This Privacy Policy explains how philsot collects, uses, stores, and protects your personal information. We are committed to handling your data in full compliance with the Philippine Data Privacy Act of 2012.
This Privacy Policy applies to all personal data collected and processed by philsot in connection with your use of the philsot Platform at philsot.org. It forms part of the agreement between you and philsot together with our Terms & Conditions. By registering an Account or using the Platform, you acknowledge that you have read and understood this Policy.
philsot is committed to protecting the privacy and personal data of all players who use the philsot Platform. This Privacy Policy has been prepared in accordance with the Philippine Data Privacy Act of 2012 (Republic Act No. 10173, hereinafter "the DPA"), its Implementing Rules and Regulations, and the issuances of the National Privacy Commission (NPC) of the Philippines.
As a PAGCOR-licensed online casino operator, philsot is also subject to data handling obligations under PAGCOR's regulatory framework, which imposes additional requirements regarding identity verification, transaction recording, and regulatory reporting. These obligations operate in parallel with and are consistent with the DPA.
This Policy describes: the categories of personal data philsot collects; the purposes for which that data is processed; the lawful bases for processing; how long data is retained; who data may be shared with; the security measures we apply; and the rights available to you as a data subject under Philippine law.
We encourage you to read this Policy carefully. If you have any questions after reading it, please contact our Data Protection Officer using the details in Section 15.
The data controller responsible for your personal data collected through the philsot Platform is:
philsot
Platform: philsot.org
Regulatory Authority: Philippine Amusement and Gaming Corporation (PAGCOR)
License Type: Online Casino Operator (Philippines)
Data Protection Officer: See Section 15
Support Contact: [email protected]
philsot determines the purposes and means of processing your personal data and is accordingly the "personal information controller" as that term is defined under Section 3(h) of the DPA.
philsot collects the following categories of personal data in connection with providing, securing, and improving the Platform:
| Category | Data Types Collected | Mandatory? |
|---|---|---|
| Identity Data | Full legal name, date of birth, nationality, government-issued ID type and number (e.g., Philippine passport, driver's license, national ID) | Yes — KYC |
| Contact Data | Registered mobile number (Philippine format), email address, residential address (city, province) | Yes |
| Account Data | Username, encrypted password hash, account creation date, login timestamps, session data, device identifiers | Yes |
| Financial Data | GCash/Maya mobile number, partial bank account or card details (last 4 digits only), transaction amounts, deposit/withdrawal history | Yes — payments |
| Gaming Activity Data | Game sessions, bet amounts, game outcomes, balance movements, promotional participation records, sports betting history | Yes — PAGCOR |
| Technical Data | IP address, browser type and version, operating system, device type, screen resolution, referring URL, geolocation (country/city level) | Automatic |
| Communications Data | Live chat transcripts, email correspondence, Viber/Messenger message logs with philsot support | When contacted |
| KYC Documentation | Scanned or photographed copies of government-issued identification, proof of address, selfie/liveness check images (for identity verification) | Yes — KYC |
| Responsible Gaming Data | Self-exclusion records, deposit/loss limit settings, cool-off period activations, problem gambling self-assessment responses | Where applicable |
philsot does not collect special categories of personal data (as defined under Section 13 of the DPA, including racial or ethnic origin, health data, political opinions, or religious beliefs) except where strictly necessary for responsible gaming assessments, in which case explicit consent is obtained separately.
philsot collects personal data through the following channels and mechanisms:
philsot processes your personal data for the following specific, explicit, and legitimate purposes:
| Purpose | Data Categories Used |
|---|---|
| Account registration and management | Identity, Contact, Account Data |
| Age and identity verification (KYC — PAGCOR-mandated) | Identity Data, KYC Documentation |
| Processing deposits, withdrawals, and payment reconciliation | Identity, Financial, Account Data |
| Delivering gaming services and maintaining game integrity | Account, Gaming Activity, Technical Data |
| Fraud prevention and account security monitoring | Identity, Account, Technical, Financial Data |
| Anti-money laundering compliance (R.A. 9160) | Identity, Financial, Gaming Activity Data |
| Regulatory reporting to PAGCOR and the AMLC | Identity, Financial, Gaming Activity Data |
| Customer support and complaint resolution | Identity, Account, Communications Data |
| Responsible gaming monitoring and self-exclusion enforcement | Account, Gaming Activity, Responsible Gaming Data |
| Platform improvement and technical troubleshooting | Technical, Gaming Activity Data (aggregated/anonymized where possible) |
| Sending promotional communications (with consent) | Contact Data, Gaming Activity Data (for personalization) |
philsot processes your personal data on one or more of the following lawful bases as set out under Section 12 of the Philippine Data Privacy Act:
philsot does not sell, rent, or trade your personal data to third-party advertisers or marketing companies. We share personal data only in the following circumstances and only to the extent necessary for the stated purpose:
philsot engages third-party service providers who process personal data on our behalf and under our instruction. These include:
All service providers are bound by data processing agreements that require them to process data only on philsot's documented instructions, implement appropriate security measures, and not further disclose data to unauthorized third parties.
