🔒 Your privacy matters. 27phfun processes your personal data in compliance with the Philippine Data Privacy Act of 2012 (RA 10173) and the regulations of the National Privacy Commission (NPC). By using the 27phfun Platform, you consent to the data practices described in this Policy.
1. About This Policy
This Privacy Policy ("Policy") applies to all personal data collected by 27phfun ("we", "us", "our") in connection with your use of the 27phfun website, mobile web application, and all related services (collectively, the "Platform"). It applies to registered players, visitors who browse without registering, and any individual who communicates with 27phfun through customer support channels.
This Policy should be read in conjunction with the 27phfun Terms & Conditions. Terms not defined herein have the meanings given to them in the Terms & Conditions. By creating a 27phfun account or accessing the Platform, you acknowledge that you have read and understood this Policy and consent to the data practices described herein.
2. Data We Collect
2.1 Registration Data
When you create a 27phfun account, we collect your full legal name, Philippine mobile number, email address, date of birth, and the password you set (stored in encrypted form only — we never store plain-text passwords).
2.2 Identity Verification (KYC) Data
To comply with PAGCOR regulations and the Anti-Money Laundering Act (AMLA), we may collect copies of government-issued identification documents (e.g., PhilSys ID, passport, driver's licence, UMID), proof-of-address documents, and, where required, source-of-funds documentation.
2.3 Financial Data
We record transaction data including deposit amounts, withdrawal amounts, payment method identifiers (e.g., GCash-linked mobile number, bank account last four digits), transaction timestamps, and wallet balance history. We do not store full credit or debit card numbers on our servers.
2.4 Gameplay Data
We collect records of all gaming activity on the Platform, including game type, bet amounts, outcomes, session duration, and timestamps. This data is required for regulatory reporting to PAGCOR and for the fair-play audit trail.
2.5 Technical & Device Data
We automatically collect IP address, browser type and version, device type and operating system, screen resolution, session identifiers, and referring URL when you access the Platform. This data is used for security monitoring, fraud detection, and Platform optimisation.
2.6 Communications Data
If you contact 27phfun customer support via live chat, email, or any other channel, we retain records of those communications for quality assurance, dispute resolution, and regulatory compliance purposes.
| Data Category | Examples | Primary Purpose |
|---|---|---|
| Registration | Name, mobile, email, DOB | Account creation & authentication |
| KYC / Identity | Gov't ID, proof of address | Regulatory compliance, AML |
| Financial | GCash number, transaction history | Payment processing, fraud prevention |
| Gameplay | Bets, outcomes, session logs | Fair play audit, PAGCOR reporting |
| Technical | IP address, browser, device | Security, fraud detection |
| Communications | Support chat transcripts | Dispute resolution, QA |
3. How We Use Your Data
27phfun uses the personal data we collect for the following purposes:
- Account management: Creating, maintaining, and securing your 27phfun account; authenticating your identity at login; enabling password resets and OTP verification;
- Payment processing: Facilitating deposits via GCash, Maya, BPI, BDO, Metrobank, GrabPay, QR Ph, and 7-Eleven CLiQQ; processing withdrawal requests; reconciling your PHP wallet balance;
- Regulatory compliance: Meeting PAGCOR licensing obligations; fulfilling Anti-Money Laundering Act (RA 9160) reporting requirements; responding to requests from law enforcement and regulatory authorities;
- Fraud prevention and security: Detecting and investigating suspicious login activity, unusual betting patterns, bonus abuse, multi-account creation, and money laundering signals;
- Platform improvement: Analysing aggregated, anonymised usage data to improve game selection, UI performance, and feature prioritisation;
- Responsible gaming: Monitoring play patterns to identify possible problem gambling indicators; enabling and enforcing deposit limits, session alerts, and self-exclusion requests;
- Customer support: Resolving inquiries, disputes, and technical issues submitted via live chat or email;
- Marketing communications: Sending promotional offers, bonus notifications, and platform updates to your registered email or mobile number — you may opt out at any time via Account Settings.
4. Legal Basis for Processing
27phfun processes your personal data on the following legal grounds under the Data Privacy Act of 2012 (RA 10173):
- Contractual necessity: Processing required to fulfil the agreement between you and 27phfun when you register an account and use the Platform (e.g., account creation, payment processing, gameplay records);
- Legal obligation: Processing required to comply with applicable Philippine laws, including PAGCOR regulations, AMLA, and orders from the National Privacy Commission;
- Legitimate interests: Processing for fraud prevention, security monitoring, and Platform improvement where such interests are not overridden by your privacy rights;
- Consent: Processing for direct marketing communications, where you have opted in or not opted out. You may withdraw consent at any time without affecting the lawfulness of prior processing.
5. Data Sharing & Disclosure
27phfun does not sell your personal data to third parties. We may share your data in the following circumstances:
- Payment processors: GCash (GXI), Maya (Voyager Innovations), GrabPay, InstaPay/PESONet operators, and partner banks receive transaction data strictly necessary to process your deposits and withdrawals;
- Game providers: Licensed game studios (e.g., Pragmatic Play, PG Soft, Jili Games) may receive session identifiers and bet data necessary to deliver game content and validate outcomes;
- Regulatory authorities: PAGCOR, the Anti-Money Laundering Council (AMLC), the National Privacy Commission, and other competent Philippine government bodies may receive your data as required by law;
- Service providers: Technology vendors providing hosting infrastructure, fraud detection, customer support software, and analytics services, all bound by data processing agreements requiring equivalent data protection standards;
- Legal proceedings: Courts, law enforcement agencies, or legal counsel where disclosure is required by a court order, subpoena, or applicable law.
