php99 Privacy Policy
At php99, your personal data belongs to you. This Privacy Policy explains exactly what information we collect, why we collect it, how we use and protect it, and what rights you hold as a Philippine-based player under the Data Privacy Act of 2012.
Six Ways php99 Protects Your Data
256-Bit SSL Encryption
Every data transmission between your device and php99's servers is protected by 256-bit SSL/TLS encryption — the same standard used by Philippine banks like BPI and BDO. Your login credentials, personal details, and financial transaction data are never transmitted in plain text.
Encrypted Data Storage
Personal data stored in php99's systems is encrypted at rest using industry-standard AES-256 encryption. Passwords are stored exclusively as salted cryptographic hashes — php99 staff cannot view your password in any form, which is why account recovery requires a reset rather than retrieval.
DPA 2012 Compliance
php99 processes personal data in compliance with Republic Act 10173 — the Philippine Data Privacy Act of 2012 — and the implementing rules issued by the National Privacy Commission (NPC). You retain all rights granted to data subjects under Philippine law, including the right to access, correct, and erasure.
No Data Selling
php99 does not sell, rent, or trade your personal information to third-party advertisers, data brokers, or marketing companies. Your data is used solely to provide, secure, and improve the php99 gaming platform and to comply with PAGCOR and Philippine legal obligations.
Minimal Data Collection
php99 collects only the personal data that is strictly necessary for account operation, identity verification, payment processing, and regulatory compliance. We do not collect sensitive personal information beyond what PAGCOR's KYC requirements mandate for licensed online gaming operators.
Your Data Controls
You can access, review, update, and in many cases delete your personal information directly from your php99 account settings. For requests that require manual processing — such as full account data export or erasure — php99's Data Protection Officer will respond within the timelines required by the Data Privacy Act of 2012.
01 Introduction
php99 ("php99", "we", "us", "our") operates the online gaming platform accessible at php99.cam, licensed and regulated by the Philippine Amusement and Gaming Corporation (PAGCOR) to provide online casino, sports betting, bingo, and related gaming services to eligible Filipino players.
This Privacy Policy describes how php99 collects, uses, stores, shares, and protects the personal data of individuals who visit our website, register an Account, or otherwise interact with the php99 Platform. It applies to all Philippine and international users of php99.cam.
php99 is committed to processing personal data transparently, lawfully, and in a manner consistent with the Republic Act No. 10173, otherwise known as the Data Privacy Act of 2012 (DPA), its Implementing Rules and Regulations (IRR), and the issuances of the National Privacy Commission (NPC) of the Philippines.
By registering a php99 Account or using the Platform, you acknowledge that you have read and understood this Privacy Policy and consent to the collection and processing of your personal data as described herein. If you do not agree, you must not register an Account or use the Platform.
02 Data Controller
For the purposes of the Data Privacy Act of 2012 and applicable data protection laws, php99 acts as the Personal Information Controller (PIC) with respect to the personal data of its registered Players and site visitors.
php99 has appointed a Data Protection Officer (DPO) responsible for overseeing compliance with data protection obligations, handling data subject rights requests, and serving as the point of contact with the National Privacy Commission. Contact details for php99's DPO are provided in Section 15 of this Policy.
03 Personal Data We Collect
3.1 Registration Data
When you create a php99 Account, we collect the following personal data:
- Full legal name (as it appears on your government-issued Philippine ID)
- Date of birth (to verify minimum age requirement of 21 years)
- Philippine mobile number (used for OTP two-factor authentication)
- Email address
- Username and hashed password (passwords are never stored in readable form)
- Residential address (required for KYC verification at higher account tiers)
3.2 KYC Verification Data
In compliance with PAGCOR regulations and Philippine anti-money laundering laws (Republic Act No. 9160, as amended), php99 may request the following documents for Know Your Customer (KYC) verification:
- Government-issued photo identification: UMID, Philippine passport, driver's license, SSS/GSIS card, or voter's ID
- Proof of address: recent utility bill, bank statement, or barangay clearance
- Selfie photograph with government ID for liveness verification
- Source of funds declaration for high-volume accounts as required under AMLA regulations
3.3 Financial Transaction Data
php99 collects data related to deposits and withdrawals processed through your Account, including:
- Payment method type (e.g., GCash, Maya, BPI, BDO)
- Transaction amounts, dates, and reference numbers
- GCash or Maya account identifiers (mobile number associated with the wallet)
- Bank account details where bank transfer methods are used
php99 does not store complete payment card numbers. Where card payments are processed, they are handled directly by PCI-DSS-compliant payment processors — php99 retains only the last four digits and card type for transaction reference purposes.
