phlwin Privacy Policy
Your privacy matters to us. This page explains exactly what personal data phlwin collects, how we use it, who we share it with, and what rights you have as a Filipino player on our platform.
Privacy at a Glance
Before diving into the full legal text, here is a plain-language summary of the six most important things phlwin does to protect your personal information.
Encrypted Storage
All personal data stored on phlwin servers is encrypted at rest using industry-standard AES-256 encryption. Your account credentials are hashed and salted — we cannot read your password, and neither can anyone else.
No Data Selling
phlwin does not sell, rent, or trade your personal data to third-party marketers. Your information is used solely to operate your account, process transactions, and comply with our regulatory obligations under PAGCOR.
Your Rights
As a phlwin player, you have the right to access, correct, and request deletion of your personal data at any time. You can also request a copy of all data we hold about you by contacting our support team.
Cookie Transparency
phlwin uses cookies strictly for platform functionality, session management, and analytics. We do not use third-party advertising cookies. You can manage your cookie preferences at any time through your browser settings.
Secure Transmission
All data transmitted between your device and phlwin is protected by TLS 1.3 encryption. Look for the padlock icon in your browser's address bar — that confirms your connection to phlwin is secure at all times.
Retention Limits
phlwin retains your personal data only for as long as necessary to fulfil the purposes described in this policy, or as required by Philippine law and PAGCOR regulations. Data no longer needed is securely deleted or anonymised.
This Privacy Policy ("Policy") describes how phlwin ("phlwin", "we", "us", "our") collects, uses, stores, and protects the personal information of users ("you", "Player") who access or use the phlwin platform at phlwin.one. By registering an account or using our services, you acknowledge that you have read and understood this Policy and consent to the processing of your personal data as described herein.
Introduction
phlwin is committed to protecting the privacy and personal data of every player who uses our platform. We understand that trust is the foundation of any good relationship — and that is especially true when it comes to how we handle your information. This Policy has been written to be as clear and straightforward as possible, so you always know exactly where you stand.
This Policy applies to all personal data collected through the phlwin website at phlwin.one, any mobile-optimised versions of the site, and all services, games, and features offered through the platform. It covers data collected during registration, during gameplay, during financial transactions, and through your general use of the phlwin platform.
phlwin operates in compliance with the Republic Act No. 10173, also known as the Data Privacy Act of 2012 of the Philippines, and its implementing rules and regulations. We are also guided by the standards set by the National Privacy Commission (NPC) of the Philippines. Where our operations intersect with international data protection standards, we apply equivalent protections.
If you have any questions about this Policy or about how phlwin handles your personal data, please contact our Data Protection Officer using the details provided in Section 13 of this Policy.
Data We Collect
phlwin collects personal data from you in several ways: directly when you provide it to us during registration or account management, automatically when you use the platform, and from third parties such as payment processors and identity verification providers. The categories of personal data we collect are described below.
2.1 Registration & Account Data
When you create a phlwin account, we collect the following information:
- Full legal name as it appears on your government-issued ID
- Date of birth (to verify the 21+ age requirement)
- Residential address (including barangay, city, province, and postal code)
- Email address
- Mobile phone number
- Username and encrypted password
- Nationality and country of residence
2.2 Identity Verification (KYC) Data
As part of our Know Your Customer (KYC) obligations under PAGCOR regulations and anti-money laundering laws, we may collect:
- Copies of government-issued photo ID (e.g., Philippine passport, driver's licence, SSS/UMID card, PhilSys national ID)
- Proof of address documents (e.g., utility bill, bank statement)
- Selfie or liveness verification image for identity matching
- Source of funds documentation where required by regulation
2.3 Financial & Transaction Data
When you make deposits or withdrawals on phlwin, we collect:
- Payment method details (e.g., GCash mobile number, PayMaya account reference, BPI/BDO/Metrobank account details — we do not store full bank account numbers)
- Transaction amounts, dates, and reference numbers
- Deposit and withdrawal history
- Bonus and promotional credit history
2.4 Gaming Activity Data
We collect records of your activity on the phlwin platform, including:
- Games played, bet amounts, and game outcomes
- Session duration and login/logout timestamps
- Responsible gaming tool usage (deposit limits, self-exclusion requests)
- Customer support interactions and chat transcripts
2.5 Technical & Device Data
When you access phlwin, our systems automatically collect certain technical information:
- IP address and approximate geolocation
- Device type, operating system, and browser version
- Pages visited, links clicked, and time spent on each page
- Referring URL (the page you visited before arriving at phlwin)
- Cookie identifiers and session tokens
How We Use Your Data
phlwin uses the personal data we collect for the following purposes. We only process your data where we have a valid legal basis for doing so, as described in Section 4.
