phl168 ("we," "us," "our," or the "Platform") is committed to protecting the privacy and personal data of every player and visitor who interacts with our platform at phl168.app. This Privacy Policy has been prepared in accordance with the Philippine Data Privacy Act of 2012 (Republic Act No. 10173), its Implementing Rules and Regulations, and the issuances of the National Privacy Commission (NPC).
This Privacy Policy applies to all personal data collected through the phl168 website, mobile interface, customer support channels, and any other touchpoint through which you interact with phl168. It describes:
- What categories of personal data phl168 collects from you;
- The purposes for which that data is collected and processed;
- The legal bases that justify our processing activities;
- How and with whom we may share your data;
- How long we retain your data;
- The rights you hold as a data subject under Philippine law; and
- How to exercise those rights or raise a concern with phl168.
By registering for a phl168 account or continuing to use the phl168 platform, you acknowledge that you have read and understood this Privacy Policy. If you do not agree with any part of this Policy, please discontinue use of the platform and contact our support team to close your account.
phl168 collects only the personal data that is necessary and proportionate to the purposes described in this Policy. The categories of personal data we collect include:
2.1 Registration & Identity Data
- Full legal name (as it appears on your government-issued ID)
- Date of birth (for age verification – players must be 21 years of age or older)
- Residential address (including city, province, and postal code)
- Email address and mobile number
- Username and encrypted password
- Nationality and country of residence
2.2 Identity Verification (KYC) Data
- Copies of government-issued identification documents (e.g., Philippine passport, PhilSys National ID, SSS ID, UMID, driver's license)
- Proof of address documents (e.g., utility bills, bank statements)
- Source of funds declarations where required by anti-money laundering (AML) regulations
- Selfie or liveness verification images where required
2.3 Financial & Transaction Data
- Deposit and withdrawal transaction records, including amounts, timestamps, and payment method references
- GCash account references, PayMaya account references, BPI/BDO/Metrobank account details (account name and last four digits only – full account numbers are not stored by phl168)
- Account balance history and bonus transaction records
2.4 Gaming Activity Data
- Game session logs, including games played, wager amounts, win/loss records, and session durations
- Responsible gaming tool usage (deposit limits, session limits, self-exclusion requests)
- Bonus and promotion participation records
2.5 Technical & Device Data
- IP address and approximate geolocation (country/region level)
- Device type, operating system, and browser type and version
- Unique device identifiers
- Login timestamps and session activity logs
2.6 Communications Data
- Records of your communications with phl168 customer support, including live chat transcripts and email correspondence
- Feedback, survey responses, and complaint records
phl168 does not collect sensitive personal information such as racial or ethnic origin, political opinions, religious beliefs, health data, or biometric data, except where a liveness check is required for KYC verification purposes, in which case such data is processed solely for identity verification and is not retained beyond the verification process.
phl168 collects personal data through the following means:
- Directly from you: When you register an account, complete KYC verification, make a deposit or withdrawal, contact customer support, or participate in promotions.
- Automatically: Through cookies, web beacons, and similar tracking technologies when you browse or use the phl168 platform. See Section 7 for full details on our cookie practices.
- From third-party service providers: Including payment processors (GCash, PayMaya, BPI, BDO, Metrobank), identity verification providers, and fraud detection services, where such data is necessary to provide the phl168 service or comply with legal obligations.
- From regulatory authorities: Where required by law, phl168 may receive information from PAGCOR or other competent Philippine authorities in connection with regulatory compliance or investigations.
phl168 uses the personal data we collect for the following purposes:
| Purpose |
Data Categories Used |
| Account registration and management |
Registration & Identity Data |
| Age verification (21+ requirement) |
Identity Data, KYC Data |
| KYC / AML compliance |
KYC Data, Financial Data |
| Processing deposits and withdrawals |
Financial & Transaction Data |
| Providing gaming services and support |
Gaming Activity Data, Communications Data |
| Fraud prevention and platform security |
Technical Data, Financial Data, KYC Data |
| Responsible gaming monitoring |
Gaming Activity Data, Registration Data |
| Customer support and dispute resolution |
Communications Data, Transaction Data |
| Platform improvement and analytics |
Technical Data, Gaming Activity Data (aggregated) |
| Promotional communications (with consent) |
Registration Data, Gaming Activity Data |
| Legal and regulatory compliance |
All categories as required by law |
phl168 will not use your personal data for any purpose that is incompatible with the purposes listed above without first obtaining your explicit consent or establishing a separate legal basis for the new processing activity.