3.4 Gaming Activity Data
php99 logs gaming activity data associated with your Account, including:
- Game session history, wager amounts, and game outcomes
- Bonus claims and wagering progress
- Account balance history and transaction ledger
- Responsible gaming tool settings (deposit limits, session limits, self-exclusion status)
3.5 Technical and Device Data
When you access php99, we automatically collect technical data including:
- IP address and approximate geographic location (country/region level)
- Device type, operating system, and browser version
- Device fingerprint used for fraud detection and account security
- Session duration, pages visited, and navigation patterns within the Platform
- Error logs and crash reports
3.6 Communications Data
php99 retains records of communications between you and php99 support, including Live Chat transcripts, email correspondence, and any documented complaint or dispute. These records are retained for the purposes of resolving disputes, training, and regulatory compliance.
04 How We Collect Personal Data
php99 collects personal data through the following channels and methods:
- Directly from you: When you register an Account, complete KYC verification, make deposits or withdrawals, contact support, or participate in promotions.
- Automatically: Through cookies, browser local storage, server logs, and device fingerprinting when you access the Platform.
- From third parties: Identity verification providers, payment processors (GCash, Maya, bank APIs), fraud detection services, and PAGCOR's centralized player registry where applicable under our license conditions.
05 Purposes of Processing
php99 processes your personal data for the following specific purposes:
php99 does not process personal data for purposes incompatible with those listed above without obtaining separate, specific consent from the affected Player.
06 Legal Basis for Processing
php99 relies on the following legal bases under the Data Privacy Act of 2012 for processing your personal data:
- Contractual necessity: Processing required to perform the gaming services contract with you, including Account management, game delivery, and payment processing.
- Legal obligation: Processing required to comply with PAGCOR license conditions, Republic Act No. 9160 (Anti-Money Laundering Act), RA 10173 (Data Privacy Act), and other applicable Philippine laws.
- Legitimate interests: Processing for fraud detection, platform security, and responsible gaming monitoring, where such interests are not overridden by your data protection rights.
- Consent: Processing for optional communications such as promotional emails and SMS notifications, where you have provided explicit consent that may be withdrawn at any time.
07 Data Sharing and Disclosure
php99 does not sell, rent, or trade your personal data. php99 shares personal data only in the following limited circumstances:
7.1 Service Providers
php99 engages third-party processors to support Platform operations, including: payment processors (GCash/Maya integrations, banking APIs), KYC and identity verification providers, cloud hosting infrastructure providers, fraud detection and cybersecurity services, and customer support tooling. All processors are bound by data processing agreements that require them to process data only on php99's instructions and to maintain confidentiality and security standards at minimum equivalent to those required by the DPA.
7.2 Regulatory and Legal Disclosures
php99 will disclose personal data to PAGCOR, the Anti-Money Laundering Council (AMLC), the National Privacy Commission (NPC), and other competent Philippine government authorities when required to do so by applicable law, regulatory mandate, court order, or valid legal process. php99 will notify affected Players of such disclosures to the extent permitted by law.
7.3 Corporate Transactions
In the event of a merger, acquisition, sale of assets, or restructuring involving php99, personal data may be transferred to a successor entity, subject to that entity's assumption of the same data protection obligations described in this Policy. Affected Players will be notified prior to any such transfer taking effect.
7.4 Self-Exclusion Programs
Where a Player activates self-exclusion through php99 or through PAGCOR's national self-exclusion register, php99 may be required to share identifying information with PAGCOR's database to enforce cross-platform exclusion obligations.
php99 will never share your personal data with third-party advertising networks, data brokers, or marketing companies. If you receive a message claiming to be from php99 offering data-related services from a third party, treat it as a phishing attempt and report it to our support team.
