This Privacy Policy applies to all personal data collected and processed by phingo in connection with the phingo.one platform. By registering an account or continuing to use phingo, you acknowledge that you have read and understood this policy. If you do not agree, please discontinue use and request account closure.
1. Definitions
For the purposes of this Privacy Policy, the following terms have the meanings set out below:
- "Personal Data" means any information relating to an identified or identifiable natural person, including name, contact details, government identification numbers, financial information, and device identifiers.
- "Processing" means any operation performed on Personal Data, including collection, recording, storage, use, disclosure, erasure, or destruction.
- "Data Subject" means the individual to whom the Personal Data relates — in this context, a phingo member or visitor to phingo.one.
- "Data Controller" means the entity that determines the purposes and means of processing Personal Data. phingo is the Data Controller for all Personal Data collected through phingo.one.
- "Third Party" means any entity other than phingo and the Data Subject, including payment processors, game software providers, and regulatory bodies.
- "PDPA" refers to the Philippine Data Privacy Act of 2012 (Republic Act No. 10173) and its implementing rules and regulations.
2. Data Controller Identity
phingo operates phingo.one and acts as the Data Controller for all personal information collected through the platform. phingo is responsible for ensuring that Personal Data collected from Filipino members and platform visitors is processed lawfully, fairly, and transparently in accordance with the PDPA.
If you have any questions regarding how phingo handles your Personal Data, wish to exercise your data rights, or need to report a data concern, please contact us using the details provided in Section 14 of this Policy.
3. Personal Data We Collect
phingo collects the following categories of Personal Data from members and platform visitors:
- Identity Information: Full legal name, date of birth, nationality, and gender as provided at registration and during KYC verification.
- Contact Information: Philippine mobile number, email address, and residential address.
- Government Identification: Type and number of Philippine government-issued ID submitted for KYC (e.g., PhilSys National ID, Passport, Driver's Licence, SSS/GSIS ID, Voter's ID). phingo does not retain full copies of identification documents beyond the period required by applicable law.
- Financial Information: GCash or Maya account references, bank account details (where used for deposits or withdrawals), transaction history, deposit amounts, and withdrawal requests. Full payment card numbers are never stored by phingo — card transactions are processed by certified payment processors.
- Gaming Activity: Game sessions played, wagers placed, game outcomes, balance history, and bonus usage. This data is used for account management, fraud prevention, and responsible gaming monitoring.
- Technical and Device Data: IP address, browser type, operating system, device identifiers, session duration, pages visited, and referring URLs collected automatically when you access phingo.one.
- Communication Records: Records of customer support interactions, including live chat transcripts, email correspondence, and any information you voluntarily provide to phingo support.
4. How We Collect Your Data
phingo collects Personal Data through the following means:
- Direct Collection: Information you provide when completing the phingo registration form, submitting KYC documents, completing deposit or withdrawal requests, or contacting phingo support.
- Automated Collection: Technical and device data collected automatically via cookies, web beacons, log files, and similar tracking technologies when you visit phingo.one. See Section 8 for details on cookies.
- Third-Party Sources: Information received from payment processors (e.g., transaction confirmation data from GCash, Maya, BPI, BDO, or Metrobank), identity verification service providers, and fraud prevention services where necessary to verify your identity or protect against financial crime.
phingo does not purchase Personal Data from data brokers or compile profiles of non-members from external sources for marketing purposes.
5. Purposes of Processing Personal Data
phingo processes your Personal Data for the following defined purposes only:
- Account Registration and Management: Creating, maintaining, and managing your phingo account, including authentication and session management.
- Identity Verification (KYC): Verifying your identity and age (21+ requirement) in compliance with applicable Philippine regulations and anti-money laundering obligations.
- Payment Processing: Processing deposits and withdrawals in PHP via GCash, Maya, bank transfers, and other accepted channels.
- Service Delivery: Providing access to phingo games, live casino, sports betting, bingo, sabong, and all other platform features.
