phlag Privacy Policy
This Privacy Policy explains how phlag collects, uses, stores, and protects your personal data when you use the phlag Casino platform. phlag is committed to handling your data with transparency and in full compliance with Republic Act No. 10173, the Philippine Data Privacy Act of 2012, and applicable PAGCOR data governance requirements.
Philippine Data Privacy Act
phlag processes all personal data in compliance with Republic Act No. 10173 (Data Privacy Act of 2012) and its Implementing Rules and Regulations. Your personal data rights under Philippine law are fully honoured by phlag at all times.
Your Data Stays Yours
phlag does not sell your personal data to third-party advertisers or data brokers. Your information is shared only with vetted service providers necessary to operate the platform, or as required by Philippine law and PAGCOR regulations.
Full Data Subject Rights
Filipino players registered with phlag have the right to access, correct, erase, object to, restrict, and port their personal data. Requests are handled by phlag's designated Data Protection Officer (DPO) within the timeframes prescribed by Philippine law.
Data Minimisation
phlag collects only the personal data that is necessary for the specific purposes stated in this Policy. We do not collect data speculatively or retain it longer than required for the stated purpose or applicable legal retention requirement.
SSL & Encryption
All data transmitted between your device and phlag's servers is protected by industry-standard SSL/TLS encryption. Sensitive data including passwords and payment details are stored in encrypted form using current cryptographic standards. phlag conducts regular security audits.
Breach Notification
In the event of a personal data breach that poses a real risk to affected individuals, phlag will notify the National Privacy Commission (NPC) and affected players within the timeframes required under the Data Privacy Act of 2012 and NPC Circular No. 16-03.
Introduction & Scope
phlag ("phlag," "we," "us," or "our") is committed to protecting the privacy and personal data of every individual who interacts with the phlag Casino platform. This Privacy Policy describes how phlag collects, processes, stores, shares, and protects personal data in connection with the use of our online casino, sports betting, bingo, and related gaming services accessible through phlag.co.
This Policy applies to all registered players, prospective players who visit phlag.co without registering, and any other individual whose personal data phlag processes in the course of operating its platform. It covers data processed through the phlag website, any phlag mobile web application, customer support channels, marketing communications, and payment processing flows.
phlag operates for Filipino players within the Philippines and processes personal data in accordance with Republic Act No. 10173, the Philippine Data Privacy Act of 2012 ("DPA"), its Implementing Rules and Regulations, relevant issuances from the National Privacy Commission ("NPC"), and the data governance requirements applicable to PAGCOR-regulated gaming operators. Where applicable, international best practices in data protection are also observed.
This Policy is written in plain English to be understood by Filipino players. Legal-style precision is maintained throughout, but we've tried to make it readable — not deliberately difficult. If anything is unclear, contact phlag support or our Data Protection Officer (Section 15).
Data Controller
For the purposes of the Philippine Data Privacy Act of 2012 and this Privacy Policy, phlag is the personal information controller in respect of all personal data collected and processed through the phlag platform. As personal information controller, phlag determines the purposes and means of the processing of your personal data and is responsible for ensuring that such processing complies with applicable Philippine data privacy laws.
phlag has appointed a Data Protection Officer ("DPO") who is responsible for overseeing phlag's data protection compliance, handling data subject rights requests, managing data breach notifications, and serving as the primary point of contact with the National Privacy Commission. Contact details for the DPO are provided in Section 15 of this Policy.
phlag's personal data processing activities are registered with the NPC as required under the DPA and NPC Circular No. 17-01 on the registration of data processing systems.
