Your privacy matters to phmacoa. This Privacy Policy explains in plain terms what personal data we collect, why we collect it, how we use and protect it, and what rights you have as a Filipino data subject under Republic Act No. 10173 — the Data Privacy Act of 2012 ("DPA"). Please read this document before using the phmacoa platform. If you have questions, contact our Data Protection Officer at the details in Section 15.
phmacoa ("we," "our," or "us") operates the online gaming platform at phmacoa.club, providing Filipino players with access to live casino games, JILI slots, virtual sports betting, bingo, and Super Keno under the regulatory oversight of the Philippine Amusement and Gaming Corporation (PAGCOR).
As a data controller operating in the Philippines, phmacoa is bound by the requirements of Republic Act No. 10173 (the Data Privacy Act of 2012), its Implementing Rules and Regulations, and the issuances of the National Privacy Commission ("NPC"). phmacoa is registered with the NPC as required for organisations processing sensitive personal information.
This Privacy Policy sets out the basis on which any personal data we collect from you, or that you provide to phmacoa, will be processed. This policy is incorporated by reference into phmacoa's Terms and Conditions, and together with those Terms, governs your relationship with the phmacoa platform.
This Privacy Policy applies to all personal data collected and processed by phmacoa in connection with:
This policy does not apply to third-party websites or services that may be linked to or from phmacoa.club, including the websites of payment providers such as GCash, Maya, BPI, or BDO. phmacoa encourages Members to review the privacy policies of any third-party services they use.
phmacoa collects the following categories of personal data about Members and prospective Members:
| Data Category | Examples of Data Collected |
|---|---|
| Identity Data | Full legal name, date of birth, nationality, government ID type and number (e.g., PhilSys ID, driver's licence, passport, UMID, SSS card), and photograph where required for identity verification. |
| Contact Data | Philippine mobile number (primary account identifier), email address (where provided), and home or mailing address (where required for verification). |
| Financial Data | Deposit and withdrawal transaction records, payment method details (e.g., registered GCash number, Maya account, bank account name — not card numbers), transaction amounts, and wallet balance history. |
| Gaming Activity Data | Games played, bets placed, game outcomes, session durations, win/loss records, bonus usage, and wagering history across all phmacoa game categories. |
| Device and Technical Data | IP address, device type and model, operating system, browser type and version, screen resolution, and device identifiers used to access phmacoa.club. |
| Usage Data | Pages visited on phmacoa.club, links clicked, time and duration of visits, referral source, navigation paths, and error logs. |
| Communications Data | Records of all interactions with phmacoa's customer support team, including live chat transcripts and email correspondence, and responses to phmacoa surveys or feedback requests. |
| Responsible Gaming Data | Deposit limit settings, self-exclusion requests, session time preferences, responsible gaming tool usage history, and any information shared with phmacoa in connection with a gambling-related concern. |
phmacoa does not collect or store full payment card numbers. All payment processing is handled by regulated third-party payment providers, and phmacoa receives only the minimum payment reference information required to reconcile transactions.
phmacoa collects personal data through the following means:
phmacoa processes Members' personal data for the following purposes:
Under the Data Privacy Act of 2012, phmacoa processes personal data on the following legal bases:
phmacoa does not sell, rent, or trade Members' personal data to third parties for their own commercial purposes. phmacoa will share Member data only in the following circumstances and only to the extent necessary:
All third-party service providers with whom phmacoa shares personal data are required to process that data only for the specified purposes and in accordance with phmacoa's instructions, and are contractually bound to maintain appropriate technical and organisational data protection measures.
phmacoa retains personal data only for as long as necessary to fulfil the purposes for which it was collected, subject to the following minimum retention periods:
| Data Category | Retention Period | Basis |
|---|---|---|
| Identity & KYC documents | 5 years from account closure | AMLC regulations, PAGCOR compliance |
| Financial transaction records | 5 years from transaction date | AMLC Act, BIR requirements |
| Gaming activity records | 3 years from account closure | PAGCOR licensing requirements |
| Customer support records | 3 years from last interaction | Contractual & legal dispute resolution |
| Marketing consent records | Until consent is withdrawn + 1 year | DPA consent records requirement |
| Technical / server log data | 12 months from collection | Security monitoring purposes |
| Self-exclusion records | Duration of exclusion + 5 years | PAGCOR responsible gaming requirements |
Upon expiry of the applicable retention period, phmacoa will securely delete or anonymise personal data in accordance with industry-standard data destruction procedures, unless continued retention is required by a specific ongoing legal obligation.
phmacoa has implemented the following technical and organisational security measures to protect Members' personal data against unauthorised access, disclosure, alteration, or destruction:
In the event of a personal data breach that is likely to result in a risk to the rights and freedoms of affected Members, phmacoa will notify the National Privacy Commission (NPC) within 72 hours of becoming aware of the breach, and will notify affected Members without undue delay, in accordance with the DPA's breach notification requirements.
phmacoa uses cookies and similar tracking technologies on phmacoa.club. A cookie is a small text file stored on your device by your browser when you visit a website. phmacoa uses the following categories of cookies:
phmacoa does not use third-party advertising or tracking cookies that would allow external advertising networks to build profiles of Members' behaviour across other websites. Members may manage cookie preferences through their browser settings; however, disabling strictly necessary cookies will impair the functionality of the phmacoa platform.