philsot will disclose personal data to competent Philippine authorities when required to do so by law, including:
In the event of a merger, acquisition, corporate restructuring, or sale of all or substantially all of philsot's assets, personal data held by philsot may be transferred to the acquiring or successor entity, subject to that entity providing equivalent privacy protections. philsot will notify affected players of any such transfer via email or prominent notice on the Platform.
philsot retains personal data only for as long as necessary to fulfill the purposes for which it was collected, to comply with legal and regulatory obligations, or as otherwise permitted by the DPA. The following retention periods apply:
| Data Category | Retention Period | Basis |
|---|---|---|
| Account and Identity Data | Duration of Account + 5 years after closure | PAGCOR / AML legal requirement |
| KYC Documentation | 5 years from Account closure | R.A. 9160 (AMLA) |
| Financial Transaction Records | 5 years from transaction date | R.A. 9160 / PAGCOR |
| Gaming Activity Logs | 5 years from session date | PAGCOR licensing condition |
| Customer Support Communications | 3 years from last communication | Legitimate interest (dispute resolution) |
| Self-Exclusion Records | Permanently retained | PAGCOR responsible gaming obligation |
| Marketing Consent Records | Until consent withdrawn + 1 year | DPA compliance |
| Technical / Log Data | 12 months | Security monitoring |
Upon expiry of the applicable retention period, personal data is securely deleted or anonymized such that it can no longer be associated with an identifiable individual, unless further retention is required by a specific legal obligation or ongoing regulatory inquiry.
philsot implements security measures consistent with the requirements of Section 20 of the Philippine Data Privacy Act and the NPC's standards for the protection of personal data. All security controls are reviewed regularly and updated in response to emerging threats.
The specific security measures philsot implements include, but are not limited to:
While philsot takes all reasonable steps to protect your personal data, no data transmission over the internet is entirely secure. Players are responsible for maintaining the security of their own Account credentials and for notifying philsot immediately of any suspected unauthorized access.
philsot uses cookies and similar tracking technologies on the Platform. Cookies are small data files stored on your device by your browser that help us deliver and improve the Platform experience.
| Cookie Type | Purpose | Required? |
|---|---|---|
| Essential Cookies | Session management, login authentication, security tokens, Platform functionality. Without these cookies, the Platform cannot function correctly. | Yes |
| Functional Cookies | Remembering user preferences such as language settings and "Remember Me" login options. Improve your Platform experience. | Optional |
| Analytics Cookies | Aggregated, anonymized data about how Players navigate the Platform — page views, session duration, navigation paths. Used to improve Platform design and performance. | Optional |
| Security Cookies | Fraud detection, bot prevention, and account security monitoring based on behavioral signals and device fingerprinting. | Yes |
philsot does not use third-party advertising cookies or tracking pixels that share your browsing data with external advertising networks.
You may control non-essential cookies through your browser settings. Disabling essential cookies will impair your ability to use the Platform. Please note that clearing cookies will log you out of your philsot Account.
Under the Philippine Data Privacy Act of 2012, you have the following rights as a data subject with respect to your personal data held by philsot. These rights are subject to applicable legal limitations and philsot's compliance obligations under PAGCOR regulations and the AMLA.
To exercise any of the above rights, please submit a written request to philsot's Data Protection Officer using the contact details in Section 15. philsot will respond to all data subject requests within 15 business days of receipt. Where requests are complex or numerous, the response period may be extended by a further 30 days, of which you will be notified.
Identity verification will be required before philsot processes a data subject access or erasure request, to ensure we do not disclose or delete data at the request of an unauthorized person.
