally.
2. Data Controller
2.1 phtttt Casino, operating the platform at phtttt.app, is the personal information controller ("PIC") for all personal data collected through the platform, as that term is defined under the Philippine Data Privacy Act.
2.2 As PIC, phtttt determines the purposes and means of processing personal data collected from players, and is responsible for ensuring that all processing activities comply with the DPA, its IRR, and applicable NPC regulations.
2.3 phtttt has designated a Data Protection Officer ("DPO") who is responsible for overseeing the implementation of this Policy and serving as the primary point of contact for data privacy inquiries, complaints, and requests. Contact details for the DPO are provided in Section 15 of this Policy.
3. Categories of Personal Data We Collect
3.1 phtttt collects the following categories of personal data from players:
| Category | Examples | Required? |
|---|---|---|
| Identity Data | Legal full name, date of birth, nationality, government-issued ID type and number (UMID, Driver's License, Passport, PhilSys) | Mandatory for KYC |
| Contact Data | Philippine mobile number (Globe or Smart), email address (where provided) | Mandatory |
| Financial Data | GCash account reference, Maya account reference, bank account name and number (BPI, BDO, Metrobank), transaction history | Required for withdrawals |
| Technical Data | IP address, device type, browser type and version, operating system, session tokens, login timestamps | Automatic |
| Usage Data | Games played, bet amounts, session duration, pages visited, feature interactions | Automatic |
| Communications Data | Live chat transcripts, support ticket content, OTP verification logs | When you contact us |
| Verification Documents | Scanned or photographed copies of government-issued IDs submitted for age and identity verification | Required for withdrawals |
3.2 phtttt does not intentionally collect sensitive personal information as defined under the DPA (such as health information, religious beliefs, or political affiliations) unless strictly required by law or with your explicit consent.
4. How We Collect Personal Data
4.1 Direct Collection. phtttt collects personal data that you provide directly when you: register an account at phtttt.app; complete identity verification (KYC); make a deposit or request a withdrawal; contact customer support via live chat; participate in promotional offers or surveys; or update your account profile.
4.2 Automatic Collection. When you access phtttt.app, our systems automatically collect technical and usage data through server logs, session tracking, and cookies. This includes your IP address, device identifiers, browser information, and details of your interactions with the platform.
4.3 Third-Party Sources. phtttt may receive personal data about you from third parties in specific circumstances, including:
- Payment processors (GCash, Maya, BPI, BDO, Metrobank, GrabPay, InstaPay) confirming transaction details
- Identity verification service providers conducting document authentication
- Fraud detection and anti-money laundering service providers
- PAGCOR or other Philippine regulatory authorities as part of compliance processes
For Filipino Players: Your GCash and Maya account details (the registered mobile number associated with your e-wallet) are used solely to process your deposits and withdrawals. phtttt does not have access to your GCash or Maya PIN, account balance, or transaction history outside of the specific transactions you initiate on phtttt.
5. Purposes of Processing
5.1 phtttt processes your personal data for the following specific, legitimate purposes:
- Account Management: Creating, maintaining, verifying, and administering your phtttt player account
- Age & Identity Verification: Confirming that you are 21 years of age or older, as required by Philippine gaming regulations, and verifying your identity in accordance with KYC requirements
- Payment Processing: Processing deposits from and withdrawals to your registered GCash, Maya, bank, or other approved payment method
- Regulatory Compliance: Meeting phtttt's obligations under the DPA, PAGCOR regulations, Anti-Money Laundering Act (AMLA), and other applicable Philippine laws
- Fraud Prevention & Security: Detecting, investigating, and preventing fraudulent activity, unauthorised account access, money laundering, and other prohibited conduct
- Customer Support: Responding to your inquiries, resolving complaints, and providing technical assistance
- Service Improvement: Analysing usage patterns to improve the platform, personalise your experience, and develop new features
- Responsible Gaming: Monitoring gaming activity to identify potential problem gambling behaviour and applying responsible gaming tools where appropriate
- Marketing Communications: Sending promotional offers, bonus notifications, and relevant updates — subject to your communication preferences and the right to opt out
6. Legal Bases for Processing
6.1 Under the Philippine Data Privacy Act, phtttt relies on the following legal bases for processing your personal data:
6.1 Contractual Necessity
Processing is necessary for the performance of the agreement between you and phtttt — specifically, the phtttt Terms & Conditions. This includes account registration, payment processing, game access, and customer support.
6.2 Legal Obligation
Processing is necessary to comply with phtttt's legal obligations under Philippine law, including the Data Privacy Act, Anti-Money Laundering Act, and regulatory requirements imposed by PAGCOR. This includes KYC verification, transaction monitoring, and regulatory reporting.
6.3 Legitimate Interests
Processing is necessary for phtttt's legitimate interests — including fraud prevention, platform security, responsible gaming monitoring, and service improvement — provided those interests are not overridden by your rights and interests.
