phcsh Privacy Policy
This Privacy Policy describes how phcsh collects, uses, stores, shares, and protects the personal information of all players and visitors. Your data belongs to you — this document explains exactly what we do with it.
phcsh collects only the personal data that is strictly necessary for account operation, identity verification, payment processing, and regulatory compliance. We do not harvest data for purposes unrelated to the platform services you have signed up for.
phcsh does not sell, rent, or trade your personal information to any third-party organization for marketing or commercial purposes. Your contact details, transaction history, and gaming behaviour are not monetized beyond the phcsh platform itself.
All data transmitted between your device and phcsh is protected by SSL/TLS encryption. Personal and financial data at rest is stored in encrypted form on access-controlled servers. Payment credentials are handled by certified PCI-DSS compliant payment processors.
As a Philippine resident, you are protected by the Data Privacy Act of 2012 (RA 10173). phcsh recognizes and honours your right to access, correct, delete, and port your personal data. Requests can be submitted at any time to our Data Protection Officer.
Promotional communications from phcsh are opt-in. You can withdraw consent for marketing messages at any time through your account settings or by contacting support. Withdrawal of marketing consent does not affect the lawful processing of data required to operate your account.
phcsh retains personal data only as long as required for the purposes it was collected or as mandated by PAGCOR regulations and Philippine law. Once the applicable retention period expires, data is securely deleted or irreversibly anonymized.
Introduction
phcsh ("we," "us," or "our") operates the online casino and sports betting platform accessible at phcsh.org. As a platform that processes personal and financial data from Filipino players across Manila, Cebu, Davao, and the rest of the Philippines, we take data privacy obligations seriously and comply with the requirements of Republic Act No. 10173, the Data Privacy Act of 2012 (DPA), and its Implementing Rules and Regulations as enforced by the National Privacy Commission (NPC).
This Privacy Policy applies to all personal data collected through the phcsh website, platform features, customer support channels, payment processing flows, and any related services. It governs data collected from registered players, visitors who browse without registering, and individuals who contact phcsh through any communication channel.
By using the phcsh platform or creating an account, you acknowledge that you have read and understood this Privacy Policy and consent to the collection and use of your personal data as described herein. If you do not agree, you should discontinue use of the phcsh platform and request account closure if applicable.
Data Controller
For the purposes of the Data Privacy Act of 2012 and this Privacy Policy, phcsh acts as the Personal Information Controller (PIC) with respect to all personal data collected from players and visitors of the phcsh.org platform.
As the PIC, phcsh determines the purpose and means of processing your personal information. Where phcsh engages third-party service providers to process data on our behalf (for example, payment processors, game providers, and fraud prevention services), those parties act as Personal Information Processors (PIPs) and are bound by data processing agreements that prohibit them from using your data for any purpose beyond the service they provide to phcsh.
Contact details for phcsh's designated Data Protection Officer (DPO) are provided in Section 15 of this Policy.
Data We Collect
The categories of personal data phcsh collects depend on how you interact with the platform. The following table outlines the main data categories, the specific data points within each, and the context in which they are collected:
| Category | Data Points | When Collected |
|---|---|---|
| Identity Data | Full legal name, date of birth, nationality, gender, government ID type and number | Registration & KYC |
| Contact Data | Philippine mobile number, email address (if provided), home address (if required for enhanced KYC) | Registration |
| Financial Data | GCash / Maya account reference, bank account name (not full account numbers), deposit and withdrawal transaction records | Payment Processing |
| Gaming Data | Game session history, bet amounts, win/loss records, bonus usage, session duration, game preferences | Platform Usage |
| Technical Data | IP address, device type and OS, browser type, session tokens, login timestamps, geolocation (country/region level) | Any Platform Access |
| Communications | Support chat transcripts, email correspondence, feedback submissions | Support Interactions |
| Responsible Gaming | Self-exclusion status, deposit limit settings, cooling-off periods, risk flags | Tool Activation |
phcsh does not intentionally collect sensitive personal information as defined under the DPA (such as health data, religious beliefs, or political views) unless it is directly relevant to a legal compliance obligation — for example, a self-declaration of a medical condition in connection with a responsible gaming self-exclusion request.
How We Collect Data
phcsh collects your personal data through the following means:
- Direct submission: Information you provide when registering an account, completing KYC verification, making a deposit or withdrawal request, contacting customer support, or filling in any platform form.
- Automated collection: Technical data collected automatically when you access the phcsh platform, including through cookies, web beacons, session tracking, and server logs. See Section 11 for full details on cookies.
- Payment providers: Transaction reference data passed to phcsh by GCash, Maya, BPI, BDO, Metrobank, InstaPay, or any other payment service used to fund or withdraw from your phcsh wallet. phcsh does not receive full payment credentials — only the reference information needed to confirm and reconcile transactions.
- Identity verification services: Data returned by third-party KYC verification providers used to validate the authenticity of identity documents submitted during registration.
- Game providers: Session and outcome data passed back to phcsh by JILI, Pragmatic Play, PG Soft, Evolution, and other game suppliers in connection with gameplay conducted on the phcsh platform.