Personal Data We Collect
phlag collects the following categories of personal data, depending on how you interact with the platform:
3.1 Registration & Identity Data
- Legal full name as it appears on your government-issued ID
- Date of birth (collected to verify the 21+ age requirement mandated by PAGCOR)
- Philippine mobile number
- Email address
- Region and city of residence within the Philippines
- Username and encrypted password (passwords are stored in hashed form and are never accessible in plain text by phlag staff)
3.2 KYC & Verification Data
- Government-issued photo identification (PhilSys National ID, UMID, Driver's License, Passport, Voter's ID, or SSS ID) — document number, issuing authority, expiry date, and photograph
- Proof of address documents (utility bill, bank statement, or equivalent) where required
- Proof of payment method ownership where required for withdrawal processing
- Selfie or liveness verification image where required for enhanced due diligence
3.3 Financial & Transaction Data
- Deposit and withdrawal transaction records including amounts, dates, and payment method references
- GCash or Maya account reference (not stored in full — reference numbers used for reconciliation only)
- Bank account references for bank transfer payments (BPI, BDO, UnionBank) — account name and last four digits only
- Cryptocurrency wallet addresses used for USDT TRC20 transactions
- Account balance and transaction history
3.4 Gaming Activity Data
- Game session records: games played, bets placed, wagers, wins, losses, and session duration
- Sports betting selections, odds accepted, and settlement records
- Bonus and promotional credit usage records
- Loyalty programme tier and points history
3.5 Technical & Device Data
- IP address and geolocation data (country and region level) used for fraud prevention and regulatory jurisdiction verification
- Device type, operating system, and browser type and version
- Session logs including login timestamps, session duration, and activity logs
- Cookies and similar tracking technology data as described in Section 8
3.6 Communications Data
- Records of live chat, email, and any other support communications between you and phlag
- Feedback, complaint, and dispute records
- Marketing communication preference records (opt-in / opt-out status)
Certain data collected by phlag may constitute "sensitive personal information" under the DPA — specifically government ID numbers and biometric data (photographs). phlag applies enhanced safeguards to sensitive personal information consistent with Section 13 of the DPA, and processes such data only on the legal bases specified in Section 6 of this Policy.
How We Collect Your Data
phlag collects personal data through the following channels:
- Directly from you: When you register for a phlag account, complete KYC verification, make deposits or withdrawal requests, contact phlag support, participate in promotions, or update your account settings.
- Automatically during platform use: Through server logs, session monitoring, fraud detection systems, and cookies and similar tracking technologies as you browse and use the phlag website and gaming platform.
- From third-party service providers: phlag's KYC verification partners may provide identity verification results, fraud risk scores, and document authentication outcomes in connection with the verification of your identity. Payment processors may provide transaction confirmation data. Game providers may transmit session and wagering data to phlag.
- From public sources: Publicly available information may be accessed where permitted by law for fraud prevention, AML/CFT screening, or responsible gaming purposes.
Purposes of Processing
phlag processes your personal data for the following specific, explicit, and legitimate purposes:
| Purpose | Data Categories Used |
|---|---|
| Account registration and management | Registration & Identity Data, Communications Data |
| Identity verification and KYC compliance | KYC & Verification Data, Registration & Identity Data |
| Age verification (21+ PAGCOR requirement) | Registration & Identity Data, KYC & Verification Data |
| Processing deposits and withdrawals | Financial & Transaction Data, KYC & Verification Data |
| Operating games and sports betting | Gaming Activity Data, Financial & Transaction Data |
| Anti-money laundering (AML) compliance | Financial & Transaction Data, Registration & Identity Data, KYC Data |
| Fraud detection and prevention | Technical & Device Data, Financial & Transaction Data, Gaming Activity Data |
| Responsible gaming monitoring | Gaming Activity Data, Financial & Transaction Data, Registration Data |
| Customer support and dispute resolution | Communications Data, Gaming Activity Data, Financial & Transaction Data |
| Platform improvement and analytics | Technical & Device Data, Gaming Activity Data (aggregated and anonymised) |
| Marketing communications (with consent) | Registration & Identity Data, Gaming Activity Data, Communications Data |
| PAGCOR regulatory reporting | All categories as required by PAGCOR regulations |
Legal Bases for Processing
Under the Philippine Data Privacy Act of 2012, phlag processes your personal data on the following legal bases:
- Contractual necessity (Section 12(b), DPA): Processing necessary to perform our contractual obligations to you as a phlag account holder — including account management, processing of gaming transactions, and payment processing.
- Legal obligation (Section 12(c), DPA): Processing required to comply with legal obligations including PAGCOR regulatory reporting, Anti-Money Laundering Act (AMLA) compliance, Data Privacy Act compliance, and NPC requirements.