08 International Data Transfers
php99's primary data processing infrastructure is located within the Philippines or in jurisdictions providing equivalent data protection standards as assessed by the National Privacy Commission. Where personal data is transferred to processors located outside the Philippines — for example, cloud hosting providers with regional data centers — php99 ensures that such transfers are protected by:
- Standard contractual clauses approved by the NPC or equivalent competent authority;
- Binding corporate rules where the processor is part of a corporate group with NPC-recognized cross-border transfer policies; or
- Your explicit prior consent to the specific transfer, where neither of the above safeguards is available.
php99 maintains a register of international data transfers and the safeguards applied, which is available to Players upon written request to the DPO.
09 Data Retention
php99 retains personal data only for as long as is necessary to fulfill the purposes for which it was collected, or as required by applicable law. The following general retention periods apply:
- Account data and KYC records: Retained for the duration of the Account and for a minimum of five (5) years following Account closure, in compliance with PAGCOR requirements and AMLA record-keeping obligations.
- Financial transaction records: Retained for a minimum of five (5) years from the date of each transaction, consistent with AMLA and BIR record-keeping requirements.
- Gaming activity logs: Retained for two (2) years from the date of each session for dispute resolution purposes, and in aggregated/anonymised form for longer periods for platform analytics.
- Customer support records: Retained for three (3) years from the date of the support interaction.
- Marketing communications consent records: Retained until withdrawal of consent and for one (1) year thereafter as evidence of consent management.
- Technical logs (IP addresses, device data): Retained for twelve (12) months for security and fraud investigation purposes.
Upon expiry of the applicable retention period, personal data is securely deleted or permanently anonymised in accordance with NPC-approved data disposal procedures.
10 Cookies and Tracking Technologies
10.1 What php99 Uses Cookies For
php99 uses cookies and similar technologies (local storage, session storage) exclusively for the following purposes:
- Essential/Functional cookies: Required for the Platform to operate — maintaining your login session, remembering your game preferences, and enabling two-factor authentication flows. These cannot be disabled without impairing core Platform functionality.
- Security cookies: Used for CSRF protection, device fingerprinting for fraud detection, and identifying suspicious login patterns.
- Analytics cookies: Anonymised/aggregated data on how Players navigate the Platform, used solely to improve user experience. php99 does not use third-party advertising analytics (e.g., Google Ads conversion tracking) on the Platform.
10.2 What php99 Does Not Do with Cookies
php99 does not use cookies to: serve you third-party advertising; track your activity across other websites not affiliated with php99; build advertising profiles; or share tracking data with social media platforms.
10.3 Managing Cookies
You may configure your browser to reject or delete cookies. Note that disabling essential cookies may prevent the Platform from functioning correctly — in particular, the login session and game continuity features rely on session cookies that cannot be functionally replaced by other mechanisms.
11 Your Data Subject Rights
Under Republic Act 10173 (Data Privacy Act of 2012) and its IRR, you have the following rights with respect to your personal data held by php99:
- Right to be Informed: The right to be notified of what personal data php99 collects and how it is processed — fulfilled by this Privacy Policy.
- Right of Access: The right to obtain a copy of your personal data held by php99, including information on the purposes of processing and any third parties to whom it has been disclosed.
- Right to Rectification: The right to correct inaccurate or incomplete personal data held by php99. You may update most account information directly through your Account settings.
- Right to Erasure or Blocking: The right to request deletion or blocking of your personal data where it is no longer necessary for the purposes for which it was collected, or where processing is unlawful. This right is subject to php99's legal retention obligations under PAGCOR, AMLA, and other applicable laws.
- Right to Object: The right to object to the processing of your personal data for direct marketing purposes at any time, with immediate effect. You may also object to other processing based on legitimate interests grounds.
- Right to Data Portability: The right to receive your personal data in a structured, commonly used, machine-readable format for transfer to another service, where technically feasible.
