This Privacy Policy explains how phpopen collects, uses, stores, and protects your personal information when you use the phpopen platform at phpopen.app. It is designed to comply fully with the Data Privacy Act of 2012 (Republic Act No. 10173) and the implementing rules and regulations issued by the National Privacy Commission of the Philippines.
Before diving into the full legal text, here are the six core principles that guide how phpopen handles every piece of personal information it holds about you.
phpopen collects only the personal data necessary for operating the platform and complying with Philippine law. Your data is never used for purposes beyond those stated in this Policy without your explicit consent.
All personal data stored by phpopen is protected using 256-bit AES encryption at rest and in transit. Access is restricted to staff with a verified operational need, and all access events are logged.
phpopen does not sell, rent, or trade your personal data to third parties for marketing purposes. Data sharing with service providers is governed by data processing agreements that restrict further use.
The Data Privacy Act gives you meaningful rights over your personal information. phpopen has built the systems and processes necessary to honor those rights promptly — not just acknowledge them on paper.
phpopen retains personal data only for as long as required to fulfill the purpose for which it was collected or to comply with applicable legal obligations. Data no longer needed is securely deleted.
This Policy clearly describes what phpopen collects, why, how long it is kept, and who it may be shared with. Updates to this Policy are communicated to players before they take effect.
phpopen ("we," "us," or "our") is the operator of the online gaming platform accessible at phpopen.app, offering casino games, sports betting, bingo, Tongits Go, and related services to registered players in the Philippines. phpopen is the Data Controller for the personal information processed pursuant to this Privacy Policy.
As a Data Controller, phpopen determines the purposes and means of processing your personal data. phpopen has appointed a Data Protection Officer (DPO) who is responsible for overseeing compliance with the Data Privacy Act of 2012 (RA 10173) and the implementing rules and regulations issued by the National Privacy Commission (NPC) of the Philippines. Contact details for the DPO are provided in Section 14 of this Policy.
Scope: This Privacy Policy applies to all personal data collected by phpopen through the phpopen.app website, any phpopen mobile web application, and all associated services including payment processing, customer support, and promotional communications. It applies to all registered players, prospective players who have initiated registration but not completed it, and visitors to the platform.
phpopen collects the following categories of personal data:
| Data Category | Examples | When Collected |
|---|---|---|
| Identity Data | Full legal name, date of birth, nationality, government ID type and number | Registration; KYC verification |
| Contact Data | Philippine mobile number, email address | Registration; account updates |
| Financial Data | GCash number, bank account details (masked), transaction records, deposit and withdrawal history | Payment processing; AML compliance |
| KYC Documents | Copies of government-issued photo ID (PhilSys, passport, LTO license, SSS/UMID card) | KYC verification before first withdrawal |
| Gaming Data | Bet history, game session duration, win/loss records, bonus usage, wagering patterns | Continuous platform use |
| Technical Data | IP address, device type, browser type and version, operating system, screen resolution, session timestamps | Automatic — every platform visit |
| Communication Data | Support chat transcripts, email correspondence, feedback submissions | Customer support interactions |
| Preference Data | Preferred games, language settings, marketing preferences, notification opt-in status | Account settings; behavioral analysis |
phpopen does not intentionally collect sensitive personal information (as defined under RA 10173) such as racial or ethnic origin, political opinions, religious beliefs, or health data, except where specifically required by law (for example, disability information provided voluntarily in connection with a responsible gaming request).
phpopen collects personal data through the following methods:
phpopen uses your personal data for the following purposes:
Under the Data Privacy Act of 2012 (RA 10173), phpopen processes your personal data on the following legal bases:
phpopen does not sell your personal data. We do not share your data with third parties for their independent marketing or commercial purposes. We share your personal data only in the following circumstances:
Business Transfer: In the event of a merger, acquisition, or sale of all or substantially all of phpopen's assets, your personal data may be transferred to the acquiring entity. In such an event, you will be notified in advance, and the acquiring entity will be bound by this Privacy Policy or a replacement policy that provides equivalent protection.
phpopen uses cookies and similar tracking technologies on the phpopen.app platform. A cookie is a small text file placed on your device when you visit a website, used to remember information about your visit and improve your experience.
phpopen uses the following categories of cookies:
| Cookie Type | Purpose | Can You Opt Out? |
|---|---|---|
| Strictly Necessary | Maintain your login session, process transactions, and ensure platform security. Required for the platform to function. | No — required for operation |
| Functional | Remember your language preference, game display settings, and account display preferences. | Yes — via account settings |
| Analytics | Aggregate, de-identified data about how players navigate the platform, which game categories are most visited, and technical performance metrics. | Yes — via browser settings |
| Security & Fraud Prevention | Detect unusual login patterns, identify device fingerprints associated with fraudulent accounts, and flag anomalous transaction behavior. | No — required for security |
phpopen does not use advertising or retargeting cookies that track your browsing activity across other websites. You can manage cookie preferences through your browser settings. Disabling strictly necessary cookies will impair or prevent your ability to log in and use the platform.
phpopen retains your personal data for as long as necessary to fulfill the purpose for which it was collected, or as required by applicable Philippine law. The following retention guidelines apply:
Upon expiry of the applicable retention period, personal data is securely deleted or anonymized such that it can no longer be attributed to any identified or identifiable individual. Securely deleted data cannot be recovered.
phpopen implements technical and organizational security measures appropriate to the sensitivity of the personal data it holds, including:
Your Role in Security: phpopen's security measures are one side of account protection. Your obligation to maintain a strong, unique password and to enable two-factor authentication is equally important. See the phpopen Terms & Conditions for your account security obligations.