- Legitimate interests (Section 12(f), DPA): Processing for phlag's legitimate business interests including fraud prevention, responsible gaming monitoring, platform security, and anonymised analytics — where such interests are not overridden by your rights and interests.
- Consent (Section 12(a), DPA): Where required by law or where phlag has sought your specific consent — in particular, for direct marketing communications and for the use of non-essential cookies. You may withdraw consent at any time without affecting the lawfulness of processing carried out prior to withdrawal.
- Vital interests (Section 12(e), DPA): In circumstances where processing is necessary to protect life or prevent serious harm — for example, sharing data with authorities where there is a credible threat to the safety of a person.
For sensitive personal information (government ID data, biometric data), phlag processes such information under Section 13(b) of the DPA (processing necessary for compliance with legal obligations) and Section 13(f) (processing required for the protection of lawful rights) as applicable.
Third-Party Sharing & Disclosure
phlag does not sell, rent, or commercially trade your personal data. phlag shares your personal data only in the following circumstances and only to the extent necessary:
- KYC and Identity Verification Providers: Third-party identity verification services engaged by phlag to perform document authentication, facial recognition, and fraud risk assessment as part of the KYC process. These providers act as personal information processors under a data processing agreement with phlag.
- Payment Processors: GCash, Maya, BPI, BDO, UnionBank, 7-Eleven Cliqq, USDT processors, and Coins.ph receive transaction data necessary to process your deposit and withdrawal requests.
- Game Providers: JILI Games, PG Soft, Pragmatic Play, Evolution Gaming, and other licensed game providers receive a player identifier and session data necessary to operate game sessions. These providers are bound by data processing agreements and are prohibited from using your data for purposes outside of providing games to phlag.
- Regulatory Authorities: PAGCOR, the Anti-Money Laundering Council (AMLC), the National Privacy Commission (NPC), and other competent Philippine authorities — where disclosure is required by law, court order, or regulatory instruction.
- Law Enforcement: Philippine law enforcement agencies where disclosure is required by valid legal process or where phlag believes disclosure is necessary to prevent or investigate criminal activity, fraud, or a threat to safety.
- Professional Advisers: Legal counsel, auditors, and compliance advisers engaged by phlag, subject to professional confidentiality obligations.
All third parties with whom phlag shares personal data are required by contract to implement appropriate technical and organisational data security measures and to process your data only for the specified purposes and in accordance with applicable Philippine law.
phlag does not and will not sell your personal data to any third party, including advertisers, data brokers, or analytics companies, for their own commercial purposes. Your data is used exclusively to operate the phlag platform and meet our legal obligations.
Cookies & Tracking Technologies
phlag uses cookies and similar tracking technologies on the phlag website and platform. Cookies are small text files placed on your device that help the platform function correctly, remember your preferences, prevent fraud, and — with your consent — deliver personalised content and measure platform performance.
8.1 Types of Cookies Used by phlag
- Strictly Necessary Cookies: Essential for the platform to function — session management, login authentication, security tokens, and fraud prevention signals. These cookies cannot be disabled without disabling core platform functionality.
- Functional Cookies: Remember your preferences such as language, region, and game lobby settings to provide a more personalised experience on phlag.
- Analytics Cookies: Used by phlag (via privacy-compliant analytics tools) to understand how players use the platform in aggregate — page visits, session lengths, feature usage, and error rates. Data collected is aggregated and does not identify individual players. These cookies require your consent.
- Responsible Gaming Cookies: Track session time locally on your device to support phlag's responsible gaming session timer features. These are functional in nature and are necessary for responsible gaming tools to operate.
8.2 Managing Cookies
You can manage or disable non-essential cookies through the phlag cookie preference centre, accessible from the phlag website footer. You can also manage cookies through your browser settings. Disabling certain cookies may affect the functionality of some phlag platform features. Strictly necessary cookies cannot be disabled without impairing your ability to use the platform.
phlag does not use third-party advertising cookies or cross-site tracking technologies that share your behaviour data with external advertisers.