- Right to Damages: The right to be indemnified for damages sustained due to inaccurate, incomplete, outdated, false, unlawfully obtained, or unauthorised use of personal data in accordance with the DPA.
- Right to File a Complaint: The right to file a complaint with the National Privacy Commission (NPC) if you believe php99 has violated your data protection rights.
To exercise any of these rights, contact php99's Data Protection Officer at [email protected] with the subject line "Data Subject Rights Request". php99 will respond to all rights requests within fifteen (15) calendar days of receipt, in accordance with the DPA's required timelines.
12 Children's and Minors' Privacy
The php99 Platform is strictly for individuals aged twenty-one (21) years and above, in compliance with PAGCOR regulations. php99 does not knowingly collect personal data from any individual below the age of 21 years.
If php99 becomes aware that it has collected personal data from a person below 21 years of age, it will immediately suspend the associated Account, investigate the registration, delete the collected data (subject to any legal hold obligations), and report the incident as required by PAGCOR's age verification compliance procedures.
If you are a parent or guardian and believe that a minor has registered a php99 Account, contact php99 support immediately at [email protected]. We will act on such reports within 24 hours.
13 Security Measures
php99 implements a comprehensive set of technical and organisational security measures to protect personal data from unauthorized access, disclosure, alteration, destruction, and accidental loss:
- Encryption: 256-bit TLS/SSL for all data in transit; AES-256 encryption for data at rest.
- Access controls: Role-based access control (RBAC) limiting staff access to personal data on a strict need-to-know basis; multi-factor authentication required for all privileged system access.
- Two-factor authentication (2FA): OTP-based 2FA enforced for Player logins from unrecognised devices, reducing unauthorized account access risk.
- Penetration testing: Regular independent security assessments of the Platform and supporting infrastructure.
- Incident response: A documented data breach response plan consistent with NPC Circular 16-03 (Security of Personal Data in Government Agencies) and NPC Advisory 2021 equivalent standards. php99 will notify affected Players and the NPC of qualifying personal data breaches within seventy-two (72) hours of confirmation.
- Staff training: All php99 staff with access to personal data receive regular data protection and cybersecurity training.
Notwithstanding these measures, no internet-based platform can guarantee absolute security. If you suspect that your php99 Account has been accessed without authorization, contact php99 support immediately via Live Chat.
14 Changes to This Privacy Policy
php99 may update this Privacy Policy from time to time to reflect changes in our data processing practices, regulatory requirements, or Platform features. The most current version of this Policy will always be accessible at php99.cam/privacy-policy, with the "Last Updated" date prominently displayed at the top.
For material changes — including changes that affect how we use your personal data or your rights as a data subject — php99 will provide at least fourteen (14) days' advance notice via your registered email address or an in-Platform notification before the changes take effect.
Your continued use of the php99 Platform after a Policy change takes effect constitutes your acceptance of the updated Privacy Policy. If you do not accept the changes, you must stop using the Platform and may close your Account in accordance with the Account closure process described in our Terms & Conditions.
15 Contact Us & Data Protection Officer
For any questions, concerns, or formal requests relating to this Privacy Policy or to the processing of your personal data by php99, please contact our Data Protection Officer:
php99 Data Protection Officer
Email: [email protected]
(subject line: "Data Subject Rights Request" or "Privacy Enquiry")
Response time: Within fifteen (15) calendar days for data subject rights requests;
within five (5) business days for general privacy enquiries.
php99 Customer Support (General)
Available 24 hours a day, 7 days a week on Philippine Standard Time (PST).
Fastest channel: Live Chat on php99.cam — average response time under 2 minutes.
If you are not satisfied with php99's response to your privacy concern, you have the right to lodge a complaint with the National Privacy Commission of the Philippines:
National Privacy Commission (NPC)
5th Floor, Delegation Building, PICC Complex,
Pasay City, Metro Manila, Philippines 1307
Website: privacy.gov.ph (do not click — type manually in your browser)
Your Data Is Safe with php99
Play on a platform that takes data protection seriously — PAGCOR-licensed, DPA 2012-compliant, and built for Filipino players who expect both great gaming and genuine privacy.
Login to php99 Terms & Conditions