| Purpose | Data Used |
|---|---|
| Creating and managing your phlwin account | Registration data, KYC data |
| Processing deposits and withdrawals | Financial data, KYC data |
| Verifying your identity and age (21+) | KYC data, registration data |
| Providing customer support | Account data, support interaction records |
| Detecting and preventing fraud and money laundering | All categories of data |
| Complying with PAGCOR and legal obligations | All categories of data |
| Sending account-related notifications | Email address, mobile number |
| Improving platform performance and user experience | Technical data, gaming activity data |
| Responsible gaming monitoring and intervention | Gaming activity data, financial data |
| Sending promotional offers (where you have opted in) | Email address, mobile number, gaming preferences |
phlwin does not use your personal data for automated decision-making that produces legal or similarly significant effects without human review. Where automated tools are used to flag accounts for fraud or responsible gaming review, a member of the phlwin compliance team will review the flagged account before any action is taken.
Legal Basis for Processing
Under the Data Privacy Act of 2012 (Republic Act No. 10173) and its implementing rules, phlwin processes your personal data on the following legal bases:
- Contractual necessity: Processing required to fulfil our obligations to you under the phlwin Terms & Conditions — including account management, payment processing, and game provision.
- Legal obligation: Processing required to comply with applicable Philippine laws and PAGCOR regulations, including anti-money laundering (AMLA) obligations, KYC requirements, and tax reporting.
- Legitimate interests: Processing necessary for phlwin's legitimate business interests, including fraud prevention, platform security, and improving our services — provided these interests are not overridden by your rights and interests.
- Consent: Processing based on your freely given, specific, and informed consent — primarily for marketing communications. You may withdraw your consent at any time by updating your communication preferences in your account settings or by contacting support.
Data Sharing & Disclosure
phlwin does not sell, rent, or trade your personal data to third parties for their own marketing purposes. We share your data only in the circumstances described below, and only to the extent necessary for the stated purpose.
5.1 Service Providers
phlwin works with carefully selected third-party service providers who process personal data on our behalf. These include:
- Payment processors: GCash, PayMaya, BPI, BDO, Metrobank — to process your deposits and withdrawals in Philippine Peso.
- KYC and identity verification providers: To verify your identity and age as required by PAGCOR regulations.
- Game providers: Jili, PG Soft, Pragmatic Play, and other licensed game suppliers — limited technical data is shared to facilitate gameplay and resolve disputes.
- Cloud infrastructure providers: For secure hosting and data storage.
- Customer support platform providers: To facilitate live chat and email support.
All third-party service providers are contractually required to process your data only for the specified purpose, to maintain appropriate security standards, and to comply with applicable data protection laws.
5.2 Regulatory & Legal Disclosure
phlwin may disclose your personal data to regulatory authorities, law enforcement agencies, or courts where required to do so by applicable Philippine law, by a valid court order, or by a lawful request from PAGCOR or the Anti-Money Laundering Council (AMLC). In such cases, phlwin will disclose only the minimum data necessary to comply with the legal obligation.
