Six principles that guide how phmasaya handles your personal information
phmasaya collects only the personal data that is strictly necessary to operate your account, comply with Philippine law, and deliver our gaming services. We do not collect data beyond what is described in this Privacy Policy.
All personal data transmitted to and stored by phmasaya is protected by SSL/TLS encryption in transit and AES-256 encryption at rest. Access to your personal data is restricted to authorized personnel on a need-to-know basis.
phmasaya processes personal data in compliance with Republic Act No. 10173, the Data Privacy Act of 2012, and its Implementing Rules and Regulations. We are registered with the National Privacy Commission of the Philippines.
You have the right to access, correct, object to, and request deletion of your personal data held by phmasaya. We respond to data subject requests within the timeframes required by Philippine data privacy law.
phmasaya does not sell, rent, or trade your personal information to third-party marketing companies or data brokers. Your data is used solely for the purposes described in this Privacy Policy.
In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, phmasaya will notify you and the National Privacy Commission within seventy-two (72) hours of becoming aware of the breach, in accordance with applicable Philippine law.
This Privacy Policy ("Policy") describes how phmasaya ("phmasaya," "the Platform," "we," "us," "our"), the operator of the online gaming platform at phmasaya.app, collects, uses, stores, discloses, and protects the personal data of individuals who register accounts, access, or otherwise use the phmasaya platform ("you," "Player," "Data Subject"). This Policy forms part of our overall Terms and Conditions and is incorporated therein by reference. By creating a phmasaya account or using any of our services, you acknowledge that you have read and understood this Privacy Policy.
phmasaya is committed to protecting the privacy and personal data of all players and platform visitors in accordance with Republic Act No. 10173, the Data Privacy Act of 2012 of the Republic of the Philippines ("DPA"), and its Implementing Rules and Regulations ("IRR"), together with any subsequent amendments, guidelines, and circulars issued by the National Privacy Commission ("NPC").
This Policy applies to all personal data collected and processed by phmasaya in connection with the operation of the phmasaya.app platform, including all gaming services, payment processing, customer support interactions, promotional communications, and identity verification activities. It applies to registered players, account applicants, website visitors, and any individual whose personal data phmasaya holds.
This Policy does not extend to third-party websites, payment providers, or game studios that may be linked to or integrated with the phmasaya platform. Those third parties operate under their own privacy policies, and phmasaya encourages you to review those policies independently.
For the purposes of the Data Privacy Act of 2012 and its Implementing Rules and Regulations, phmasaya is the personal information controller ("PIC") in respect of the personal data it collects and processes in connection with the phmasaya platform.
Data Protection Officer (DPO): phmasaya has appointed a Data Protection Officer responsible for overseeing compliance with this Policy and with applicable Philippine data privacy law. All data privacy inquiries, requests, and complaints may be directed to the DPO via the contact details provided in Section 15 of this Policy.
phmasaya collects the following categories of personal data from players and platform visitors:
Sensitive Personal Information: Copies of government-issued identification documents and date of birth information constitute sensitive personal information under the DPA. phmasaya applies heightened data protection measures to this category of data, including restricted access controls and enhanced encryption.
phmasaya collects personal data through the following means:
phmasaya uses the personal data it collects for the following purposes:
| Purpose | Data Used |
|---|---|
| Account creation and management | Name, email, mobile number, password, date of birth |
| Identity verification (KYC) | Government ID documents, selfie photograph, date of birth |
| Payment processing | GCash/Maya number, bank account details, transaction history |
| Fraud prevention & AML compliance | Transaction data, IP address, device data, ID documents |
| Customer support | Account data, support interaction records, contact details |
| Responsible gaming monitoring | Game session data, deposit history, self-exclusion settings |
| Regulatory reporting | Transaction data, identity data, as required by PAGCOR and AMLC |
| Platform improvement | Aggregated and anonymized behavioral and technical data |
| Marketing communications (with consent) | Email address, mobile number, game preference data |
phmasaya processes your personal data on the following legal bases as recognized under the Data Privacy Act of 2012:
phmasaya does not sell, rent, or trade your personal data to third parties for their marketing purposes. phmasaya may share your personal data with the following categories of recipients under the circumstances described:
Personal data necessary to process deposits and withdrawals (including mobile numbers, bank account details, and transaction amounts) is shared with payment processors such as GCash (G-Xchange, Inc.), Maya (PayMaya Philippines, Inc.), and Philippine banking institutions (BPI, BDO, UnionBank) solely for the purpose of executing payment transactions on your behalf.
Where phmasaya engages third-party KYC and identity verification service providers to assist with the verification of player identity and document authenticity, those providers process the personal data submitted during KYC on phmasaya's behalf as personal information processors. phmasaya ensures that such providers are bound by contractual data protection obligations consistent with the DPA.
phmasaya is required by law to disclose certain player data to Philippine regulatory and law enforcement authorities, including the Philippine Amusement and Gaming Corporation (PAGCOR), the Anti-Money Laundering Council (AMLC), and other competent authorities, where required by applicable law, court order, or official regulatory directive. Such disclosures are made strictly in compliance with applicable legal requirements.
phmasaya works with game studios, live dealer streaming providers, and platform technology vendors to deliver gaming services. These providers may process limited technical and session data on phmasaya's behalf as personal information processors. They are contractually prohibited from using such data for any purpose other than delivering the contracted services to phmasaya.