- Fraud Prevention and Security: Detecting, investigating, and preventing fraudulent transactions, money laundering, account sharing, and other prohibited conduct.
- Regulatory Compliance: Meeting obligations under Philippine law, including PDPA, the Anti-Money Laundering Act (RA 9160), and any requirements imposed by competent Philippine regulatory authorities.
- Customer Support: Responding to member queries, complaints, and support requests.
- Responsible Gaming: Monitoring gaming behaviour to identify patterns that may indicate problem gambling and implementing protective measures including self-exclusion.
- Platform Improvement: Analysing aggregated, anonymised usage data to improve phingo's games, features, performance, and user experience.
- Marketing Communications: Sending promotional offers and phingo updates to members who have not opted out, where consent has been obtained or is otherwise lawfully relied upon.
6. Legal Basis for Processing
Under the Philippine Data Privacy Act of 2012, phingo processes your Personal Data on the following legal bases:
- Contractual Necessity: Processing required to perform our obligations under the phingo Terms & Conditions, including account management, payment processing, and game service delivery.
- Legal Obligation: Processing necessary to comply with applicable Philippine laws, including KYC/AML requirements and tax reporting obligations.
- Legitimate Interests: Processing carried out for phingo's legitimate business interests — including fraud prevention, platform security, and service improvement — where such interests are not overridden by your rights and freedoms.
- Consent: Where phingo relies on consent as a legal basis — primarily for marketing communications — you may withdraw that consent at any time without affecting the lawfulness of processing prior to withdrawal.
7. Sharing of Personal Data with Third Parties
phingo does not sell your Personal Data. We share your information with third parties only in the following limited circumstances:
- Payment Processors: GCash, Maya, BPI, BDO, Metrobank, Visa/Mastercard acquirers, and other payment service providers receive only the transaction data required to process your deposits and withdrawals.
- Identity Verification Providers: Third-party KYC and AML compliance services that assist phingo in verifying member identities and screening against sanctions lists.
- Game Software Providers: Licensed third-party game studios whose software is integrated into the phingo platform. These providers may receive anonymised game session data for integrity and technical support purposes.
- IT and Security Service Providers: Hosting, cloud infrastructure, and cybersecurity service providers operating under binding data processing agreements with phingo.
- Legal and Regulatory Authorities: Philippine government bodies, courts, law enforcement agencies, and regulators where disclosure is required by law or in connection with legal proceedings.
All third-party data processors engaged by phingo are required to handle Personal Data in accordance with the PDPA and are contractually prohibited from using that data for any purpose beyond the specific service they provide to phingo.
8. Cookies and Tracking Technologies
phingo uses cookies and similar tracking technologies on phingo.one for the following purposes:
- Essential Cookies: Required for the Platform to function, including maintaining your login session, remembering your language and display preferences, and enabling secure transactions. These cannot be disabled without affecting Platform functionality.
- Analytics Cookies: Used to collect aggregated, anonymised data on how members navigate phingo.one, which pages are most visited, and where technical issues occur. This helps phingo improve the platform experience.
- Fraud Prevention Cookies: Technical identifiers used to detect suspicious login patterns, identify duplicate account attempts, and protect against automated bot activity.
You may manage cookie preferences through your browser settings. Note that disabling essential cookies will impair your ability to use phingo, including the login and payment functions.
9. Data Retention
phingo retains your Personal Data for as long as is necessary to fulfil the purposes set out in this Policy, subject to the following guidelines:
- Active Account Data: Retained for the duration of your active phingo membership and for a period of five (5) years following account closure, in compliance with Philippine AML record-keeping requirements.
- Transaction Records: Financial transaction records are retained for a minimum of five (5) years following the transaction date as required by RA 9160.
- KYC Documents: Retained for the period required by applicable Philippine regulations, typically five (5) years from the end of the business relationship.
- Support Communications: Retained for three (3) years from the date of the interaction, or longer where required for dispute resolution or legal proceedings.