Data Retention
phlag retains your personal data for no longer than is necessary for the purposes for which it was collected, subject to any longer retention period required by Philippine law or applicable PAGCOR and AMLC record-keeping requirements. The following general retention principles apply:
- Account Data: Retained for the duration of your active phlag account and for a period of five (5) years following account closure, consistent with AMLA record-keeping obligations applicable to PAGCOR-regulated gaming operators.
- KYC and Verification Documents: Retained for a minimum of five (5) years from the date of the relevant transaction, as required by the Anti-Money Laundering Act and PAGCOR compliance requirements.
- Transaction Records: Financial transaction data is retained for a minimum of ten (10) years from the date of the transaction in accordance with AMLA Section 9 requirements for covered persons in the gaming sector.
- Customer Support Records: Retained for three (3) years from the date of the communication, or for the duration of any ongoing dispute, whichever is later.
- Marketing Preference Data: Retained until you withdraw consent or for three (3) years of inactivity, whichever occurs first.
- Technical and Device Logs: Retained for twelve (12) months for security and fraud prevention purposes, after which they are deleted or anonymised.
Upon expiry of the applicable retention period, phlag will securely delete or anonymise your personal data in a manner that prevents reconstruction of the original data.
Data Security
phlag implements a comprehensive set of technical and organisational security measures to protect personal data against unauthorised access, accidental loss, destruction, alteration, or disclosure. These measures include:
- Encryption in Transit: All data transmitted between your device and phlag's servers is encrypted using TLS 1.2 or higher.
- Encryption at Rest: Sensitive personal data including passwords (hashed), government ID data, and payment references are stored using current cryptographic standards.
- Access Controls: Access to personal data within phlag's systems is restricted to authorised personnel on a strict need-to-know basis, with role-based access controls and audit logging of data access events.
- Two-Factor Authentication: Available and recommended for all player accounts to prevent unauthorised account access.
- Regular Security Audits: phlag conducts regular security assessments, vulnerability scans, and penetration testing of its platform infrastructure.
- Segregated Player Funds: Player account balances are held in accounts segregated from phlag's operational funds, protecting player funds in the event of insolvency or operational disruption.
- Staff Training: phlag personnel with access to personal data receive regular data privacy and security training.
While phlag maintains robust technical security, your account security also depends on keeping your login credentials confidential. Use a strong, unique password for your phlag account, enable 2FA, and never share your password with anyone — including anyone claiming to be from phlag. phlag will never ask for your full password.
Your Data Subject Rights
Under Republic Act No. 10173 (Data Privacy Act of 2012), you have the following rights with respect to your personal data held by phlag:
Request confirmation of whether phlag holds personal data about you, and obtain a copy of that data together with information about how it is processed.
Request correction of inaccurate or incomplete personal data that phlag holds about you. Certain corrections may require re-verification via KYC.
Request deletion of your personal data where it is no longer necessary for its original purpose, subject to legal retention requirements that may require phlag to retain certain data.
Object to the processing of your personal data for direct marketing at any time. You may also object to processing based on legitimate interests where your rights override those interests.
Request that phlag restrict processing of your data in specified circumstances — for example, while the accuracy of your data is being verified following a rectification request.
Receive a copy of personal data you have provided to phlag in a structured, commonly used, machine-readable format where processing is based on consent or contractual necessity.
To exercise any of these rights, contact phlag's Data Protection Officer as described in Section 15. phlag will respond to all verified data subject rights requests within fifteen (15) calendar days of receipt, or within thirty (30) calendar days for complex requests, in accordance with NPC requirements. phlag may require identity verification before processing rights requests to prevent unauthorised disclosure.
If you are not satisfied with phlag's response to a data subject rights request, you have the right to lodge a complaint with the National Privacy Commission of the Philippines at privacy.gov.ph.
Children's Privacy & Age Restriction
The phlag platform is strictly intended for individuals who are 21 years of age or older, as mandated by PAGCOR regulations governing online gambling in the Philippines. phlag does not knowingly collect personal data from anyone under the age of 21.