- Fraud detection systems: Risk signals and behavioural flags generated by phcsh's automated fraud detection infrastructure based on gameplay and transaction patterns.
Purpose & Legal Basis for Processing
phcsh processes your personal data only for specified, legitimate purposes. The following table summarizes each processing purpose and its legal basis under the Data Privacy Act of 2012:
| Processing Purpose | Legal Basis |
|---|---|
| Account registration and management | Fulfilment of contract (Terms & Conditions) |
| Identity verification and KYC compliance | Legal obligation (PAGCOR regulations) |
| Processing deposits and withdrawals | Fulfilment of contract |
| Fraud prevention and security monitoring | Legitimate interest / Legal obligation |
| Anti-money laundering (AML) screening | Legal obligation (AMLC regulations) |
| Responsible gaming monitoring | Legal obligation / Vital interests |
| Customer support and dispute resolution | Fulfilment of contract / Legitimate interest |
| Platform analytics and improvement | Legitimate interest |
| Sending promotional communications | Consent (opt-in only) |
| Regulatory reporting to PAGCOR / NPC | Legal obligation |
Where phcsh relies on your consent as the legal basis for processing (such as for marketing communications), you have the right to withdraw that consent at any time without affecting the lawfulness of processing conducted prior to withdrawal.
KYC & Identity Verification
phcsh is required by PAGCOR to verify the identity and age of all players before granting access to real-money gaming. This KYC process involves the collection and verification of your government-issued identification documents.
Accepted identity documents for KYC include Philippine-issued IDs such as the PhilSys National ID, SSS ID, UMID, driver's licence, passport, PRC ID, voter's ID, and Postal ID. phcsh may request one or more of these documents depending on the level of KYC verification required.
KYC documents are processed by phcsh and, where applicable, by our contracted identity verification service provider. These documents are stored securely in encrypted form and accessed only by authorized phcsh personnel with a direct operational need. KYC data is never shared for commercial purposes.
For players subject to enhanced due diligence — for example, those making large transactions or triggering AML screening thresholds — phcsh may request additional documentation such as proof of address, source of funds declarations, or bank statements. This is a legal obligation, not optional, and non-compliance may result in temporary restriction of withdrawal access pending verification.
Sharing Your Data
phcsh does not sell, rent, or commercially transfer your personal data to third parties. We share your data only in the following limited circumstances:
- Payment processors: Transaction data is shared with GCash, Maya, BDO, BPI, Metrobank, and other payment service providers solely to process deposits and withdrawals linked to your phcsh account.
- Game providers: Session identifiers and bet data are shared with JILI, Pragmatic Play, PG Soft, Evolution Gaming, and other platform game suppliers to deliver game content and record outcomes.
- KYC verification partners: Identity document data is shared with contracted third-party identity verification services for the purpose of age and identity validation. These parties are contractually prohibited from using your data for any other purpose.
- Fraud prevention services: Transaction patterns, device fingerprints, and behavioural data may be shared with fraud detection platforms to protect the integrity of the phcsh platform and prevent financial crime.
- Regulatory authorities: phcsh is legally required to disclose player data to PAGCOR, the Anti-Money Laundering Council (AMLC), the National Privacy Commission (NPC), and other competent Philippine authorities when required by law, court order, or regulatory direction. We will notify you of any such disclosure where we are legally permitted to do so.
- Business successors: In the event of a merger, acquisition, or transfer of the phcsh business, player data may be transferred to the acquiring entity, subject to equivalent privacy protections being maintained. Registered players will be notified of any such transfer in advance.
International Data Transfers
Some of the third-party service providers used by phcsh — including game suppliers and payment processors — may process or store data on servers located outside the Philippines. Where such international transfers occur, phcsh ensures that appropriate safeguards are in place to protect your personal data consistent with the requirements of the Data Privacy Act of 2012.
These safeguards include contractual data processing agreements that require international recipients to maintain data protection standards at least equivalent to those under Philippine law. phcsh conducts due diligence on all international data processors before engaging their services and reviews these arrangements periodically.
If you wish to obtain information about the specific safeguards phcsh has in place for any particular international transfer, you may contact our Data Protection Officer at the details provided in Section 15.
Data Retention
phcsh retains personal data for the period necessary to fulfil the purposes for which it was collected, subject to the minimum retention periods required by PAGCOR regulations, the Data Privacy Act, and other applicable Philippine law.
The following general retention periods apply:
- Account and identity data: Retained for the lifetime of the account, plus a minimum of 5 years following account closure, as required for AML compliance and regulatory audit purposes.
- Transaction records: Retained for a minimum of 5 years from the date of each transaction in compliance with AMLC record-keeping requirements.
- KYC documents: Retained for the duration of the account relationship plus 5 years post-closure, subject to PAGCOR retention mandates.
- Gaming session logs: Retained for a minimum of 3 years for dispute resolution and regulatory audit purposes.
- Support communications: Retained for 2 years from the date of the last interaction in the relevant support case.
- Marketing consent records: Retained for as long as marketing communications are sent, plus 1 year after consent is withdrawn, to demonstrate compliance.
- Technical logs: Generally retained for 12 months for security monitoring and incident response, unless a specific incident requires longer retention.
