1. Who We Are
This Privacy Policy is issued by piso88 ("piso88," "we," "our," or "us"),
the operator of the online casino and sports betting platform accessible at piso88.co
(the "Platform"). piso88 operates under a license issued by the Philippine Amusement
and Gaming Corporation (PAGCOR) and is subject to the regulatory oversight of the
National Privacy Commission (NPC) of the Philippines under Republic Act No. 10173
(the Data Privacy Act of 2012).
piso88 acts as a Personal Information Controller (PIC) with respect to
all personal data collected from players and prospective players through the Platform.
Our designated Data Protection Officer (DPO) can be contacted using the details provided
in Section 14 of this policy.
2. Personal Data We Collect
piso88 collects the following categories of personal data from registered players and Platform visitors:
Identity and Contact Data:
- Full legal name, date of birth, and nationality;
- Residential address (including barangay, city/municipality, province);
- Mobile number and email address;
- Government-issued identification documents (PhilSys ID, Driver's License, Passport, SSS/UMID, PRC License, Voter's ID, or Postal ID) and associated photographs;
- Selfie or liveness verification images submitted during KYC verification.
Financial Data:
- GCash account number, Maya account number, or bank account details used for deposits and withdrawals;
- Transaction history (deposits, withdrawals, bonuses, wagering activity);
- Source of funds documentation where required for enhanced due diligence.
Technical and Usage Data:
- IP address, device type, operating system, and browser information;
- Login timestamps, session duration, and geolocation data (city and region level);
- Game history, betting patterns, and promotional activity;
- Customer support communications (chat logs, email correspondence).
piso88 does not collect or store your full GCash or banking credentials (PIN or password).
Payment transactions are processed via the respective payment providers' secure APIs.
3. How We Collect Your Personal Data
piso88 collects personal data through the following means:
- Direct collection: Information you provide when registering a piso88 account, completing KYC verification, making a deposit or withdrawal, or contacting customer support;
- Automated collection: Technical data collected automatically when you access the Platform, including through cookies, log files, and similar tracking technologies (see Section 7);
- Third-party sources: Identity verification data from NPC-accredited or PAGCOR-approved KYC verification providers; fraud and AML screening data from licensed risk management providers; payment confirmation data from GCash, Maya, and banking partners.
4. Why We Process Your Personal Data
piso88 processes your personal data for the following specific purposes:
- Account creation and management: To register, authenticate, and maintain your piso88 player account;
- Identity verification (KYC): To verify your identity, age (21+), and eligibility to use piso88 as required by PAGCOR and AMLA regulations;
- Payment processing: To process deposits, withdrawals, and bonus payments accurately and securely;
- Regulatory compliance: To comply with PAGCOR licensing requirements, the Anti-Money Laundering Act (RA 9160 as amended), the Data Privacy Act (RA 10173), and other applicable Philippine laws;
- Fraud prevention and security: To detect, prevent, and investigate fraudulent activity, unauthorized access, cheating, and money laundering;
- Responsible gaming: To monitor gaming behavior, apply deposit limits, enforce self-exclusion requests, and identify players showing signs of problem gambling;
- Customer support: To respond to your inquiries, complaints, and service requests;
- Platform improvement: To analyze usage patterns and improve the piso88 Platform's performance, user interface, and game selection;
- Marketing communications: To send you promotional offers and relevant updates where you have provided consent and not subsequently withdrawn it.
5. Legal Bases for Processing
piso88 processes your personal data on the following legal bases under RA 10173:
- Contractual necessity: Processing required to perform the contract between you and piso88 (account creation, payment processing, game delivery);
- Legal obligation: Processing required to comply with PAGCOR licensing conditions, AMLA requirements, NPC regulations, and other mandatory Philippine laws;
- Legitimate interests: Processing for fraud prevention, platform security, and responsible gaming purposes where these interests are not overridden by your rights;
- Consent: Marketing communications and non-essential analytics, where we have obtained your prior, informed, and freely given consent.
You may withdraw consent for marketing communications at any time by contacting piso88
support or using the unsubscribe option in any marketing email. Withdrawal of consent
does not affect the lawfulness of processing carried out before withdrawal.
6. Sharing Your Personal Data
piso88 does not sell your personal data to any third party. We share your data only
where necessary and with appropriate safeguards in place, limited to the following
categories of recipients:
- Payment service providers: GCash (Mynt), Maya (Voyager Innovations), BPI, BDO, UnionBank, Metrobank, and other payment partners — solely for transaction processing;
- KYC and identity verification providers: PAGCOR-approved identity verification and liveness detection service providers;
- AML and fraud screening providers: Licensed risk management and sanctions screening providers to fulfil AMLA obligations;
- Game content providers: Game suppliers who receive anonymized or pseudonymized data necessary for game delivery and RNG certification;
- Regulatory authorities: PAGCOR, the National Privacy Commission, the Anti-Money Laundering Council (AMLC), and other government agencies, where required by law or court order;
- IT and infrastructure providers: Cloud hosting and cybersecurity providers operating under Data Processing Agreements that require them to protect your data to the same standard as piso88.
All third-party processors engaged by piso88 are contractually bound to process your
personal data only on piso88's instructions and in compliance with RA 10173.