6.4 Consent
For marketing communications and certain non-essential cookies, phtttt relies on your freely given, specific, and informed consent. You may withdraw consent for marketing at any time through your account settings or by contacting our support team.
7. Data Sharing & Third-Party Disclosure
7.1 phtttt does not sell, rent, trade, or otherwise transfer your personal data to third parties for their own marketing or commercial purposes.
7.2 phtttt may share your personal data with carefully selected third parties solely to the extent necessary for the following purposes:
- Payment Processors: GCash, Maya, BPI, BDO, Metrobank, GrabPay, InstaPay, and 7-Eleven CLiQQ — strictly for processing deposits and withdrawals you have initiated
- Identity Verification Providers: Third-party KYC service providers who assist in verifying identity documents submitted by players
- Game Studio Partners: Game studios whose titles are offered on phtttt may receive anonymised or pseudonymised session data for technical performance and integrity purposes only
- Fraud Prevention Services: Anti-fraud and AML monitoring service providers who assist phtttt in detecting and preventing financial crimes
- Technology Infrastructure Providers: Hosting, cloud storage, and cybersecurity service providers operating under contractual data processing agreements with phtttt
- Regulatory Authorities: PAGCOR, the Anti-Money Laundering Council (AMLC), the NPC, and Philippine law enforcement agencies — where disclosure is required by law, court order, or regulatory directive
7.3 All third-party service providers who process personal data on phtttt's behalf are bound by contractual data processing agreements requiring them to process data only on phtttt's instructions and to maintain appropriate security standards.
Important: phtttt will never share your personal data with unauthorized third parties. If you receive a communication claiming to be from phtttt that asks for your personal data via a channel other than phtttt.app, treat it as a phishing attempt and do not respond.
8. Data Retention
8.1 phtttt retains personal data for the minimum period necessary to fulfil the purpose for which it was collected, subject to the following retention standards:
| Data Category | Retention Period | Basis |
|---|---|---|
| Account & Identity Data | Duration of account + 5 years after closure | AMLA / Regulatory requirement |
| Financial Transaction Records | 5 years from date of transaction | AMLA Section 9 compliance |
| KYC / Verification Documents | 5 years after account closure | AML / PAGCOR compliance |
| Customer Support Records | 3 years from last interaction | Dispute resolution / Legal claims |
| Technical / Usage Logs | 12 months from collection | Security & fraud detection |
| Marketing Consent Records | Until consent is withdrawn + 1 year | DPA consent accountability |
8.2 Upon expiry of the applicable retention period, phtttt will securely delete or anonymise personal data so that it can no longer be associated with an identified or identifiable individual.
8.3 Where personal data is subject to a legal dispute, regulatory inquiry, or law enforcement hold, retention will be extended for the duration of that proceeding.
9. Security Measures
9.1 phtttt implements and maintains a comprehensive set of technical and organisational security measures to protect your personal data against unauthorised access, accidental loss, destruction, alteration, or disclosure. These measures include:
- 256-bit SSL/TLS encryption on all connections between your browser and phtttt.app
- Encryption of sensitive data fields at rest in phtttt's database infrastructure
- Multi-factor authentication requirements for administrative access to systems containing personal data
- Role-based access controls ensuring that staff can only access personal data necessary for their specific function
- Regular security audits, penetration testing, and vulnerability assessments of phtttt's technical infrastructure
- Secure development practices and code review processes for platform updates
- Comprehensive audit logging of all access to systems containing personal data
- Staff data privacy training and confidentiality obligations
9.2 While phtttt maintains robust security controls, no online platform can guarantee absolute security. Players are encouraged to use strong, unique passwords, enable two-factor authentication in their account settings, and promptly report any suspected unauthorised access to their phtttt account.
10. Cookies & Tracking Technologies
10.1 phtttt.app uses cookies and similar tracking technologies to operate the platform, maintain your session, prevent fraud, and improve your experience. The following categories of cookies are used:
Essential Cookies
Strictly necessary for the platform to function. These cookies maintain your login session, apply security measures, and enable core platform features. Essential cookies cannot be disabled without preventing the platform from functioning correctly.
Functional Cookies
Used to remember your preferences — such as language settings, last-played games, and display preferences — to personalise your phtttt experience. Functional cookies are enabled by default but can be disabled in your browser settings.
Analytics Cookies
Used to collect anonymised or aggregated data about how players use phtttt.app, including which games are most popular, how players navigate the site, and where technical issues occur. This data is used solely to improve the platform and does not identify individual players.
Security Cookies
Used to detect fraudulent activity, prevent automated abuse, and verify that login attempts are legitimate. Security cookies are essential and cannot be disabled.
10.2 You can control non-essential cookies through your browser settings. Note that disabling certain cookies may affect the functionality of phtttt.app. For detailed information on managing cookies in your specific browser, consult your browser's help documentation.