Upon expiry of applicable retention periods, phcsh will securely delete or irreversibly anonymize the relevant data. Anonymized data — from which all personally identifying information has been permanently removed — may be retained indefinitely for platform analytics.
Security Measures
phcsh implements a layered set of technical and organizational security measures designed to protect your personal data against unauthorized access, disclosure, alteration, and destruction:
- Encryption in transit: All data transmitted between your browser or app and the phcsh platform is protected using TLS 1.2 or higher (SSL). phcsh enforces HTTPS across all pages and API endpoints.
- Encryption at rest: Sensitive personal data and financial data stored in phcsh databases is encrypted using AES-256 encryption or equivalent. Encryption keys are managed separately from the data they protect.
- Access controls: Access to systems containing personal data is restricted to phcsh personnel with a documented operational need. All access is authenticated through multi-factor authentication and logged for audit purposes.
- Payment security: phcsh does not store full payment card numbers, CVVs, or banking passwords. Payment credential processing is handled entirely by PCI-DSS certified payment processors.
- Penetration testing: phcsh conducts periodic security assessments of its platform infrastructure to identify and remediate vulnerabilities before they can be exploited.
- Incident response: phcsh maintains a data breach response procedure aligned with NPC requirements. In the event of a personal data breach that poses a significant risk to affected individuals, phcsh will notify the NPC within 72 hours of discovery and notify affected players without undue delay.
Cookies & Tracking Technologies
phcsh uses cookies and similar technologies to operate the platform, remember your preferences, maintain session security, and understand how the platform is being used. The following categories of cookies are used:
- Strictly necessary cookies are essential for the platform to function. They enable session management, login authentication, security token validation, and basic navigation. These cookies cannot be disabled without breaking core platform functionality.
- Analytics cookies collect aggregated, anonymized data about how players navigate and use the phcsh platform. This data helps us identify usability issues, measure feature performance, and prioritize improvements. No personally identifiable information is collected in analytics cookies.
- Preference cookies remember settings you have configured — such as display preferences or responsible gaming tool selections — so they are retained between sessions.
phcsh does not use advertising or retargeting cookies that track your behaviour across third-party websites. All tracking on the phcsh platform is limited to first-party analytics aimed at improving platform quality.
Most browsers allow you to block or delete cookies through browser settings. Note that blocking strictly necessary cookies will prevent the phcsh platform from functioning correctly. Instructions for managing cookies are available in your browser's help documentation.
Your Data Rights
Under the Data Privacy Act of 2012, you have the following rights with respect to your personal data held by phcsh. These rights can be exercised by contacting our Data Protection Officer at the details in Section 15.
Request a copy of the personal data phcsh holds about you, the purposes for which it is processed, and the parties with whom it has been shared.
Request correction of inaccurate or incomplete personal data. You can update most contact details directly from your phcsh account settings.
Request deletion of your personal data when it is no longer necessary, where consent is withdrawn, or where processing is unlawful. Requests may be declined where retention is required by law.
Object to the processing of your personal data on grounds of legitimate interest or for direct marketing purposes. Objections to marketing are actioned immediately.
Request that phcsh provide your personal data in a structured, machine-readable format, or transmit it to another service provider where technically feasible.
Lodge a complaint with the National Privacy Commission (NPC) if you believe phcsh has violated your data privacy rights under Philippine law.
phcsh will respond to all data rights requests within 30 days of receipt. For complex requests, we may extend this period by a further 30 days with prior notification and explanation. All requests must be accompanied by sufficient identity verification to ensure phcsh is disclosing or modifying data to the correct individual.
Minors
The phcsh platform is strictly intended for adults aged 21 years and above. phcsh does not knowingly collect personal data from individuals under the age of 21. The KYC process is designed to detect and prevent registration by underage individuals, including cross-checking submitted ID documents against the stated date of birth.
Parents and guardians who believe a minor may have accessed the phcsh platform should contact our Data Protection Officer immediately at the details provided in Section 15.
Policy Updates
phcsh may update this Privacy Policy from time to time to reflect changes in our data processing practices, the services we offer, applicable law, or guidance from the National Privacy Commission. The "Effective Date" at the top of this page will be updated whenever a revision is made.
For material changes — those that significantly affect how we process your personal data or your rights as a data subject — phcsh will provide advance notice to registered players via their registered mobile number or platform notification at least 15 days before the changes take effect. Continued use of the phcsh platform after the effective date of any revision constitutes acceptance of the updated Privacy Policy.
We recommend reviewing this Privacy Policy periodically to stay informed about how phcsh protects your data. Prior versions of this Policy are retained by phcsh for a period of 5 years and are available upon request from our Data Protection Officer.
Contact & Data Protection Officer
For all queries, complaints, or requests relating to this Privacy Policy or the exercise of your data rights under the Data Privacy Act of 2012, please contact phcsh's designated Data Protection Officer:
Ready to Play at phcsh?
Now that you understand how phcsh handles your personal data, sign in to your account or explore the casino. 21+ only, play responsibly, and know your rights.
// 21+ only · RA 10173 compliant · phcsh.org