Under the Philippine Data Privacy Act of 2012, phl168 relies on the following legal bases to process your personal data:
- Contractual Necessity: Processing is necessary to perform the contract between you and phl168 – specifically, to operate your account, process transactions, and deliver gaming services.
- Legal Obligation: Processing is required to comply with applicable Philippine laws and regulations, including AML obligations, PAGCOR regulatory requirements, and the Data Privacy Act itself.
- Legitimate Interests: Processing is necessary for phl168's legitimate interests in fraud prevention, platform security, responsible gaming monitoring, and improving our services, provided these interests are not overridden by your rights and freedoms.
- Consent: For optional processing activities such as sending promotional emails or SMS notifications, phl168 relies on your freely given, specific, informed, and unambiguous consent. You may withdraw this consent at any time without affecting the lawfulness of processing carried out before withdrawal.
phl168 does not sell, rent, or trade your personal data. We may share your data with the following categories of recipients only to the extent necessary and proportionate:
- Payment Processors: GCash, PayMaya, BPI, BDO, Metrobank, and other payment service providers, solely to process your deposit and withdrawal transactions.
- KYC & Identity Verification Providers: Third-party identity verification services engaged to assist with KYC compliance and age verification.
- Game Content Providers: Licensed game studios and live dealer operators whose games are available on the phl168 platform. These providers may receive session data necessary to deliver their games.
- Fraud Prevention & Security Services: Specialist providers engaged to detect and prevent fraudulent activity, money laundering, and unauthorized account access.
- Regulatory Authorities: PAGCOR, the National Privacy Commission, the Anti-Money Laundering Council (AMLC), and other competent Philippine government authorities, where disclosure is required by law or regulatory instruction.
- Legal & Professional Advisors: Lawyers, auditors, and other professional advisors engaged by phl168, subject to strict confidentiality obligations.
- Business Transfers: In the event of a merger, acquisition, or sale of all or part of phl168's business, your personal data may be transferred to the acquiring entity, subject to equivalent privacy protections.
All third-party service providers engaged by phl168 are contractually required to process your personal data only on phl168's instructions, to maintain appropriate security measures, and to comply with applicable Philippine data protection law.
phl168 uses cookies and similar tracking technologies to operate the platform, remember your preferences, and analyze usage patterns. The types of cookies we use are:
- Strictly Necessary Cookies: Essential for the platform to function. These include session authentication cookies and security tokens. These cookies cannot be disabled without affecting core platform functionality.
- Functional Cookies: Used to remember your preferences, such as language settings, display preferences, and responsible gaming tool configurations.
- Analytics Cookies: Used to collect aggregated, anonymized data about how players use the phl168 platform, helping us identify areas for improvement. No personally identifiable information is included in analytics reports.
- Security Cookies: Used to detect and prevent fraudulent activity, unauthorized access attempts, and bot traffic.
You may manage your cookie preferences through your browser settings. Please note that disabling certain cookies may affect the functionality of the phl168 platform. phl168 does not use third-party advertising or behavioral tracking cookies.
phl168 retains your personal data only for as long as necessary to fulfill the purposes for which it was collected, or as required by applicable law. Our standard retention periods are as follows:
- Account & Identity Data: Retained for the duration of your account relationship with phl168, plus a minimum of five (5) years following account closure, in compliance with AML record-keeping requirements under Philippine law.
- KYC Documents: Retained for a minimum of five (5) years from the date of verification, or longer if required by PAGCOR or AMLC regulations.
- Financial Transaction Records: Retained for a minimum of five (5) years from the date of each transaction, in accordance with AML and tax record-keeping obligations.
- Gaming Activity Logs: Retained for three (3) years from the date of each session, for responsible gaming monitoring and dispute resolution purposes.
- Customer Support Communications: Retained for two (2) years from the date of the last communication, for quality assurance and dispute resolution purposes.
- Technical & Device Data: Retained for twelve (12) months from collection, unless required for longer periods for security or fraud investigation purposes.
Upon expiry of the applicable retention period, personal data is securely deleted or anonymized in accordance with phl168's data disposal procedures.
phl168 implements a comprehensive set of technical and organizational security measures to protect your personal data against unauthorized access, disclosure, alteration, or destruction. These measures include:
- 256-Bit SSL/TLS Encryption: All data transmitted between your device and phl168 servers is encrypted using industry-standard SSL/TLS protocols.
