phplush Privacy Policy
This Privacy Policy explains how phplush collects, uses, stores, shares, and protects your personal data. Your privacy is a core obligation — not an afterthought — and phplush is fully committed to compliance with Philippine data protection law.
Six key commitments phplush makes to every player. These summaries do not replace the full legal text below — please read the complete policy carefully.
RA 10173 Compliance
phplush operates in full compliance with the Philippines Data Privacy Act of 2012 (Republic Act 10173) and the implementing rules issued by the National Privacy Commission. Your rights as a data subject under Philippine law are fully respected.
Data Minimization
phplush collects only the personal information that is genuinely necessary for account operation, regulatory compliance, and service delivery. We do not collect data speculatively or beyond what our legitimate purposes require.
No Sale of Your Data
phplush does not sell, rent, or trade your personal information to third-party marketers or data brokers. Your data is shared only with service providers who support platform operation and with regulatory authorities as legally required.
Your Rights Are Exercisable
You have real, enforceable rights over your personal data under RA 10173 — including the right to access, correct, delete, and port your data. phplush has a designated Data Privacy Officer who handles all data subject requests.
Secure Data Handling
phplush uses industry-standard technical and organizational security measures to protect your personal data from unauthorized access, disclosure, alteration, or destruction — including SSL encryption, access controls, and regular security reviews.
Defined Retention Periods
phplush retains your personal data only for as long as necessary for the purposes for which it was collected, or as required by PAGCOR regulations and Philippine anti-money-laundering laws. Data is securely deleted or anonymized when retention is no longer justified.
How to Read This Policy: This Privacy Policy ("Policy") describes how phplush ("phplush," "we," "us," "our") — the operator of the online casino platform at phplush.win — processes the personal data of registered players and website visitors ("you," "User," "Data Subject"). By registering for a phplush account or continuing to use the phplush platform, you acknowledge that you have read and understood this Policy. This Policy is incorporated into and should be read alongside the phplush Terms & Conditions.
01 Introduction
phplush is committed to protecting the personal data of everyone who uses our platform. This commitment is grounded in Philippine law — specifically the Data Privacy Act of 2012 (Republic Act 10173, "DPA") and its Implementing Rules and Regulations issued by the National Privacy Commission ("NPC") — as well as in our obligations as a PAGCOR-licensed online casino operator.
We understand that trust is fundamental to the relationship between phplush and every Filipino player who chooses to deposit real money, share personal identification, and engage with our platform. Protecting your personal data is one of the clearest expressions of that trust we can make. This Policy describes in plain, specific terms exactly what data we collect, why we collect it, what we do with it, who we share it with, and what rights you have as a data subject under Philippine law.
If anything in this Policy is unclear or you wish to exercise any of your data subject rights, please contact our Data Privacy Officer using the details in Section 15.
02 Data Controller
For the purposes of the Philippines Data Privacy Act, the data controller responsible for your personal data is phplush, the operator of the online casino platform accessible at phplush.win. phplush determines the purposes and means of processing your personal data as described in this Policy.
phplush has designated a Data Privacy Officer ("DPO") as required under RA 10173 and NPC regulations. The DPO is responsible for overseeing phplush's compliance with the DPA, handling data subject rights requests, and serving as the primary contact point for the National Privacy Commission. The DPO's contact information is provided in Section 15 of this Policy.
03 Personal Data We Collect
The categories of personal data phplush collects depend on your relationship with the platform. The following table summarizes the main categories and their sources:
| Category | Examples | Source |
|---|---|---|
| Identity Data | Full legal name, date of birth, nationality, government ID number, ID document images | Provided directly by you during registration and KYC |
| Contact Data | Philippine mobile number, email address, residential address | Provided directly by you during registration |
| Financial Data | GCash account number, bank account details, transaction history, deposit and withdrawal records | Provided by you and generated automatically during platform use |
| Gaming Activity Data | Game session logs, wagers placed, game outcomes, win/loss records, betting patterns, bonus usage | Generated automatically during platform use |
| Technical Data | IP address, device type, operating system, browser type, session tokens, login timestamps | Collected automatically when you access phplush |
| Communications Data | Live chat transcripts, email correspondence, support ticket content | Generated when you contact phplush Customer Support |
| Responsible Gaming Data | Self-exclusion status, deposit limit settings, cooling-off period records, problem gambling flags | Generated from your use of phplush responsible gaming tools |
Sensitive Personal Information: Government-issued identification documents submitted for KYC purposes constitute sensitive personal information under RA 10173. phplush handles all sensitive personal information with heightened security measures and limits access to authorized personnel on a strict need-to-know basis.