Reminder: phmasaya will never share your personal data with third-party marketing companies, data aggregators, or lead generation platforms. If you receive unsolicited communications purportedly from phmasaya via channels you did not register with us, please report this to our support team immediately as it may indicate a phishing attempt.
phmasaya retains your personal data for as long as is necessary to fulfill the purposes for which it was collected, subject to the minimum retention periods required by Philippine law:
Upon the expiry of the applicable retention period, phmasaya will securely delete or anonymize your personal data in accordance with procedures approved by its Data Protection Officer.
phmasaya uses cookies and similar tracking technologies on the phmasaya.app platform for the following purposes:
You may manage your cookie preferences through your browser settings. Disabling essential cookies may impair your ability to log into or use the phmasaya platform. phmasaya does not use third-party advertising or retargeting cookies.
phmasaya implements the following technical and organizational security measures to protect your personal data against unauthorized access, disclosure, alteration, or destruction:
Important: While phmasaya employs robust security measures, no online platform can guarantee absolute security. You are encouraged to use a strong, unique password for your phmasaya account and to enable Two-Factor Authentication (2FA) available in your account security settings.
Under the Data Privacy Act of 2012 and its Implementing Rules and Regulations, you have the following rights with respect to your personal data held by phmasaya. To exercise any of these rights, please contact phmasaya's Data Protection Officer using the contact details in Section 15.
Rights granted to you under the Data Privacy Act of 2012 (RA 10173) as a phmasaya player
You have the right to be informed of how phmasaya collects, uses, retains, and discloses your personal data. This Privacy Policy is our primary means of fulfilling this obligation.
You may request a copy of the personal data phmasaya holds about you. We will respond to access requests within thirty (30) days of receipt, subject to identity verification.
If any personal data phmasaya holds about you is inaccurate, incomplete, or outdated, you have the right to request correction. Contact our support team or update your details directly in your account settings.
You may request deletion of your personal data where it is no longer necessary for the purposes for which it was collected, subject to phmasaya's legal data retention obligations under Philippine law.
You have the right to object to the processing of your personal data for direct marketing purposes. You may opt out of marketing communications at any time by contacting our support team.
You have the right to receive a structured, machine-readable copy of personal data you provided to phmasaya, where technically feasible and where processing is carried out by automated means.
Where you contest the accuracy of your data or have objected to processing, you may request that phmasaya restrict further processing of your data while the matter is under review.
If you believe phmasaya has not handled your personal data in accordance with the Data Privacy Act, you have the right to lodge a complaint with the National Privacy Commission (NPC) of the Philippines.
Where phmasaya's non-compliance with the Data Privacy Act has caused you actual damage, you have the right to seek compensation for such damage in accordance with applicable Philippine law.
phmasaya's gaming services are strictly intended for individuals who are 21 years of age or older, in compliance with Philippine gaming law. phmasaya does not knowingly collect personal data from individuals under the age of 21. Where phmasaya discovers or has reasonable grounds to believe that an account has been registered by or on behalf of an individual under 21 years of age, it will immediately suspend the account, void any associated transactions, and delete all personal data associated with that account, subject to any legal retention obligations.
If you are a parent or guardian and believe that a minor has registered a phmasaya account using your information or otherwise, please contact phmasaya's Data Protection Officer immediately using the details in Section 15.
Where phmasaya engages third-party service providers — such as cloud hosting providers, game studios, KYC verification partners, or payment processors — that process personal data outside the Republic of the Philippines, phmasaya ensures that such transfers are conducted in compliance with Section 21 of the Data Privacy Act and applicable NPC guidelines on cross-border data transfers.
Specifically, phmasaya requires that all international data processing agreements include contractual clauses that afford the personal data transferred a level of protection at least equivalent to that provided under Philippine law, including obligations on data security, purpose limitation, and data subject rights. phmasaya does not transfer sensitive personal information (such as KYC documents) to processors in jurisdictions that do not provide an adequate level of data protection without appropriate safeguards.
phmasaya reserves the right to update or amend this Privacy Policy at any time to reflect changes in our data processing practices, applicable Philippine law, or NPC guidance. Where changes are material, phmasaya will notify registered players by email to their registered address and by posting a prominent notice on the platform at least seven (7) days before the amended Policy takes effect.
The "Last Updated" date at the top of this Privacy Policy will reflect the date of the most recent revision. Your continued use of the phmasaya platform following the effective date of any amended Privacy Policy constitutes your acknowledgment of and agreement to the updated terms. We encourage you to review this Policy periodically to stay informed about how phmasaya protects your personal data.
For all data privacy inquiries, data subject rights requests, or complaints relating to phmasaya's processing of your personal data, please contact our Data Protection Officer through the following channels:
phmasaya will acknowledge all data subject rights requests within forty-eight (48) hours and will respond substantively within thirty (30) calendar days. Where a request requires additional time due to its complexity or volume, phmasaya will notify you of the extension and the reasons therefor within the initial thirty-day period.
NPC Complaints: If you are not satisfied with phmasaya's response to your data privacy complaint, you have the right to escalate the matter to the National Privacy Commission of the Philippines. Information on how to file a complaint with the NPC is available on the NPC's official website.
Now that you know how we protect your data, explore 700+ games with confidence — GCash deposits, 24/7 support, and a platform built for Filipino players.