phlao is committed to protecting the personal data of every Filipino player on our platform. This Privacy Policy explains exactly what information we collect, why we collect it, how we use it, and the rights you have over your own data.
This Privacy Policy applies to all personal data collected and processed by phlao in connection with the operation of the phlao online casino and sports betting platform, accessible at phlao.com. It applies to all registered players, visitors to the phlao website, and any individual who interacts with phlao's customer support team.
phlao takes its data protection obligations seriously. We process personal data in accordance with applicable Philippine data privacy laws, including the Data Privacy Act of 2012 (Republic Act No. 10173) and its implementing rules and regulations. By registering a phlao account or using the phlao platform, you acknowledge that you have read and understood this Privacy Policy.
This Privacy Policy should be read alongside the phlao Terms & Conditions, which govern your use of the platform as a whole. Capitalised terms used but not defined in this Policy have the meanings given to them in the Terms & Conditions.
phlao collects the following categories of personal data from players and platform users:
phlao collects personal data through the following means:
phlao processes your personal data for the following purposes:
| Purpose | Data Used |
|---|---|
| Account registration and management | Identity, contact data |
| Age and identity verification (KYC) | Identity data, ID documents |
| Processing deposits and withdrawals | Financial data, identity data |
| Providing and improving gaming services | Gaming data, technical data |
| Fraud prevention and security monitoring | Technical data, financial data, gaming data |
| Regulatory compliance and AML obligations | Identity data, financial data, gaming data |
| Responsible gaming monitoring and tools | Gaming data, responsible gaming settings |
| Customer support | Identity data, communications data |
| Marketing communications (with consent) | Contact data, gaming data |
| Platform analytics and performance | Technical data, gaming data |
phlao processes your personal data on the following legal bases under the Data Privacy Act of 2012:
phlao does not sell your personal data to third parties. We share personal data only in the following circumstances:
phlao shares data with carefully selected third-party service providers who assist in operating the platform, including KYC and identity verification providers, payment processors (GCash, PayMaya, BPI, BDO, Metrobank), fraud detection services, and cloud infrastructure providers. All service providers are contractually bound to process data only on phlao's instructions and to maintain appropriate security standards.
phlao may disclose personal data to PAGCOR , the National Privacy Commission (NPC), law enforcement agencies, or other competent authorities where required by Philippine law, court order, or regulatory obligation. phlao will notify affected players of such disclosures where legally permitted to do so.
In the event of a merger, acquisition, or sale of all or part of phlao's business, your personal data may be transferred to the acquiring entity as part of that transaction. phlao will notify affected players prior to any such transfer and ensure that the receiving entity is bound by data protection obligations no less stringent than those in this Policy.
Where phlao transfers personal data outside the Philippines, we ensure that appropriate safeguards are in place in accordance with the Data Privacy Act of 2012 and the regulations of the National Privacy Commission. We do not transfer personal data to jurisdictions that do not provide an adequate level of data protection without implementing appropriate contractual protections.
phlao retains personal data only for as long as necessary to fulfil the purposes for which it was collected, or as required by applicable law. The following general retention periods apply:
| Data Category | Retention Period |
|---|---|
| Account and identity data | Duration of account plus 5 years after closure |
| KYC documents | Duration of account plus 5 years after closure |
| Financial transaction records | 10 years (AML regulatory requirement) |
| Gaming and betting history | Duration of account plus 3 years after closure |
| Customer support communications | 3 years from date of communication |
| Technical and session logs | 12 months from collection |
| Marketing consent records | Until consent is withdrawn, plus 1 year |
After the applicable retention period, personal data is securely deleted or anonymised in accordance with phlao's data disposal procedures. Anonymised data that can no longer identify you may be retained indefinitely for statistical and analytical purposes.
phlao implements a comprehensive set of technical and organisational security measures to protect your personal data against unauthorised access, disclosure, alteration, or destruction. These measures include:
phlao uses cookies and similar tracking technologies on the phlao platform to enhance your experience, maintain session security, and gather analytics data. The following types of cookies are used:
These cookies are strictly necessary for the phlao platform to function. They enable core features such as account login sessions, security tokens, and payment flow continuity. Essential cookies cannot be disabled without impairing platform functionality.
phlao uses analytics cookies to understand how players interact with the platform — which games are most popular, how long sessions last, and where players encounter difficulties. This data is used in aggregate and anonymised form to improve the phlao experience. Analytics cookies are only placed with your consent.
Preference cookies remember your platform settings, such as language preferences and display options, so you do not need to reconfigure them on each visit.
You can manage your cookie preferences through the cookie settings panel on the phlao platform, or by adjusting your browser settings. Note that disabling non-essential cookies will not affect your ability to use the core features of the phlao platform, but may limit certain personalisation features.
Under the Data Privacy Act of 2012 (Republic Act No. 10173), you have the following rights with respect to your personal data held by phlao:
If you are a parent or guardian and believe that a minor has registered a phlao account or provided personal data to phlao, please contact phlao support immediately at [email protected]. phlao will investigate and take appropriate action without delay.
phlao employs age verification procedures during account registration and KYC review to prevent minors from accessing the platform. These procedures are a core part of phlao's commitment to responsible gaming and compliance with Philippine gaming regulations.
phlao may update this Privacy Policy from time to time to reflect changes in our data processing practices, applicable law, or regulatory requirements. When material changes are made, phlao will notify registered players via the email address associated with their account and by displaying a prominent notice on the phlao platform.
The updated Privacy Policy will take effect from the date specified in the notice. Your continued use of the phlao platform after the effective date of any revision constitutes your acknowledgement of the updated Policy. We encourage you to review this page periodically to stay informed about how phlao protects your data.
If you have any questions, concerns, or requests relating to this Privacy Policy or phlao's handling of your personal data, please contact the phlao Data Protection Officer:
phlao is committed to resolving all privacy-related queries and complaints promptly. If you are not satisfied with phlao's response, you may escalate your complaint to the National Privacy Commission of the Philippines.
Privacy is not an afterthought at phlao — it is built into every layer of the platform. Here is a quick look at the protections in place for every Filipino player.
Every connection to phlao is secured with TLS encryption. Your personal details, payment information, and gaming data travel between your device and our servers in an encrypted tunnel that third parties cannot read.
phlao does not sell, rent, or trade your personal data to advertisers or data brokers — full stop. Your information is used solely to operate the phlao platform and comply with Philippine regulatory requirements.
Under the Data Privacy Act of 2012, you have the right to access, correct, and request deletion of your personal data. phlao makes it straightforward to exercise these rights — just reach out to our support team.
phlao processes personal data in accordance with Republic Act No. 10173 (Data Privacy Act of 2012) and its implementing rules. Our data practices are aligned with PAGCOR requirements and Philippine financial regulations.
phlao collects only the data that is genuinely necessary to operate the platform, verify your identity, and process your transactions. We do not collect data speculatively or for purposes beyond those described in this Policy.
In the unlikely event of a data breach affecting your personal information, phlao will notify you and the National Privacy Commission within the timeframes required by Philippine law. Transparency is a core part of how we operate.
You've read how phlao handles your personal data. Now experience the platform built around that commitment — secure transactions in PHP, certified fair games, and a support team available around the clock for players across Manila, Cebu, Davao, Quezon City, and the rest of the Philippines. Sign in or explore the full phlao Casino today. 21+ only.
Your data is protected by phlao