04 How We Collect Your Data
phplush collects personal data through the following means:
4.1 Direct Collection
You provide personal data directly to phplush when you: register for a phplush account; complete KYC identity verification; make a deposit or request a withdrawal; contact Customer Support; participate in promotions; use responsible gaming tools; or update your account profile. The accuracy of directly provided data is your responsibility under the phplush Terms & Conditions.
4.2 Automated Collection
When you access and use the phplush platform, certain technical and gaming activity data is automatically collected by our systems. This includes server logs recording your IP address and session activity, in-game event data tracking wager and outcome information, device fingerprinting used for fraud prevention and account security, and cookie-based session management as described in Section 11.
4.3 Third-Party Sources
phplush may receive personal data about you from third-party sources including: payment processors (GCash, PayMaya, Philippine banks) confirming transaction status; KYC verification service providers confirming identity document authenticity; fraud prevention and AML screening services checking names against watchlists and sanctions databases; and PAGCOR, in the context of regulatory compliance obligations.
05 Purposes of Processing
phplush processes your personal data for the following specific purposes:
- Account Registration and Management: Creating, maintaining, and administering your phplush player account, verifying your identity, and enabling platform access.
- Know Your Customer (KYC) and Age Verification: Verifying that you are at least 21 years of age and that your identity and payment methods are legitimate, as required by PAGCOR and Philippine law.
- Payment Processing: Processing deposits, withdrawals, and internal wallet transactions; reconciling accounts; and communicating with payment providers.
- Game Operation and Dispute Resolution: Operating casino games, recording game outcomes, maintaining game logs for dispute resolution, and ensuring game integrity.
- Anti-Money Laundering (AML) Compliance: Monitoring transactions for suspicious activity, screening against sanctions lists, and reporting to the Anti-Money Laundering Council (AMLC) as required by RA 9160 (as amended).
- Fraud Prevention and Platform Security: Detecting and preventing fraudulent accounts, unauthorized access, bonus abuse, and other prohibited conduct described in the Terms & Conditions.
- Responsible Gaming: Operating deposit limits, self-exclusion tools, and session trackers; identifying players who may be experiencing gambling-related harm; and fulfilling PAGCOR's responsible gaming requirements.
- Customer Support: Responding to your inquiries, resolving complaints, and maintaining records of support interactions.
- Communications and Marketing: Sending you account notifications, transactional communications, and, where you have given consent or we have a legitimate interest, promotional communications about phplush offers and games. You may opt out of marketing communications at any time through your account settings.
- Legal and Regulatory Compliance: Fulfilling all obligations imposed on phplush by PAGCOR, the NPC, the AMLC, and other competent Philippine regulatory authorities.
- Platform Analytics and Improvement: Analyzing aggregated usage data to improve platform performance, user experience, and game library — using anonymized or pseudonymized data where possible.
06 Legal Bases for Processing
Under the Philippines Data Privacy Act, phplush processes your personal data on the following legal bases:
- Contractual Necessity: Processing required to perform the phplush Terms & Conditions — including account management, payment processing, and game operation — is necessary to fulfill the contract between you and phplush.
- Legal Obligation: Processing required to comply with applicable Philippine laws and regulations, including PAGCOR licensing requirements, the Anti-Money Laundering Act, and the Data Privacy Act itself.
- Legitimate Interests: Processing for fraud prevention, platform security, and responsible gaming operations, where phplush's interests in maintaining a safe and legally compliant platform do not override your data protection rights.
- Consent: Processing for direct marketing communications, where consent has been obtained and can be withdrawn at any time without affecting the lawfulness of prior processing.
07 Sharing Your Personal Data
phplush does not sell, rent, or trade your personal data. We share your data only in the following circumstances and with the following categories of recipient:
7.1 Service Providers
phplush engages third-party service providers who process personal data on our behalf and under our instructions, subject to appropriate data processing agreements. These include: payment processors (GCash, PayMaya, BDO, BPI, Metrobank, UnionBank); KYC and identity verification providers; fraud screening and AML compliance platforms; game content providers who operate live dealer studios; cloud hosting and infrastructure providers; and customer support platform operators. All service providers are required to maintain appropriate security standards and may only process your data for the purposes specified by phplush.
7.2 Regulatory Authorities
phplush is required to share personal data with Philippine regulatory authorities including PAGCOR (in the context of licensing compliance and audits), the Anti-Money Laundering Council (AMLC) (for suspicious transaction reports and covered transaction reports as required by RA 9160), the National Privacy Commission (NPC) (in the context of data breach notifications and compliance investigations), and law enforcement agencies acting under a valid legal order or warrant issued by a Philippine court.
