This Privacy Policy explains how phataya collects, processes, stores, shares, and protects your personal data when you use the phataya platform. We take data privacy seriously — your information is never sold and is protected under Philippine law.
This Privacy Policy ("Policy") is issued by phataya ("phataya," "Company," "we," "us," "our"), the operator of the online gaming platform accessible at phataya.co and its associated mobile applications and services (the "Platform"). This Policy applies to all personal data collected from individuals ("Users," "Players," "you") who register, access, or interact with the Platform in any capacity.
This Policy is to be read alongside phataya's Terms and Conditions. In the event of a conflict between this Policy and the Terms and Conditions on a privacy matter, this Policy shall prevail.
phataya acts as the Personal Information Controller (PIC) as defined under Republic Act No. 10173 (the Data Privacy Act of 2012, "DPA") and its Implementing Rules and Regulations ("IRR") with respect to personal data processed in connection with the Platform. phataya has registered with the National Privacy Commission (NPC) of the Philippines as required by applicable law.
This Policy does not apply to third-party websites, payment processors, or service providers that maintain their own privacy policies. phataya is not responsible for the privacy practices of third parties, even where links to their services appear on or are integrated within the Platform.
phataya collects personal data that is necessary, proportionate, and relevant to the purposes described in this Policy. The categories of personal data we collect include:
| Category | Examples of Data Collected | Collection Method |
|---|---|---|
| Registration Data | Full legal name, date of birth, Philippine mobile number, chosen username | Provided by you at registration |
| Identity Verification (KYC) | Government-issued ID (e.g., PhilSys, SSS, UMID, passport, driver's licence), selfie photograph, proof of address | Submitted by you during KYC |
| Financial Data | GCash / Maya account references, bank account details (BPI, BDO, UnionBank), transaction history, deposit and withdrawal records | Provided by you and via payment processors |
| Gaming Activity Data | Game session logs, bet amounts, game round results, bonus usage, win/loss history | Automatically generated by Platform use |
| Technical & Device Data | IP address, device type and operating system, browser type, session timestamps, login history, geolocation (city/region level) | Automatically collected |
| Communications Data | Support chat transcripts, email correspondence, SMS OTP logs, feedback submissions | Generated through your communications with phataya |
| Responsible Gaming Data | Self-imposed deposit limits, session limits, cool-down periods, self-exclusion status | Set by you via account settings |
phataya does not intentionally collect sensitive personal information such as racial or ethnic origin, political opinions, religious beliefs, or health information unless specifically required for responsible gaming compliance or regulatory purposes, and only with your explicit consent or as legally mandated.
phataya processes your personal data for the following purposes:
Under the Data Privacy Act of 2012, phataya processes your personal data on the following lawful bases:
phataya does not sell your personal data to third parties. We share personal data only in the following circumstances and only to the extent necessary:
All third-party recipients of personal data are required by phataya to implement appropriate technical and organisational security measures and to process data only for the specified purpose.
phataya retains personal data for as long as necessary to fulfil the purposes for which it was collected, including to satisfy applicable legal, regulatory, and reporting obligations. Key retention periods include:
| Data Category | Retention Period | Basis |
|---|---|---|
| Account & KYC Data | 5 years from account closure | AMLA / PAGCOR regulatory requirement |
| Financial Transaction Records | 5 years from transaction date | AMLA / tax compliance |
| Gaming Session Logs | 2 years from session date | Dispute resolution / regulatory audit |
| Support Communications | 3 years from last interaction | Legitimate interests / dispute resolution |
| Self-Exclusion Records | Duration of exclusion + 5 years | Responsible gaming compliance |
| Marketing Consent Records | Until withdrawn + 1 year | NPC consent audit trail requirements |
Upon expiry of the applicable retention period, personal data is securely deleted or anonymised in accordance with phataya's data destruction procedures.
phataya implements a multi-layered security framework to protect your personal data from unauthorised access, disclosure, alteration, or destruction. Key technical and organisational measures include:
Notwithstanding these measures, no electronic transmission or storage system can be guaranteed to be 100% secure. In the event of a personal data breach that poses a risk to your rights and freedoms, phataya will notify affected individuals and the National Privacy Commission in accordance with NPC Circular No. 16-03 and applicable DPA requirements.
phataya uses cookies and similar tracking technologies to operate the Platform, enhance user experience, and analyse Platform usage. The types of cookies used include:
phataya does not use third-party advertising cookies or share cookie data with advertising networks. You may manage cookie preferences through your browser settings; however, disabling essential cookies will prevent full Platform functionality.
As a data subject under the Data Privacy Act of 2012, you have the following rights with respect to your personal data held by phataya:
To exercise any of these rights, contact phataya's Data Protection Officer at the contact details in Section 12. phataya will respond to valid requests within thirty (30) calendar days. We may ask you to verify your identity before processing a request.
The phataya Platform is strictly intended for individuals who are at least twenty-one (21) years of age. phataya does not knowingly collect personal data from persons under 21. Age verification is a mandatory component of the phataya registration and KYC process.
If phataya becomes aware that personal data has been collected from an individual under 21 years of age, that account will be immediately closed, all associated data will be deleted in accordance with phataya's data destruction procedures, and any funds held will be handled in accordance with PAGCOR guidelines and applicable law.
If you believe a minor has registered on the phataya Platform, please contact [email protected] immediately.
phataya may update this Privacy Policy from time to time to reflect changes in our data practices, Platform features, or applicable law. Material changes will be communicated to registered Users via in-Platform notification or SMS to the registered mobile number at least seven (7) days before the amended Policy takes effect.
The current version of this Policy is always accessible at phataya.co/privacy-policy. The "Last Updated" date at the top of this document indicates when the most recent revision was made. Continued use of the Platform after the effective date of an amendment constitutes your acceptance of the updated Policy.
phataya has designated a Data Protection Officer (DPO) as required under the Data Privacy Act of 2012. To exercise your data privacy rights, submit a data subject request, or raise a privacy concern, please contact:
A summary of the six key commitments phataya makes to every Player with respect to their personal information.
phataya does not sell, rent, or trade your personal information to any third party for commercial purposes. Your data is used only to operate the Platform and comply with Philippine law — never monetised externally.
phataya is registered with the National Privacy Commission and processes all personal data in accordance with Republic Act No. 10173 (Data Privacy Act of 2012). Your rights as a data subject are fully recognised and honoured.
All personal data in transit is protected by TLS 1.3 (256-bit AES). Data at rest — including KYC documents and financial records — is encrypted using AES-256. phataya's security posture matches Philippine banking standards.
Access, rectification, erasure, portability, objection, and consent withdrawal are rights phataya genuinely processes — not placeholder commitments. Submit a data subject request and phataya responds within 30 calendar days.
phataya collects only personal data that is necessary, proportionate, and directly relevant to operating the Platform and meeting regulatory requirements. We do not collect data speculatively or beyond what is needed.
phataya sends promotional communications only with your consent. You may opt out of all marketing messages at any time through your account notification settings or by contacting support — no questions asked, effective immediately.
If you have questions about how phataya processes your personal data, want to exercise your DPA rights, or need to report a privacy concern, our support team and Data Protection Officer are available around the clock.