- Encrypted Data Storage: Sensitive personal data, including KYC documents and financial records, is stored in encrypted form on secured servers.
- Access Controls: Access to personal data is restricted to authorized phl168 personnel on a strict need-to-know basis. All staff with access to personal data are subject to confidentiality obligations.
- Multi-Factor Authentication: Administrative access to phl168 systems containing personal data requires multi-factor authentication.
- Regular Security Audits: phl168 conducts regular security assessments and penetration testing to identify and remediate vulnerabilities.
- Incident Response: phl168 maintains a data breach response plan. In the event of a personal data breach that poses a risk to your rights and freedoms, phl168 will notify the National Privacy Commission and affected data subjects within the timeframes prescribed by the Data Privacy Act.
While phl168 takes all reasonable steps to protect your data, no internet transmission or electronic storage system is 100% secure. You are responsible for maintaining the confidentiality of your phl168 account credentials and for notifying us immediately if you suspect unauthorized access to your account.
Under the Philippine Data Privacy Act of 2012, you have the following rights with respect to your personal data held by phl168:
- Right to Be Informed: You have the right to be informed about how phl168 collects and processes your personal data. This Privacy Policy fulfills that obligation.
- Right of Access: You have the right to request a copy of the personal data phl168 holds about you, along with information about how it is being processed.
- Right to Rectification: You have the right to request correction of any inaccurate or incomplete personal data phl168 holds about you. You may update most account information directly through your phl168 account settings.
- Right to Erasure: You have the right to request deletion of your personal data where it is no longer necessary for the purposes for which it was collected, subject to phl168's legal retention obligations.
- Right to Object: You have the right to object to the processing of your personal data where phl168 relies on legitimate interests as the legal basis, or where your data is being processed for direct marketing purposes.
- Right to Data Portability: You have the right to receive a copy of the personal data you have provided to phl168 in a structured, commonly used, and machine-readable format.
- Right to Lodge a Complaint: If you believe phl168 has violated your data privacy rights, you have the right to lodge a complaint with the National Privacy Commission (NPC) of the Philippines.
To exercise any of the above rights, please contact the phl168 Data Protection Officer via the contact details provided in Section 13. phl168 will respond to all data subject requests within fifteen (15) business days of receipt. In complex cases, this period may be extended by a further fifteen (15) business days, with prior notification to you.
phl168 will not charge a fee for processing data subject requests unless the request is manifestly unfounded or excessive, in which case a reasonable administrative fee may apply.
phl168 is strictly an adult platform. In accordance with Philippine gaming law and PAGCOR regulations, phl168 is available only to individuals who are 21 years of age or older. phl168 does not knowingly collect personal data from individuals under the age of 21.
phl168 employs age verification procedures during the registration process to prevent minors from accessing the platform. If phl168 becomes aware that personal data has been collected from an individual under the age of 21, we will immediately suspend the relevant account, delete the personal data in question, and take appropriate steps to prevent recurrence.
If you are a parent or guardian and believe that your child has registered on phl168, please contact our support team immediately so that we can take prompt action.
phl168 reserves the right to update or amend this Privacy Policy at any time to reflect changes in our data processing practices, applicable law, or regulatory requirements. When material changes are made, phl168 will notify registered players via email or an in-platform notification at least seven (7) days before the changes take effect, where practicable.
The most current version of this Privacy Policy will always be available on this page, with the "Last Updated" date at the top reflecting the date of the most recent revision. We encourage you to review this Policy periodically to stay informed about how phl168 protects your personal data.
Your continued use of the phl168 platform following the effective date of any amendment constitutes your acknowledgment of the updated Privacy Policy. If you do not agree with the revised Policy, you must cease using phl168 and may request account closure in accordance with our Terms & Conditions.
If you have any questions, concerns, or requests relating to this Privacy Policy or phl168's data processing practices, please contact our Data Protection Officer (DPO) or customer support team through the following channels:
Live Chat
Available 24/7 via the chat icon on the phl168 platform. Fastest response for urgent account matters.
For formal data subject requests (access, rectification, erasure, portability), please email our DPO with the subject line "Data Subject Request – [Your Full Name]" and include a copy of a valid government-issued ID for identity verification purposes. We will acknowledge your request within three (3) business days and provide a full response within fifteen (15) business days.