1. Introduction
phluck ("we," "us," or "our") operates the online gaming platform accessible at phluck.one. As a data controller, phluck is responsible for the personal data of all registered Members and visitors to our platform. This Privacy Policy ("Policy") describes our practices regarding the collection, use, storage, disclosure, and protection of your personal information.
This Policy is incorporated into and forms part of phluck's Terms & Conditions. By registering an account or using the phluck platform, you acknowledge that you have read and understood this Policy and consent to the processing of your personal data as described herein. If you do not agree with this Policy, you must not use the phluck platform.
phluck is registered with the National Privacy Commission (NPC) of the Philippines as required under the Data Privacy Act of 2012. Our Data Protection Officer (DPO) can be contacted at [email protected] for any privacy-related inquiries or complaints.
2. Personal Data We Collect
phluck collects the following categories of personal data from Members and platform visitors:
Identity Data:
- Full legal name as it appears on your government-issued identification
- Date of birth (used to verify the 21+ age requirement)
- Nationality and country of residence
- Government-issued ID number (e.g., PhilSys ID, passport, driver's license, SSS/GSIS number)
- Photograph or selfie submitted for identity verification purposes
Contact Data:
- Email address
- Mobile phone number
- Residential address (barangay, city/municipality, province, ZIP code)
Financial Data:
- GCash or PayMaya mobile wallet number
- Bank account details (BPI, BDO, Metrobank, or other Philippine banks) for withdrawal processing
- Transaction history, including deposit amounts, withdrawal amounts, and dates
- Source of funds declarations where required by anti-money laundering regulations
Gaming Activity Data:
- Game history, including games played, wagers placed, and outcomes
- Session duration and frequency of play
- Bonus and promotion usage history
- Responsible gaming tool settings and self-exclusion records
Technical Data:
- IP address and approximate geolocation
- Device type, operating system, and browser information
- Cookie identifiers and session tokens
- Platform access logs and timestamps
3. How We Collect Your Data
phluck collects personal data through the following means:
- Direct Collection: Data you provide when registering an account, completing KYC verification, making deposits or withdrawals, contacting customer support, or participating in promotions.
- Automated Collection: Technical data collected automatically when you access the phluck platform, including through cookies, web beacons, and server logs.
- Third-Party Sources: Identity verification data from KYC service providers; fraud detection signals from payment processors; geolocation data from IP intelligence services. All third-party data sources used by phluck are contractually bound to comply with applicable data protection laws.
4. How We Use Your Personal Data
phluck processes your personal data for the following purposes:
- Account Management: To create, maintain, and administer your phluck account, including verifying your identity and age eligibility.
- Service Delivery: To provide access to games, process deposits and withdrawals, and deliver the gaming services you have requested.
- Legal Compliance: To comply with our obligations under the Anti-Money Laundering Act (AMLA), the Data Privacy Act, PAGCOR regulations, and other applicable Philippine laws. This includes conducting KYC checks, filing Suspicious Transaction Reports (STRs) where required, and maintaining transaction records.
- Fraud Prevention and Security: To detect, investigate, and prevent fraudulent activity, unauthorized account access, and other security threats.
- Responsible Gaming: To monitor gaming patterns and identify Members who may be exhibiting signs of problem gambling, and to administer responsible gaming tools such as deposit limits and self-exclusion.
- Customer Support: To respond to your inquiries, resolve disputes, and provide technical assistance.
- Marketing Communications: To send you promotional offers, bonus notifications, and platform updates, where you have provided consent or where permitted by applicable law. You may opt out of marketing communications at any time.
- Platform Improvement: To analyze usage patterns and improve the functionality, performance, and user experience of the phluck platform.
5. Legal Basis for Processing
phluck processes your personal data on the following legal bases as recognized under the Data Privacy Act of 2012:
- Contractual Necessity: Processing required to perform our obligations under the Terms & Conditions you have agreed to, including account management and service delivery.
- Legal Obligation: Processing required to comply with applicable Philippine laws, including AMLA, PAGCOR regulations, and tax reporting requirements.
- Legitimate Interests: Processing for fraud prevention, platform security, and responsible gaming monitoring, where our legitimate interests are not overridden by your data protection rights.
- Consent: Processing for marketing communications and non-essential cookies, where you have provided explicit consent. You may withdraw consent at any time without affecting the lawfulness of prior processing.
6. Data Sharing and Disclosure
phluck does not sell, rent, or trade your personal data to third parties for their own marketing purposes. We may share your personal data with the following categories of recipients, strictly on a need-to-know basis:
- KYC and Identity Verification Providers: Third-party services that assist in verifying your identity and age as required by our compliance obligations.
- Payment Processors: GCash, PayMaya, BPI, BDO, Metrobank, and other payment service providers necessary to process your deposits and withdrawals.
- Game Providers: Third-party game studios whose games are hosted on the phluck platform may receive limited technical data necessary to deliver game services.
- Regulatory Authorities: PAGCOR, the Anti-Money Laundering Council (AMLC), the National Privacy Commission (NPC), and other Philippine government authorities, where disclosure is required by law or regulatory order.
- Law Enforcement: Philippine law enforcement agencies, where disclosure is required pursuant to a valid legal process, court order, or to protect the safety of our Members or the public.