21+ Restriction: The philsot Platform is strictly restricted to individuals aged 21 years and older. philsot does not knowingly collect personal data from individuals under 21 years of age. If philsot discovers that personal data has been collected from a person under 21, that data will be deleted immediately and the associated Account will be suspended. Parents or guardians who believe their child may have provided personal data to philsot should contact us immediately via the details in Section 15.
philsot enforces the 21+ age requirement through mandatory KYC identity verification at Account registration. All registrations require submission of a valid Philippine government-issued ID showing date of birth. Registration is not completed and Account access is not granted until identity and age have been verified to philsot's satisfaction.
Some of philsot's third-party service providers — including cloud infrastructure providers, game software suppliers, and fraud detection services — may process personal data outside the Philippines. Where such transfers occur, philsot ensures that they are conducted in compliance with Section 21 of the DPA and NPC Circular No. 16-01 governing cross-border data flows.
philsot implements the following safeguards for cross-border transfers:
Your personal data is never transferred to a jurisdiction or recipient that does not meet philsot's data protection standards. A list of the countries where philsot's key processors are located is available upon request from the Data Protection Officer.
14.1 philsot reserves the right to update or amend this Privacy Policy at any time to reflect changes in our data processing practices, new regulatory requirements, or improvements to how we protect your data.
14.2 Material changes to this Privacy Policy will be communicated to registered Players via email to the address on file and/or via a prominent notice on the Platform for a minimum of 7 days before the changes take effect.
14.3 Where changes are required to comply immediately with a new NPC or PAGCOR directive, philsot may implement those changes without advance notice. The effective date of such changes will be clearly stated on this page.
14.4 The date at the top of this page reflects the date this version of the Privacy Policy was last updated. We recommend reviewing this page periodically. Continued use of the Platform after the effective date of an amendment constitutes acceptance of the revised Policy.
For all privacy-related inquiries, data subject rights requests, data breach reports, and complaints, please contact philsot's designated Data Protection Officer:
philsot Data Protection Officer
Role: Data Protection Officer (DPO) — registered with the National Privacy Commission
Platform: philsot.org
Support Email: [email protected]
Subject Line: "Privacy / DPO Request — [Your Account Username]"
Live Chat: Available 24/7 via the Platform
Languages: Tagalog and English
Response Time: Within 15 business days of receipt
If you are not satisfied with philsot's response to your privacy inquiry, you have the right to lodge a complaint directly with the National Privacy Commission (NPC) of the Philippines, which is the competent supervisory authority for data protection matters in the Republic of the Philippines.
This Privacy Policy was last reviewed and approved by philsot's Data Protection Officer on 1 January 2026 and is effective as of that date. It supersedes all prior versions of philsot's Privacy Policy.
Six concrete commitments philsot makes to every Filipino player's personal data.
Your personal data at philsot — from your government ID upload to your transaction history — is encrypted using AES-256 both in transit and at rest. The same standard the Philippine banking system uses. Not marketing language; it's the actual implementation.
philsot does not sell, rent, or trade your personal data to advertisers, data brokers, or marketing companies. Your profile, your behavior, your contact details — none of it is a commercial product. The only entities that receive your data are those necessary to operate the Platform or those required by law.
philsot processes all personal data in strict compliance with the Philippine Data Privacy Act of 2012 (R.A. 10173). A registered Data Protection Officer oversees all privacy matters. Data subject rights requests are handled within 15 business days. Breaches are reported to the NPC within 72 hours.
philsot doesn't keep your data indefinitely. Each category of personal data has a defined retention period — primarily 5 years for KYC and financial records as required by the AMLA, and shorter periods for communications and analytics. When the period expires, data is securely deleted or anonymized.
Access, correction, erasure, portability, objection — all of the data subject rights under the Philippine DPA are available to you as a philsot player and are genuinely exercisable. Contact the DPO, get a response within 15 business days. Not a theoretical right buried in a policy document.
This Privacy Policy describes exactly what philsot collects, why, for how long, and who it is shared with. There are no undisclosed data practices. What is written in this Policy is what philsot does — nothing more. If practices change materially, players are notified before the change takes effect.
philsot's Data Protection Officer and support team are available 24/7 in Tagalog and English. If anything in this Privacy Policy is unclear, or if you want to exercise your data rights, reach out anytime.
21+ only. PAGCOR-licensed. Data protected under R.A. 10173.