5.3 Business Transfers
In the event of a merger, acquisition, or sale of all or part of phlwin's business, your personal data may be transferred to the acquiring entity as part of the transaction. You will be notified of any such transfer and of any changes to this Privacy Policy that result from it.
phlwin will never share your personal data with third-party advertisers, data brokers, or marketing companies. If you receive unsolicited communications claiming to be from phlwin, please report them to our support team immediately.
Cookies & Tracking Technologies
phlwin uses cookies and similar tracking technologies to operate the platform, remember your preferences, and understand how players use our services. This section explains what cookies we use and how you can manage them.
6.1 What Are Cookies?
Cookies are small text files placed on your device by a website when you visit it. They allow the website to remember information about your visit — such as your login session, language preference, and display settings — so you do not have to re-enter this information every time you return.
6.2 Types of Cookies We Use
| Cookie Type | Purpose | Can Be Disabled? |
|---|---|---|
| Strictly Necessary | Session management, login authentication, security tokens. Required for the platform to function. | No — disabling these will prevent login |
| Functional | Remembering your language, display preferences, and responsible gaming settings. | Yes — via browser settings |
| Analytics | Understanding how players navigate the platform so we can improve the user experience. Data is aggregated and anonymised. | Yes — via browser settings |
| Security | Detecting fraudulent activity, bot traffic, and suspicious login attempts. | No — required for platform security |
phlwin does not use third-party advertising cookies or cross-site tracking cookies. You can manage or delete cookies at any time through your browser settings. Note that disabling strictly necessary or security cookies will affect your ability to use the phlwin platform.
Data Retention
phlwin retains your personal data for as long as is necessary to fulfil the purposes described in this Policy, or as required by applicable Philippine law and PAGCOR regulations. The following retention periods apply:
- Account and KYC data: Retained for the duration of your account and for a minimum of 5 years after account closure, as required by anti-money laundering regulations.
- Transaction records: Retained for a minimum of 5 years from the date of the transaction, in compliance with AMLC and BIR requirements.
- Gaming activity records: Retained for 3 years from the date of the activity, or longer if required for dispute resolution or regulatory purposes.
- Customer support records: Retained for 2 years from the date of the last interaction.
- Marketing consent records: Retained until you withdraw your consent, plus 1 year for compliance documentation purposes.
- Technical and device data: Retained for 12 months from collection, after which it is anonymised or deleted.
When personal data is no longer required, phlwin securely deletes or anonymises it in accordance with our data disposal procedures. Anonymised data (from which you cannot be identified) may be retained indefinitely for statistical and analytical purposes.
Data Security
phlwin takes the security of your personal data seriously and implements a range of technical and organisational measures to protect it against unauthorised access, disclosure, alteration, or destruction.
Security Measures in Place:
TLS 1.3 encryption for all data in transit · AES-256 encryption for data at rest · Bcrypt password hashing · Multi-factor authentication options · Regular penetration testing · 24/7 security monitoring · Role-based access controls for staff · Regular security audits
While phlwin implements robust security measures, no online platform can guarantee absolute security. You also play an important role in keeping your account secure. You should use a strong, unique password for your phlwin account, enable any available two-factor authentication, and never share your login credentials with anyone. phlwin will never ask for your password via chat, email, or phone.
In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, phlwin will notify the National Privacy Commission (NPC) within 72 hours of becoming aware of the breach, and will notify affected players without undue delay, in accordance with the Data Privacy Act of 2012.
Your Data Rights
Under the Data Privacy Act of 2012 (Republic Act No. 10173), you have the following rights with respect to your personal data held by phlwin. To exercise any of these rights, please contact our Data Protection Officer using the details in Section 13.
phlwin will respond to all data rights requests within 30 days of receipt. In complex cases, this period may be extended by a further 30 days, in which case we will notify you of the extension and the reason for it. There is no charge for exercising your data rights, unless requests are manifestly unfounded or excessive.