- IT and Security Service Providers: Cloud hosting, cybersecurity, and fraud detection vendors who process data on our behalf under strict data processing agreements.
All third parties with whom phluck shares personal data are contractually required to implement appropriate technical and organizational security measures and to process data only for the specified purposes.
7. Cookies and Tracking Technologies
phluck uses cookies and similar tracking technologies to enhance your experience on our platform. Cookies are small text files stored on your device that help us recognize you, remember your preferences, and analyze platform usage.
We use the following types of cookies:
- Strictly Necessary Cookies: Essential for the platform to function. These cannot be disabled as they are required for login sessions, security, and basic functionality.
- Performance Cookies: Collect anonymized data about how visitors use the platform, helping us identify and fix performance issues.
- Functional Cookies: Remember your preferences such as language settings and display options.
- Analytics Cookies: Help us understand user behavior and improve the platform experience. These are only set with your consent.
You can manage your cookie preferences through your browser settings. Note that disabling certain cookies may affect the functionality of
the phluck platform.
8. Data Retention
phluck retains your personal data only for as long as necessary to fulfill the purposes for which it was collected, or as required by applicable Philippine law. The following retention periods apply:
- Account and Identity Data: Retained for the duration of your account and for a minimum of five (5) years following account closure, as required by AMLA and PAGCOR record-keeping obligations.
- Transaction and Financial Data: Retained for a minimum of five (5) years from the date of each transaction, in compliance with AMLA requirements.
- Gaming Activity Data: Retained for three (3) years following account closure, or longer if required for dispute resolution or regulatory purposes.
- Customer Support Records: Retained for two (2) years from the date of the last interaction.
- Marketing Consent Records: Retained until you withdraw consent, plus one (1) year thereafter as evidence of prior consent.
- Technical and Log Data: Retained for twelve (12) months from the date of collection.
Upon expiry of the applicable retention period, personal data is securely deleted or anonymized in accordance with our data disposal procedures.
9. Data Security
phluck implements industry-standard technical and organizational security measures to protect your personal data against unauthorized access, disclosure, alteration, or destruction. These measures include:
- 256-bit SSL/TLS encryption for all data transmitted between your device and our servers
- Encryption of sensitive data at rest, including financial information and identity documents
- Role-based access controls limiting employee access to personal data on a strict need-to-know basis
- Regular security audits, penetration testing, and vulnerability assessments
- Multi-factor authentication requirements for administrative access to systems containing personal data
- Incident response procedures for detecting, reporting, and managing personal data breaches
In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, phluck will notify the National Privacy Commission (NPC) within seventy-two (72) hours of becoming aware of the breach, and will notify affected Members without undue delay, as required by the Data Privacy Act of 2012.
While phluck takes all reasonable steps to protect your data, no online platform can guarantee absolute security. You are responsible for maintaining the confidentiality of your phluck login credentials and for notifying us immediately if you suspect unauthorized access to your account.
10. Your Data Privacy Rights
As a data subject under the Philippine Data Privacy Act of 2012, you have the following rights with respect to your personal data held by phluck:
- Right to Be Informed: The right to be informed of how your personal data is being collected and processed, as set out in this Policy.
- Right of Access: The right to request a copy of the personal data phluck holds about you, along with information about how it is being processed.
- Right to Rectification: The right to request correction of inaccurate or incomplete personal data. You may update most of your account information directly through your account settings.
- Right to Erasure: The right to request deletion of your personal data where it is no longer necessary for the purposes for which it was collected, subject to our legal retention obligations.
- Right to Object: The right to object to the processing of your personal data for direct marketing purposes or where processing is based on legitimate interests.
- Right to Data Portability: The right to receive your personal data in a structured, commonly used, and machine-readable format, and to transmit it to another data controller where technically feasible.
- Right to Lodge a Complaint: The right to lodge a complaint with the National Privacy Commission (NPC) if you believe your data privacy rights have been violated.
To exercise any of these rights, please contact our Data Protection Officer at [email protected]. We will respond to all verified requests within thirty (30) days. We may need to verify your identity before processing your request.
11. Children's Privacy
The phluck platform is strictly intended for individuals who are 21 years of age or older. phluck does not knowingly collect personal data from individuals under the age of 21. If we become aware that personal data has been collected from a person under 21, we will take immediate steps to delete that data and close the associated account.
If you are a parent or guardian and believe that your child has registered on phluck or provided us with personal data, please contact us immediately at [email protected] so that we can take appropriate action.
12. Changes to This Privacy Policy
phluck reserves the right to update or amend this Privacy Policy at any time to reflect changes in our data processing practices, applicable law, or regulatory requirements. When material changes are made, we will notify registered Members via email or a prominent notice on the platform at least seven (7) days before the changes take effect.
The "Last Updated" date at the top of this page indicates when the Policy was most recently revised. The current version of this Policy will always be available at phluck.one/privacy-policy. Your continued use of the phluck platform after the effective date of any amendment constitutes your acceptance of the revised Policy.
13. Contact Our Data Protection Officer
For any questions, concerns, or requests relating to this Privacy Policy or the processing of your personal data, please contact phluck's Data Protection Officer:
Role: Data Protection Officer, phluck
Email: [email protected]
Response Time: Within 30 days of verified request
Office: Manila & Cebu, Philippines