11. Your Data Privacy Rights
11.1 As a data subject under the Philippine Data Privacy Act of 2012, you have the following rights with respect to your personal data held by phtttt:
| Right | Description |
|---|---|
| Right to Information | The right to be informed that your personal data is being collected and processed, including the purposes of processing. |
| Right to Access | The right to request a copy of the personal data phtttt holds about you, and information about how it is being used. |
| Right to Rectification | The right to request correction of inaccurate or incomplete personal data held by phtttt. |
| Right to Erasure | The right to request deletion of personal data that is no longer necessary, was collected without consent, or is being processed unlawfully — subject to phtttt's legal retention obligations. |
| Right to Object | The right to object to the processing of your personal data for direct marketing or processing based on legitimate interests. |
| Right to Data Portability | The right to receive your personal data in a structured, machine-readable format and to transmit it to another controller where technically feasible. |
| Right to Damages | The right to claim compensation for damages sustained as a result of inaccurate, incomplete, outdated, false, or unlawfully obtained personal data. |
| Right to Complain | The right to file a complaint with the National Privacy Commission (NPC) if you believe your rights under the DPA have been violated. |
11.2 To exercise any of the rights listed above, please submit a written request to phtttt's Data Protection Officer using the contact details in Section 15. phtttt will acknowledge your request within five (5) business days and respond substantively within thirty (30) calendar days, consistent with NPC guidelines.
11.3 phtttt may request additional information to verify your identity before processing a data rights request, to ensure that personal data is not disclosed to unauthorised individuals.
12. Children's Privacy & Underage Players
12.1 phtttt's Services are strictly for individuals aged 21 years and above. phtttt does not knowingly collect personal data from individuals under the age of 21, and collecting such data is contrary to phtttt's Terms & Conditions and Philippine gaming regulations.
12.2 If phtttt discovers or is informed that personal data has been collected from an individual under the age of 21, that data will be deleted promptly and the associated account will be suspended. The deposited amount will be returned to the originating payment method.
12.3 Parents or guardians who believe that an individual under the age of 21 has created a phtttt account or submitted personal data to phtttt.app are encouraged to contact the Data Protection Officer immediately using the contact details in Section 15.
21+ Age Gate: phtttt requires age verification via government-issued Philippine ID before processing any withdrawal. Accounts that cannot be verified as belonging to an individual aged 21 or above will be suspended pending investigation.
13. Cross-Border Data Transfers
13.1 phtttt's primary operations and data storage are based within the Philippines. However, certain third-party service providers — including game studios and cloud infrastructure providers — may process data outside of the Philippines.
13.2 Where personal data is transferred outside of the Philippines, phtttt ensures that appropriate safeguards are in place as required by the DPA and NPC regulations, including:
- Contractual clauses requiring overseas processors to maintain data protection standards equivalent to the DPA
- Transfer only to jurisdictions that provide an adequate level of protection for personal data
- Implementation of standard contractual data processing agreements with all overseas processors
13.3 phtttt does not transfer personal data to jurisdictions that have been specifically identified by the NPC as presenting inadequate data protection frameworks without implementing additional technical or contractual safeguards.
14. Policy Updates
14.1 phtttt reserves the right to update or amend this Privacy Policy at any time to reflect changes in applicable law, NPC guidance, phtttt's data processing activities, or industry best practice.
14.2 When material changes are made to this Policy, phtttt will notify registered players via SMS to the mobile number on file and/or via a prominent notice on phtttt.app, at least seven (7) days before the changes take effect.
14.3 The "Effective Date" at the top of this Policy indicates when the current version took effect. Continued use of phtttt's Services following the effective date of an updated Policy constitutes your acceptance of the revised terms.
14.4 phtttt encourages players to review this Policy periodically to stay informed of how their personal data is being protected and used.
15. Contact & Data Protection Officer
15.1 phtttt has appointed a Data Protection Officer ("DPO") as required under the Philippine Data Privacy Act. The DPO is responsible for overseeing phtttt's data protection compliance, handling data subject rights requests, and serving as the primary liaison with the National Privacy Commission.
15.2 For all data privacy inquiries, rights requests, or complaints, please contact phtttt's DPO through the following channels:
Data Protection Officer — phtttt Casino
Email: [email protected]
Subject Line: Data Privacy Request — [Your Full Name]
Response Time: Acknowledgement within 5 business days; substantive response within 30 calendar days
15.3 If you are not satisfied with phtttt's response to your data privacy inquiry or rights request, you have the right to lodge a complaint directly with the National Privacy Commission of the Philippines (NPC). Information about filing NPC complaints is available at the NPC's official government website.
15.4 For general customer support inquiries unrelated to data privacy, phtttt's 24/7 live chat support is available through the phtttt Casino platform for all registered players.