7.3 Corporate Transactions
In the event of a merger, acquisition, or sale of phplush or its assets, your personal data may be transferred to the acquiring entity, subject to the same privacy protections described in this Policy and any required notifications to the NPC and to affected data subjects under RA 10173.
No Third-Party Marketing Disclosure: phplush does not share your personal data with third-party advertisers, data brokers, or marketing platforms for purposes unrelated to phplush's own services. Any marketing communications you receive will relate only to phplush products and promotions, and only where you have not opted out.
08 International Data Transfers
Some of phplush's service providers — including game content providers and cloud infrastructure operators — may be located outside the Philippines. Where personal data is transferred to recipients in other countries, phplush ensures that appropriate safeguards are in place as required by the NPC's implementing rules, including data processing agreements incorporating the NPC's standard contractual clauses or reliance on jurisdictions that the NPC has recognized as providing an adequate level of data protection.
phplush will not transfer your personal data to jurisdictions that the NPC has determined to provide inadequate data protection without your specific, informed consent.
09 Data Retention
phplush retains your personal data for the following periods, unless a longer retention period is required by applicable Philippine law:
- Account and Identity Data: For the duration of your active account plus five (5) years following account closure, as required by PAGCOR licensing conditions and AML regulations.
- Financial Transaction Records: For a minimum of ten (10) years following the date of each transaction, as required by the Anti-Money Laundering Act and PAGCOR financial record-keeping requirements.
- Game Activity Logs: For a minimum of three (3) years following the recorded activity, for dispute resolution purposes and regulatory audit compliance.
- KYC Documents: For the duration of your account plus five (5) years following account closure, consistent with PAGCOR KYC record-keeping obligations.
- Communications and Support Records: For three (3) years from the date of the communication, for dispute resolution and quality assurance purposes.
- Technical and Device Data: For twelve (12) months from collection, for fraud prevention and security purposes.
Upon expiry of the applicable retention period, your personal data will be securely deleted or irreversibly anonymized, unless phplush is subject to a legal hold or regulatory direction requiring continued retention.
10 Your Data Subject Rights
Under the Philippines Data Privacy Act (RA 10173), you have the following rights with respect to your personal data held by phplush. To exercise any of these rights, please contact our Data Privacy Officer using the details in Section 15.
Right to Be Informed
You have the right to be informed about how phplush processes your personal data. This Privacy Policy is the primary mechanism through which phplush fulfills this obligation. You may request additional specific information about processing activities involving your personal data at any time.
Right of Access
You have the right to request a copy of the personal data phplush holds about you, as well as information about the purposes for which it is processed, the categories of data held, and recipients to whom it has been disclosed. phplush will respond to verified access requests within thirty (30) days.
Right to Rectification
You have the right to request correction of any inaccurate or incomplete personal data phplush holds about you. Where phplush has shared the corrected data with third parties, we will notify them of the correction where feasible.
Right to Erasure
You have the right to request deletion of your personal data where the data is no longer necessary for the purposes for which it was collected, where you withdraw consent (where consent was the legal basis), or where processing is unlawful. This right is subject to overriding legal obligations — phplush cannot erase data that must be retained under PAGCOR regulations or AML law.
Right to Object
You have the right to object to processing based on legitimate interests, including processing for direct marketing purposes. Where you object to direct marketing, phplush will cease processing your data for that purpose immediately.
Right to Data Portability
You have the right to receive a copy of personal data you have provided to phplush in a structured, commonly used, and machine-readable format, and to transmit that data to another controller where technically feasible.
Right to File a Complaint
If you believe phplush has violated your data privacy rights, you have the right to file a complaint with the National Privacy Commission (NPC) of the Philippines. The NPC's contact details and complaint procedures are published on the NPC's official website.
Exercising Your Rights: To submit a data subject rights request, please contact our Data Privacy Officer at [email protected] with the subject line "Data Subject Request." You will be asked to verify your identity before your request is processed. phplush aims to respond to all verified requests within thirty (30) days, and within fifteen (15) days for urgent requests involving potential harm to your rights.
11 Cookies & Tracking Technologies
11.1 What Are Cookies
Cookies are small data files stored on your device when you visit the phplush platform. phplush uses cookies and similar technologies for the following purposes:
- Essential Cookies: Required for the platform to function — including session management (keeping you logged in), security tokens, and game state preservation. These cannot be disabled without breaking core platform functionality.