Under Republic Act No. 10173 (the Data Privacy Act of 2012), you have the following rights with respect to your personal data held by phmacoa:
To exercise any of the above rights, please contact phmacoa's Data Protection Officer using the details set out in Section 15. phmacoa will respond to all data subject rights requests within thirty (30) calendar days of receipt, as required by the DPA and its Implementing Rules and Regulations.
phmacoa will not charge any fee for processing a data subject rights request unless the request is manifestly unfounded, repetitive, or excessive, in which case phmacoa may charge a reasonable administrative fee or decline to act on the request, with written explanation provided to the Member.
phmacoa's platform is strictly for adults aged 21 years and above. phmacoa does not knowingly collect personal data from persons under the age of 21. The platform is not directed at, designed for, or accessible by minors.
In the event that phmacoa discovers or is informed that personal data has been collected from a person under the age of 21, phmacoa will:
Parents and legal guardians who believe a minor may have registered an account on phmacoa should contact phmacoa's Data Protection Officer immediately at the details in Section 15.
phmacoa's primary operations and data processing infrastructure are located within the Philippines. In some circumstances, personal data may be transferred to, or processed by, service providers and game suppliers operating from other countries in connection with the provision of cloud hosting, technical infrastructure, identity verification, or game software services.
Where such cross-border transfers occur, phmacoa ensures that appropriate safeguards are in place to protect the transferred data in accordance with the DPA and NPC standards. These safeguards include:
Members may request details of any cross-border data transfers applicable to their personal data by contacting phmacoa's Data Protection Officer.
phmacoa reserves the right to update or amend this Privacy Policy at any time to reflect changes in our processing activities, applicable Philippine law, NPC guidance, or PAGCOR regulatory requirements. The effective date at the top of this document will be updated to reflect the date of any material revision.
Where changes to this policy are material — that is, where they significantly affect Members' rights or phmacoa's data processing activities — phmacoa will provide advance notice to Members via their registered mobile number or email address, or via a prominent notice on phmacoa.club, at least seven (7) days before the revised policy takes effect.
Continued use of the phmacoa platform following the effective date of a revised Privacy Policy constitutes acceptance of the updated terms. Members who do not agree with any revisions should cease using the platform and contact phmacoa to request account closure.
The most current version of this Privacy Policy is always accessible at phmacoa.club/privacy-policy. phmacoa recommends that Members review this policy periodically to stay informed about how their personal data is handled.
phmacoa has appointed a Data Protection Officer (DPO) as required under the Data Privacy Act of 2012 for organisations processing sensitive personal information. The DPO is responsible for overseeing phmacoa's data protection compliance, handling data subject rights requests, and serving as the primary point of contact for data privacy matters.
To exercise your data subject rights, lodge a data privacy complaint, or enquire about phmacoa's personal data processing practices, you may contact the phmacoa Data Protection Officer through the following channels:
phmacoa will acknowledge all data privacy requests within three (3) business days and provide a substantive response within thirty (30) calendar days of receipt. Complex requests requiring additional investigation may take up to sixty (60) calendar days, in which case phmacoa will notify the Member of the extended timeframe with explanation.
If you are not satisfied with phmacoa's response to your data privacy concern, you have the right to escalate your complaint to the National Privacy Commission (NPC) of the Philippines, which is the government body responsible for enforcing the DPA. Information about how to file a complaint with the NPC is available through official Philippine government channels.
Regulatory oversight: phmacoa's data processing activities are subject to oversight by both the National Privacy Commission (NPC) and the Philippine Amusement and Gaming Corporation (PAGCOR). We welcome regulatory enquiries and cooperate fully with both agencies.
Six active commitments that put your data security at the centre of everything phmacoa does.
phmacoa's data practices are governed by Republic Act No. 10173 — the Philippine Data Privacy Act of 2012. We are registered with the National Privacy Commission and operate a full data governance framework with an appointed Data Protection Officer and documented processing records.
Every byte of data transmitted between your device and phmacoa's servers is protected by 256-bit SSL/TLS encryption — the same standard used by BPI, BDO, and Metrobank. Your personal information, payment details, and gaming data are never exposed in transit.
phmacoa does not sell, rent, or broker Member personal data to third parties for commercial gain — ever. Data shared with third parties is limited to what is strictly necessary for regulated purposes: payment processing, identity verification, and PAGCOR compliance. No advertising networks, no data brokers.
The DPA gives every Filipino data subject seven enforceable rights over their personal data. phmacoa actively supports all of them — access, rectification, erasure, objection, portability, consent withdrawal, and the right to complain to the NPC. Exercise any right by contacting our DPO directly.
phmacoa only keeps your data for as long as legally required or necessary for service delivery. Defined retention periods apply to every data category — from KYC documents retained for 5 years under AMLC requirements to server logs deleted after 12 months. No data is held indefinitely without justification.
In the unlikely event of a personal data breach, phmacoa is committed to notifying the NPC within 72 hours and affected Members without undue delay — as required by the DPA. We maintain an incident response plan specifically designed to protect Filipino Members' data rights in a breach scenario.
phmacoa's Privacy Policy and Terms & Conditions exist to ensure every Filipino player's data, funds, and gaming experience are protected to the highest standard. Explore the full phmacoa platform — live baccarat, JILI slots, bingo, Super Keno, and virtual sports. Minimum deposit ₱100 via GCash. Must be 21 or older.
PAGCOR-regulated | DPA-compliant | 21+ only