Your privacy matters to phiwin. This Privacy Policy explains how phiwin collects, uses, processes, discloses, and protects your personal data when you access or use the phiwin platform at phiwin.vip. It is written in accordance with the Philippine Data Privacy Act of 2012 (Republic Act No. 10173) and its implementing rules. By registering an Account or continuing to use the phiwin Platform, you confirm that you have read and understood this Privacy Policy and consent to the processing of your personal data as described herein.
phiwin's data practices are governed by the Philippine Data Privacy Act of 2012 (RA 10173). Your rights as a Filipino data subject are protected and enforced in all our processes.
All personal and financial data transmitted to and from phiwin is encrypted using 256-bit SSL — the same standard applied by major Philippine banks and financial institutions.
As a data subject, you have the right to access, correct, erase, and object to the processing of your personal data held by phiwin — exercisable at any time through your Account or by contacting support.
phiwin operates under PAGCOR licensing. Certain data disclosures to PAGCOR and the Anti-Money Laundering Council (AMLC) are legally mandated and are carried out in compliance with applicable law.
phiwin does not sell, rent, or trade your personal data to third-party advertisers or marketers. Data is only shared with service providers necessary for platform operations, under strict confidentiality obligations.
In the event of a personal data breach that poses a real risk to your rights and freedoms, phiwin will notify affected players and the National Privacy Commission within the timeframes required under RA 10173.
phiwin ("phiwin," "we," "us," or "our"), the operator of the online gaming platform accessible at phiwin.vip, is the Personal Information Controller (PIC) for the purposes of the Philippine Data Privacy Act of 2012 (Republic Act No. 10173, "DPA") in respect of all personal data collected through the phiwin Platform.
As Personal Information Controller, phiwin determines the purposes and means of processing your personal data and is accountable for ensuring that all processing is carried out lawfully, transparently, and with appropriate safeguards as required under the DPA and its implementing rules and regulations (IRR) issued by the National Privacy Commission (NPC).
Where phiwin engages third-party service providers to process personal data on its behalf, those providers act as Personal Information Processors (PIP) and are contractually bound to process data only under phiwin's documented instructions and to implement appropriate security measures.
phiwin collects and processes the following categories of personal data, depending on how you interact with the Platform:
| Category | Specific Data Points | When Collected |
|---|---|---|
| Identity Data | Full legal name, date of birth, gender, government ID type and number (PhilSys, driver's licence, passport, SSS/UMID) | Registration & KYC |
| Contact Data | Philippine mobile number, email address, registered residential address | Registration |
| Financial Data | GCash account name/number, PayMaya account details, BPI/BDO/Metrobank/UnionBank account names (not full account numbers), deposit and withdrawal transaction records in PHP | Payment processing |
| Gaming Data | Bet history, game session logs, win/loss records, game preferences, responsible gaming limit settings | Platform usage |
| Technical Data | IP address, device type and OS, browser type, session cookies, login timestamps, geolocation (city/region level) | Automated — platform access |
| Communications Data | Support chat transcripts, email correspondence, survey responses, promotional opt-in/out records | Customer interactions |
| Sensitive Personal Data | Government-issued ID photographs submitted for KYC, and where voluntarily provided, self-exclusion reason | KYC / Responsible Gaming |
phiwin collects personal data through the following channels and mechanisms:
phiwin processes your personal data on the following legal bases under the DPA and its IRR:
phiwin uses the personal data we collect for the following purposes:
6.1 General Principle. phiwin does not sell, rent, or trade your personal data to any third party for commercial purposes. Data is disclosed to third parties only to the extent necessary for legitimate operational, legal, or regulatory purposes as described below.
6.2 Service Providers (Personal Information Processors). phiwin engages the following categories of third-party service providers who may process personal data on phiwin's behalf:
All service providers are bound by contractual data processing agreements requiring them to process personal data only under phiwin's instructions and to maintain appropriate security standards.
6.3 Regulatory and Legal Disclosures. phiwin is required by Philippine law to disclose certain data to:
7.1 What Are Cookies. Cookies are small text files placed on your device by the phiwin Platform when you visit or log in. They enable the Platform to recognise your device, maintain your session, and remember preferences across visits.
7.2 Types of Cookies Used by phiwin.
7.3 Managing Cookies. You may manage cookie preferences through your browser settings. Disabling strictly necessary cookies will impair your ability to log in and use the Platform. phiwin does not use third-party advertising or remarketing cookies.
8.1 Retention Principle. phiwin retains personal data only for as long as necessary to fulfil the purposes for which it was collected, or as required by applicable Philippine law and regulation. Retention periods are determined with reference to legal requirements, business necessity, and the rights of data subjects.
8.2 Specific Retention Periods.
8.3 Deletion. Upon expiry of the applicable retention period, personal data will be securely deleted or anonymised in accordance with phiwin's data disposal procedures. Anonymised data retained for analytics purposes does not identify individuals and falls outside the scope of this Privacy Policy.