- Functional Cookies: Remembering your language and display preferences, and retaining non-essential account settings between sessions.
- Analytics Cookies: Collecting anonymized data about how players use the phplush platform — which pages are visited, how long sessions last, and where users encounter errors. This data is used in aggregate form only to improve the platform.
- Security and Fraud Prevention Cookies: Identifying suspicious login patterns, detecting automated bots, and supporting device fingerprinting for account security purposes.
11.2 Managing Cookies
You can control non-essential cookies through the cookie preferences panel accessible on the phplush platform, or through your browser's built-in settings. Blocking essential cookies will prevent you from using core phplush features including account login. phplush does not use third-party advertising cookies or allow third-party ad networks to place cookies on the phplush platform.
12 Security of Your Personal Data
phplush implements a comprehensive set of technical and organizational security measures to protect your personal data against unauthorized access, accidental loss, alteration, and disclosure. These measures include:
- SSL/TLS encryption for all data transmitted between your device and the phplush platform.
- Encryption of sensitive data fields including passwords (hashed with industry-standard algorithms) and payment instrument details at rest.
- Strict role-based access controls ensuring that only authorized personnel can access personal data, and only to the extent necessary for their specific job function.
- Regular internal security audits and vulnerability assessments of the phplush platform and infrastructure.
- Incident response procedures compliant with the NPC's Personal Data Breach Management Regulations, including the 72-hour notification requirement for high-risk breaches.
- Physical and logical access controls on data centers and servers hosting phplush data.
Data Breach Notification: In the event of a personal data breach that is likely to result in harm to affected data subjects, phplush will notify the National Privacy Commission within seventy-two (72) hours of becoming aware of the breach, and will notify affected individuals without undue delay, in accordance with RA 10173 and the NPC's Circular 16-03. Notification will be provided via the email address registered to your phplush account.
13 Minors and Age Restrictions
The phplush platform is strictly intended for adults aged 21 years and above, in compliance with PAGCOR regulations and Philippine gambling law. phplush does not knowingly collect personal data from persons under the age of 21.
If phplush becomes aware that personal data has been collected from a person under 21, we will immediately suspend the relevant account, notify the individual and any identifiable parent or guardian, delete the collected data to the extent not required for AML reporting purposes, and report the matter to PAGCOR as required by our licensing obligations.
If you believe that phplush may have received data from a person under 21, please contact our Data Privacy Officer immediately at the contact details in Section 15.
14 Changes to This Privacy Policy
phplush may update this Privacy Policy from time to time to reflect changes in our data processing practices, changes in Philippine law, NPC regulatory guidance, or changes to PAGCOR licensing requirements. When we make material changes to this Policy, we will:
- Update the "Effective Date" at the top of this document.
- Notify all registered phplush players via the email address on their account.
- Display a prominent notification on the phplush platform for a period of at least thirty (30) days following the change.
Your continued use of the phplush platform following the effective date of a revised Privacy Policy constitutes your acknowledgment of the updated Policy. Where changes require your consent under RA 10173, phplush will seek that consent separately before the revised processing commences.
15 Contact & Data Privacy Officer
For any questions, concerns, or requests related to this Privacy Policy or to phplush's processing of your personal data, please contact the phplush Data Privacy Officer:
- Data Privacy Officer Email: [email protected]
- General Support Email: [email protected]
- Live Chat: Available 24/7 through the in-platform support function on phplush.win
Please include "Privacy" or "Data Request" in the subject line of any email correspondence related to this Policy to ensure prompt routing to the Data Privacy Officer. phplush aims to acknowledge all privacy inquiries within five (5) business days and to provide a substantive response within thirty (30) calendar days.
If you are not satisfied with phplush's response to your privacy inquiry or believe your data rights have been violated, you have the right to escalate your complaint to the National Privacy Commission of the Philippines.
Entire Privacy Framework: This Privacy Policy, read together with the phplush Terms & Conditions, constitutes phplush's complete commitment to the lawful, fair, and transparent processing of your personal data. phplush's registration with the National Privacy Commission is maintained in accordance with NPC registration requirements for personal information controllers.
Questions About Your Privacy? We're Here
Our Data Privacy Officer and 24/7 support team are ready to help with any privacy questions or data subject rights requests. Sign in to manage your phplush account settings and privacy preferences.
Sign In to phplushphplush is a PAGCOR-regulated platform serving Filipino players aged 21 and above. Your personal data is handled in strict compliance with RA 10173.