If you are not satisfied with phlwin's response to a data rights request, you have the right to lodge a complaint with the National Privacy Commission of the Philippines (NPC).
Children & Minors
21+ Only: phlwin is strictly an adult gaming platform. You must be at least 21 years of age to register and use phlwin, in accordance with Philippine gaming regulations. phlwin does not knowingly collect personal data from persons under the age of 21.
During the registration process, phlwin requires all applicants to provide their date of birth and to submit a government-issued photo ID for KYC verification. This process is designed to prevent underage individuals from accessing the platform. Any account found to belong to a person under the age of 21 will be immediately suspended, all funds will be frozen pending investigation, and the matter will be reported to the relevant authorities in accordance with Philippine law.
If you believe that a minor has registered on phlwin or has accessed the platform using your account, please contact our support team immediately. phlwin takes underage gambling extremely seriously and will act swiftly on any such report.
Parents and guardians are encouraged to use parental control software to prevent minors from accessing online gaming platforms. phlwin supports responsible gaming initiatives and works with organisations dedicated to protecting young people from the harms of gambling.
International Data Transfers
phlwin primarily stores and processes your personal data within the Philippines. However, some of our third-party service providers — including cloud infrastructure providers and certain game suppliers — may process data in other countries. Where personal data is transferred outside the Philippines, phlwin ensures that appropriate safeguards are in place to protect your data to a standard equivalent to that required under the Data Privacy Act of 2012.
These safeguards may include contractual clauses approved by the National Privacy Commission, binding corporate rules, or transfers to countries that have been assessed as providing an adequate level of data protection. By using the phlwin platform, you acknowledge and consent to the transfer of your personal data to countries outside the Philippines where necessary for the provision of our services, subject to the safeguards described above.
Regardless of where your data is processed, phlwin applies the same privacy protections described in this Policy. Your rights under the Data Privacy Act of 2012 remain fully applicable to all processing of your personal data, wherever it takes place.
Policy Updates
phlwin may update this Privacy Policy from time to time to reflect changes in our data processing practices, changes in applicable law, or improvements to our platform. When we make material changes to this Policy, we will notify you by posting a prominent notice on the phlwin platform and, where appropriate, by sending a notification to the email address associated with your account.
The "Last Updated" date at the top of this Policy indicates when the most recent changes were made. We encourage you to review this Policy periodically to stay informed about how phlwin protects your personal data. Your continued use of the phlwin platform after the effective date of any updated Policy constitutes your acceptance of the changes.
If you do not agree with any changes to this Policy, you should stop using the phlwin platform and may request the closure of your account by contacting our support team. Upon account closure, phlwin will retain your data only for as long as required by law, as described in Section 7.
Contact Us
If you have any questions, concerns, or requests relating to this Privacy Policy or to the way phlwin processes your personal data, please contact our Data Protection Officer using the details below. We are committed to responding to all privacy-related enquiries promptly and thoroughly.
phlwin Data Protection Officer
Email: [email protected]
Platform: Live chat available after login at phlwin.one
Response time: Within 3 business days for general enquiries; within 30 days for formal data rights requests
Business hours: Monday to Sunday, 9:00 AM – 9:00 PM Philippine Standard Time (PST)
If you are not satisfied with our response, you have the right to lodge a complaint with the National Privacy Commission of the Philippines (NPC). The NPC is the government body responsible for administering and implementing the Data Privacy Act of 2012 and for ensuring compliance with its provisions.
phlwin is committed to resolving all privacy concerns fairly and transparently. We treat every data rights request with the same level of care and respect, whether you are a new player from Quezon City or a long-time member from Cebu or Davao.
Ready to Play with Confidence?
Now that you know exactly how phlwin protects your data, join thousands of Filipino players who trust phlwin for a safe, secure, and exciting gaming experience.
21+ only. Please gamble responsibly. phlwin supports responsible gaming.