7. Cookies & Tracking Technologies
The piso88 Platform uses cookies and similar technologies to provide core Platform
functionality, maintain your authenticated session, and analyze usage patterns. The
following categories of cookies are used:
- Essential cookies: Required for the Platform to function. These include session authentication tokens, CSRF protection tokens, and load-balancing cookies. These cannot be disabled without affecting Platform functionality;
- Analytics cookies: Used to understand how players navigate and use the Platform, enabling us to improve performance and user experience. Data collected is aggregated and does not identify individuals;
- Security cookies: Used to detect fraudulent logins, bot activity, and device fingerprinting for account protection purposes.
piso88 does not use cookies for third-party advertising or cross-site behavioral tracking.
You may configure your browser to block or delete cookies; however, disabling essential
cookies will prevent you from logging in to your piso88 account.
8. Data Retention
piso88 retains your personal data for the following periods:
- Active account data: Retained for the duration of your piso88 account and for a minimum of 5 years after account closure, in compliance with PAGCOR licensing conditions and AMLA record-keeping obligations;
- Transaction records: Retained for a minimum of 5 years from the date of each transaction, or longer if required by applicable law or ongoing regulatory investigation;
- KYC documents: Retained for the period of account activity plus 5 years minimum post-closure;
- Customer support records: Retained for 3 years from the date of each interaction;
- Marketing consent records: Retained until withdrawal of consent plus 3 years for compliance evidence purposes.
Upon expiry of the applicable retention period, personal data is securely deleted or
permanently anonymized in accordance with piso88's data disposal procedures.
9. Data Security
piso88 implements a comprehensive set of technical and organizational security measures
to protect your personal data against unauthorized access, loss, alteration, or disclosure:
- 256-bit SSL/TLS encryption for all data in transit between your device and piso88 servers;
- AES-256 encryption for sensitive data at rest (passwords stored as salted hashes, payment account references tokenized);
- Multi-factor authentication for all piso88 internal staff accounts with access to player data;
- Role-based access controls limiting data access to authorized personnel on a need-to-know basis;
- Regular third-party penetration testing and security audits;
- 24/7 intrusion detection and security monitoring systems;
- Incident response procedures aligned with NPC breach notification requirements (72-hour notification for high-risk breaches).
In the event of a personal data breach that poses a real risk of serious harm to data
subjects, piso88 will notify the NPC and affected players within 72 hours of becoming
aware of the breach, as required by NPC Circular 16-03.
10. Your Rights as a Data Subject
Under the Philippine Data Privacy Act (RA 10173), you have the following rights with
respect to your personal data held by piso88:
- Right to be informed: To be notified of how your personal data is collected, processed, and retained (fulfilled by this Privacy Policy);
- Right to access: To request a copy of the personal data piso88 holds about you and information on how it is being processed;
- Right to rectification: To request correction of inaccurate, incomplete, or outdated personal data in your piso88 account;
- Right to erasure: To request deletion of your personal data where it is no longer necessary for the purpose for which it was collected, subject to our legal retention obligations under PAGCOR and AMLA regulations;
- Right to object: To object to the processing of your personal data for direct marketing or where processing is based on legitimate interests;
- Right to data portability: To receive a copy of data you have provided to piso88 in a structured, commonly used format;
- Right to file a complaint: To lodge a complaint with the National Privacy Commission (NPC) if you believe piso88 has violated your data privacy rights.
To exercise any of these rights, please contact piso88's Data Protection Officer using
the details in Section 14. piso88 will respond to all valid requests within 15 business
days. Identity verification may be required before processing certain requests.
11. Children's Privacy
The piso88 Platform is strictly intended for individuals who are 21 years of age
or older, as mandated by PAGCOR for casino-style gambling in the Philippines.
piso88 does not knowingly collect personal data from individuals under the age of 21.
If piso88 discovers or has reasonable grounds to believe that a registered account is
held by a person under 21 years of age, piso88 will immediately suspend the account,
void all associated bets, return any real-money deposits to the originating payment
method, delete the account holder's personal data to the extent permissible by law,
and report the incident to PAGCOR as required.
12. Cross-Border Data Transfers
Certain piso88 service providers and game content suppliers are located outside the
Philippines. Where piso88 transfers personal data to recipients in other countries,
we ensure that appropriate safeguards are in place as required by the NPC, including:
- Data Processing Agreements incorporating standard contractual clauses approved by the NPC;
- Transfers only to jurisdictions with adequate data protection frameworks or where specific safeguards have been approved;
- Due diligence on recipients' data protection practices prior to engagement.
In all cases, piso88 remains responsible for ensuring that your personal data transferred
abroad receives a standard of protection equivalent to that provided under RA 10173.
13. Changes to This Privacy Policy
piso88 may update this Privacy Policy from time to time to reflect changes in our
data processing practices, regulatory requirements, or Platform functionality. The
effective date at the top of this policy indicates when the current version was adopted.
For material changes that significantly affect your rights or how your personal data
is processed, piso88 will notify registered players via in-Platform notification or
email prior to the changes taking effect. Your continued use of the piso88 Platform
following the notification period constitutes acceptance of the updated Privacy Policy.
14. Contact Us & Data Protection Officer
If you have any questions, concerns, or requests relating to this Privacy Policy or
piso88's handling of your personal data, please contact our Data Protection Officer:
- Email (DPO): [email protected]
- Live Chat: Available 24/7 via the piso88 Platform
- Subject line: "Data Privacy Request – [your registered email or mobile]"
You also have the right to raise a complaint directly with the
National Privacy Commission of the Philippines (NPC) if you believe
your data privacy rights have been violated. NPC contact information is publicly
available on the NPC's official government website.