The Data Privacy Act of 2012 (RA 10173) grants you the following rights in relation to your personal data held by phpopen. phpopen will respond to all verified rights requests within fifteen (15) business days of receipt.
The right to know that your personal data is being collected and processed, and to receive clear information about how it is used — which is the purpose of this Privacy Policy.
The right to request a copy of the personal data phpopen holds about you, including information about the purposes of processing and any third parties with whom it has been shared.
The right to request correction of any inaccurate, incomplete, or outdated personal data phpopen holds about you. Corrections to KYC data may require re-submission of verification documents.
The right to request deletion of your personal data where it is no longer necessary for the original purpose, subject to phpopen's legal retention obligations under AMLA and other applicable law.
The right to object to processing of your personal data for marketing purposes or where phpopen relies on legitimate interests as the legal basis. Objections are processed without detriment to your account.
The right to receive a structured, machine-readable copy of personal data you have provided to phpopen, for transfer to another service provider where technically feasible.
The right to lodge a complaint with the National Privacy Commission (NPC) of the Philippines if you believe phpopen has processed your personal data in violation of RA 10173. The NPC is reachable at privacy.gov.ph.
Where phpopen processes your data based on consent (primarily for marketing communications), you may withdraw that consent at any time without affecting prior lawful processing. Opt-out is available via account settings.
To exercise any of these rights, submit a written request to the phpopen Data Protection Officer using the contact details in Section 14. phpopen may request verification of your identity before processing a rights request to protect your data from unauthorized third-party access.
The phpopen platform is strictly intended for adults aged 21 years and older in compliance with PAGCOR regulations governing online casino gaming in the Philippines. phpopen does not knowingly collect personal data from individuals under 21 years of age.
During registration, every applicant is required to confirm that they are at least 21 years old. This representation is verified during the KYC process through government-issued identification documents showing date of birth. Any account found to belong to an individual under 21 will be immediately closed and all associated data deleted, except where retention is required for regulatory reporting purposes.
If you believe a minor has registered an account on phpopen, please contact the support team immediately using the contact information provided in Section 14 of this Policy.
Some of phpopen's third-party service providers — including cloud infrastructure, content delivery networks, and KYC verification services — may process data on servers located outside the Philippines. Where such cross-border transfers occur, phpopen ensures that:
phpopen will not transfer personal data to a jurisdiction that does not offer adequate protections unless one of the above safeguards is in place. Where required, phpopen will seek NPC approval for cross-border transfers in accordance with NPC Circular 16-01 and its amendments.
phpopen may update this Privacy Policy from time to time to reflect changes in its data processing practices, applicable law, or NPC guidance. The "Effective Date" at the top of this page will be updated when changes are made.
Where a change is material — meaning it significantly affects the rights of players or the nature of data processing — phpopen will provide advance notice via one or more of the following methods: a notice on the phpopen.app homepage, an in-platform notification displayed upon login, or an email to your registered email address. The notice will be provided at least 14 days before the change takes effect where practicable.
Your continued use of the phpopen platform after the effective date of an updated Privacy Policy constitutes your acknowledgment of the changes. If you do not agree with a material change to this Policy, you may close your account by contacting the support team.
The most current version of this Privacy Policy is always available at phpopen.app/privacy-policy.
If you have any questions about this Privacy Policy, wish to exercise your data subject rights, or wish to report a suspected privacy breach, please contact phpopen's Data Protection Officer using the details below.
phpopen Data Protection Officer
Contact via: [email protected] (plain text — not a clickable link)
Subject line: "DPO Request — [Your Request Type]"
Available: Monday to Friday, 9:00 AM – 6:00 PM Philippine Standard Time (PST)
General Support (24/7): [email protected]
phpopen will acknowledge receipt of your request within two (2) business days and provide a substantive response within fifteen (15) business days. Where additional time is required for complex requests, phpopen will notify you of the expected response timeline.
If you are not satisfied with phpopen's response to your privacy concern, you have the right to lodge a complaint with the National Privacy Commission (NPC) of the Republic of the Philippines. The NPC is the supervisory authority responsible for enforcing RA 10173 and can be reached through their official government website and offices in Manila.
For information about the specific rules governing your phpopen account — including payment terms, bonus conditions, and player obligations — please review the Terms & Conditions. For information about player protection tools and responsible gaming resources, please visit the Responsible Gaming page.
phpopen is built on the same security standards as Philippine digital banking — so you can focus on the game, not worry about your data.
By registering you confirm you are 21+ and have read and accepted this Privacy Policy and our Terms & Conditions.