Age is verified during the KYC process for all players seeking to make withdrawals. Where phlag discovers that it has collected personal data from an individual under 21, phlag will immediately close the associated account, delete the personal data to the extent not required to be retained by law, and take appropriate action consistent with its PAGCOR compliance obligations.
Parents and guardians who believe a minor may have accessed the phlag platform using falsified identity information are encouraged to contact phlag immediately via Live Chat or by email to the DPO. phlag will investigate and act promptly on all such reports.
The 21-year minimum age is a non-negotiable legal requirement under Philippine law and PAGCOR regulations. If you are under 21, you are not permitted to register for or use the phlag platform under any circumstances. If you know an underage individual is using phlag, please report this immediately.
Cross-Border Data Transfers
phlag primarily processes and stores personal data within the Philippines. Where phlag engages third-party service providers — including KYC verification providers, game providers, and cloud infrastructure providers — who may process personal data outside the Philippines, phlag ensures that appropriate safeguards are in place consistent with Section 21 of the DPA and NPC Circular No. 16-01 on the security of personal data in government agencies using cloud computing.
Specifically, phlag ensures that any cross-border transfer of personal data is made only:
- To countries or organisations that provide an adequate level of protection for personal data comparable to the standards of the DPA; or
- Subject to appropriate contractual safeguards, including data processing agreements that impose equivalent data protection obligations on the recipient; or
- Where the transfer is necessary for the performance of phlag's contractual obligations to you or for the implementation of pre-contractual measures taken at your request; or
- Where otherwise permitted under the DPA and NPC regulations.
phlag's third-party game providers — including companies headquartered outside the Philippines — process limited player session data (player identifiers and wagering data) necessary to deliver game services. All such providers are bound by data processing agreements requiring compliance with applicable data privacy standards.
Updates to This Privacy Policy
phlag reserves the right to update or revise this Privacy Policy at any time. The "Last Updated" date at the top of this page reflects the date of the most recent substantive revision. phlag will notify registered players of material changes to this Policy via in-platform notification or email to the registered account address.
Material changes include, but are not limited to: changes to the categories of personal data collected, changes to the purposes of processing, changes to data sharing arrangements, and changes that affect your data subject rights. Changes resulting from legislative updates or new NPC guidance will be implemented promptly and notified to players.
Your continued use of the phlag platform following notification of material changes constitutes your acknowledgement of the revised Policy. If you disagree with any material changes, you may close your phlag account in accordance with the account closure procedure described in the phlag Terms & Conditions. Please review the phlag Terms & Conditions alongside this Policy.
Contact & Data Protection Officer
For any questions, concerns, or requests relating to this Privacy Policy or the processing of your personal data by phlag, please contact phlag's Data Protection Officer. The DPO is responsible for overseeing phlag's data protection compliance and is the primary point of contact for data subject rights requests.
You may contact phlag's DPO by:
- Live Chat: Available 24/7 from your phlag account dashboard. Request to speak with a data privacy team member and your query will be routed to the DPO team.
- Email: The phlag DPO contact email is available on the phlag platform's Privacy & Data section within your account settings. Do not send sensitive personal data (such as ID document images) to general support channels — use the secure upload facility within your account for KYC submissions.
phlag commits to acknowledging all privacy-related enquiries within three (3) business days and to providing a substantive response or escalation update within fifteen (15) calendar days.
If you are not satisfied with phlag's response to your data privacy concern, you have the right to lodge a complaint with the National Privacy Commission of the Philippines. The NPC's contact information and complaint procedures are published on the NPC's official website at privacy.gov.ph.
Effective Date: This Privacy Policy is effective as of January 2026. All previous versions of the phlag Privacy Policy are superseded by this document. phlag's processing of personal data collected prior to the effective date of this Policy is governed by the version of the Policy in effect at the time of collection, except where this Policy provides greater protections, in which case this Policy applies. We encourage all phlag players to read this Policy in full and to contact our DPO with any questions.
Your Data Is Safe with phlag
phlag is built on transparency, security, and respect for Filipino players' privacy rights. Ready to experience a platform you can trust?
For players aged 21 and above only · PAGCOR Compliant · Data Privacy Act 2012 Compliant · Play responsibly