- Marketing Consent Records: Retained for the duration of your membership and for a reasonable period thereafter as evidence of consent or opt-out, as required.
Upon expiry of the applicable retention period, phingo will securely delete or anonymise your Personal Data in accordance with PDPA guidelines.
10. Data Security Measures
phingo implements a layered set of technical and organisational security measures to protect your Personal Data against unauthorised access, loss, alteration, or disclosure:
- 256-bit SSL/TLS encryption for all data in transit between your device and phingo servers.
- Encryption at rest for sensitive database fields including account credentials and financial identifiers.
- Role-based access controls ensuring that phingo personnel can only access Personal Data necessary for their specific job function.
- Multi-factor authentication required for phingo staff accessing backend systems containing Member data.
- Regular security audits and penetration testing of phingo platform infrastructure.
- Data breach detection and incident response procedures, including notification obligations under the PDPA where a breach meets the threshold for mandatory reporting to the National Privacy Commission.
No electronic transmission or storage method is 100% secure. While phingo takes all reasonable precautions to protect your data, we cannot guarantee absolute security. You are responsible for maintaining the confidentiality of your phingo login credentials.
11. Your Data Rights Under the PDPA
As a Data Subject under the Philippine Data Privacy Act, phingo members have the following rights with respect to their Personal Data:
- Right to Be Informed: The right to be told what Personal Data phingo collects, how it is used, and with whom it is shared — as set out in this Policy.
- Right of Access: The right to request a copy of the Personal Data phingo holds about you, together with information about how it is processed.
- Right to Rectification: The right to request correction of inaccurate or incomplete Personal Data. Certain corrections may require re-submission of KYC documents.
- Right to Erasure: The right to request deletion of your Personal Data, subject to phingo's legal obligations to retain certain records under Philippine law. Where erasure is not possible due to legal requirements, phingo will restrict processing of the relevant data.
- Right to Object: The right to object to processing of your Personal Data for direct marketing purposes at any time, without justification.
- Right to Data Portability: The right to receive your Personal Data in a structured, commonly used format, where technically feasible.
- Right to Lodge a Complaint: The right to lodge a complaint with the National Privacy Commission (NPC) if you believe phingo has processed your Personal Data in breach of the PDPA.
To exercise any of the above rights, please contact phingo support using the email address shown in Section 14. phingo will respond to data rights requests within the period required by the PDPA, generally within thirty (30) days of receipt.
12. Minors and Age Restriction
phingo is strictly an adult platform. The minimum age to register and use phingo is 21 years, in accordance with Philippine regulations applicable to online casino gaming. phingo does not knowingly collect Personal Data from individuals under the age of 21.
Where phingo discovers that Personal Data has been collected from an individual below the minimum age, that account will be immediately closed, any winnings forfeited, and all Personal Data deleted promptly in accordance with PDPA requirements. If you believe a minor has registered on phingo, please contact us immediately using the support details in Section 14.
13. Changes to This Privacy Policy
phingo reserves the right to update this Privacy Policy at any time to reflect changes in our data practices, applicable Philippine law, or regulatory guidance from the National Privacy Commission. When material changes are made, phingo will notify registered members via their registered email address and publish the revised Policy on this page with an updated effective date.
Your continued use of phingo following the publication of a revised Privacy Policy constitutes your acceptance of the updated terms. If you do not accept the revised Policy, you must cease using the Platform and request account closure.
Effective Date: This Privacy Policy is effective as of June 2026.
14. Contact and Data Privacy Inquiries
For any questions, concerns, or requests relating to this Privacy Policy or phingo's handling of your Personal Data — including requests to exercise your PDPA data rights — please contact the phingo Data Privacy team:
Platform: phingo · phingo.one
Support Contact: [email protected]
Response Time: Within 30 days of receipt, as required by the PDPA
You also have the right to direct complaints about phingo's data practices to the National Privacy Commission of the Philippines (NPC) if you believe your rights under the PDPA have been infringed.