9.1 Technical Safeguards. phiwin implements a comprehensive range of technical security measures to protect your personal data against unauthorised access, disclosure, alteration, and destruction:
9.2 Organisational Safeguards. phiwin's organisational data protection measures include:
9.3 Breach Response. In the event of a personal data breach, phiwin will follow its Incident Response Plan, assess the risk to data subjects, notify the National Privacy Commission within seventy-two (72) hours of becoming aware of a notifiable breach, and notify affected players without undue delay where the breach poses a real risk to their rights and freedoms.
The phiwin Platform primarily processes and stores data within infrastructure located in or connected to the Philippines. However, certain third-party service providers — including cloud hosting infrastructure providers and game software suppliers — may be located in, or process data from, jurisdictions outside the Philippines.
Where personal data is transferred outside the Philippines, phiwin ensures that appropriate safeguards are in place as required under Section 21 of the DPA and its IRR, including:
phiwin does not transfer your personal data internationally for purposes beyond those set out in this Privacy Policy. Game software providers receive only the minimum anonymised session data necessary for game delivery and do not receive personally identifiable information unless strictly required.
Under the Philippine Data Privacy Act of 2012, you have the following rights with respect to your personal data held by phiwin. These rights may be exercised at any time by contacting phiwin's Data Protection Officer through the contact details in Section 16:
12.1 Consent-Based Marketing. phiwin sends promotional emails, SMS notifications, and in-platform messages about bonuses, new games, and platform updates only to players who have opted in to receive such communications. Your consent to receive marketing is obtained at registration and can be updated at any time through your Account notification settings.
12.2 Opt-Out. You may opt out of marketing communications at any time by: (a) adjusting your notification preferences in your phiwin Account settings; (b) clicking the unsubscribe link in any promotional email; or (c) contacting phiwin customer support and requesting removal from all marketing communications.
12.3 Transactional Notifications. Opting out of marketing communications does not affect the delivery of transactional notifications — such as deposit confirmations, withdrawal processing updates, OTP messages, and security alerts — which are sent as essential account communications regardless of marketing preferences.
12.4 No Third-Party Marketing. phiwin does not disclose your contact details to any third-party advertisers or marketing agencies for their own marketing purposes.
The phiwin Platform is strictly restricted to persons aged twenty-one (21) years and above, as required by PAGCOR regulation. phiwin does not knowingly collect, process, or retain personal data from individuals under the age of 21.
Where phiwin discovers that personal data has been collected from a minor — including through an Account registered with false age information — the Account will be immediately suspended, all associated data will be handled in accordance with applicable law, and any funds deposited will be returned to the payment source, with all associated winnings voided.
The phiwin Platform may contain references or links to the websites of payment providers (such as GCash and PayMaya) and regulatory bodies. These third-party sites operate under their own privacy policies, which are independent of and unrelated to this Privacy Policy.
phiwin is not responsible for the privacy practices or content of any third-party website. We recommend reviewing the privacy policy of any third-party site before submitting personal data to it. The presence of a reference to a third-party service on the phiwin Platform does not constitute phiwin's endorsement of that service's privacy practices.
phiwin reserves the right to update or amend this Privacy Policy at any time to reflect changes in our data practices, applicable law, PAGCOR requirements, or NPC guidance. The "Last Updated" date and version number at the top of this page will be updated whenever material changes are made.
Where changes are material — such as a significant change to the categories of data collected, the purposes for which it is used, or the third parties with whom it is shared — phiwin will notify active players via their registered email address or via a notice displayed upon next login. Your continued use of the phiwin Platform following the effective date of any amendment constitutes your acceptance of the updated Privacy Policy.
Previous versions of this Privacy Policy are available on request by contacting phiwin's Data Protection Officer. phiwin recommends reviewing this page periodically to stay informed about how your data is protected.
phiwin has designated a Data Protection Officer (DPO) as required under the Philippine Data Privacy Act. The DPO is responsible for overseeing compliance with the DPA, handling data subject requests, and serving as phiwin's point of contact with the National Privacy Commission.
For any questions, concerns, or requests relating to this Privacy Policy or your personal data, including the exercise of your data subject rights, you may contact phiwin through the following:
phiwin's customer support and DPO team include Tagalog-fluent staff to assist Filipino players across Metro Manila, Cebu, Davao, and the rest of the Philippines. Response times for data subject requests are within thirty (30) calendar days of receipt of a verifiable request, as required under the DPA.
If you are not satisfied with phiwin's handling of a data protection matter, you have the right to lodge a complaint with the National Privacy Commission of the Philippines through its official government channels.
Play with confidence — phiwin protects your personal data under the Philippine Data Privacy Act and PAGCOR regulation.
Play at phiwin Learn About phiwin