All third-party recipients of your personal data are contractually required to handle it in accordance with applicable data protection laws and to use it only for the specific purpose for which it was shared.
6. Cookies & Tracking Technologies
27phfun uses cookies and similar tracking technologies (including local storage and session storage) on the Platform for the following purposes:
- Strictly necessary cookies: Required for Platform functionality, including maintaining your login session, remembering your language preference, and enabling secure transactions. These cannot be disabled without impairing Platform functionality;
- Performance cookies: Collect anonymised data on how players navigate the Platform to help us identify performance bottlenecks and improve user experience;
- Security cookies: Used to detect fraudulent login attempts, bot activity, and suspicious session behaviour.
You may configure your browser to reject or delete cookies. Note that disabling strictly necessary cookies will impair your ability to log in and use the Platform. 27phfun does not use third-party advertising cookies or cross-site behavioural tracking cookies.
7. Data Retention
27phfun retains your personal data for as long as your account is active and for such additional periods as are required by applicable law or regulatory obligation. Specific retention periods are as follows:
- Account and transaction records: Retained for a minimum of five (5) years from the date of the transaction, as required under the Anti-Money Laundering Act;
- KYC / identity verification documents: Retained for five (5) years from the date of collection or from the date of account closure, whichever is later;
- Gameplay logs: Retained for three (3) years from the date of the session for fair-play audit and dispute resolution purposes;
- Customer support communications: Retained for two (2) years from the date of the communication;
- Marketing consent records: Retained for the duration of your account plus one (1) year following account closure.
Upon expiry of the applicable retention period, personal data is securely deleted or irreversibly anonymised in accordance with NPC-recommended data disposal procedures.
8. Security Measures
27phfun implements a comprehensive set of technical and organisational security measures to protect your personal data against unauthorised access, disclosure, alteration, or destruction:
- All data transmissions between your browser and 27phfun servers are encrypted using TLS 1.3;
- Passwords are stored using bcrypt hashing with per-account salts — we cannot recover or view your password in plain text;
- Sensitive account changes (password reset, withdrawal request, email change) require OTP verification to your registered Philippine mobile number;
- Production databases containing personal data are encrypted at rest and accessible only to authorised personnel through access-controlled systems;
- 27phfun conducts periodic security assessments and maintains an internal incident response procedure for data breaches.
In the event of a personal data breach affecting your rights and freedoms, 27phfun will notify the National Privacy Commission within 72 hours of discovery and will notify affected players without undue delay, as required under RA 10173.
9. Your Rights Under RA 10173
As a data subject under the Philippine Data Privacy Act of 2012, you have the following rights with respect to your personal data held by 27phfun:
- Right to be informed: The right to know how your personal data is collected, used, stored, and shared — which this Policy fulfils;
- Right of access: The right to request a copy of the personal data 27phfun holds about you;
- Right to rectification: The right to correct inaccurate or incomplete personal data. Most data fields can be updated directly via Account Settings;
- Right to erasure: The right to request deletion of your personal data, subject to 27phfun's legal retention obligations under PAGCOR regulations and AMLA;
- Right to data portability: The right to receive your personal data in a structured, commonly used format;
- Right to object: The right to object to the processing of your data for direct marketing purposes or on grounds relating to your particular situation;
- Right to file a complaint: The right to lodge a complaint with the National Privacy Commission (NPC) if you believe your data protection rights have been violated.
To exercise any of these rights, contact 27phfun at [email protected]. We will respond within fifteen (15) business days.
10. Children & Minors
The 27phfun Platform is strictly for individuals who are at least 21 years of age, as required by PAGCOR regulations governing online gaming in the Philippines. 27phfun does not knowingly collect personal data from individuals under 21 years of age. If we become aware that a registered account belongs to a person under 21, we will immediately suspend the account, void any associated balances, and delete the personal data collected from that individual.
If you are a parent or guardian and believe that a minor has created a 27phfun account, please contact us immediately at [email protected].
11. Cross-Border Data Transfers
Some of 27phfun's service providers — including cloud infrastructure providers and game studios — may process or store data outside the Philippines. Where personal data is transferred outside the Philippines, 27phfun ensures that such transfers are subject to appropriate safeguards, including contractual data processing agreements that impose data protection standards equivalent to those required by RA 10173, consistent with NPC guidance on cross-border data transfers.
12. Changes to This Policy
27phfun reserves the right to update this Privacy Policy at any time. When material changes are made, we will publish the updated Policy on the Platform with a revised "Last Updated" date and notify registered players via their registered email address or through the Platform notification system. Your continued use of the Platform following the publication of an updated Policy constitutes your acceptance of the revised terms. If you do not agree with the updated Policy, you may request account closure by contacting customer support.
13. Contact Our Data Protection Officer
For any questions, concerns, or requests relating to this Privacy Policy or 27phfun's data practices, please contact our Data Protection Officer:
Email: [email protected]
Our DPO will acknowledge your inquiry within three (3) business days and provide a substantive response within fifteen (15) business days. For urgent account security matters — such as suspected unauthorised access — live chat support is available 24 hours a day, 7 days a week.
You also have the right to lodge a complaint directly with the National Privacy Commission of the Philippines if you believe your data protection rights have not been adequately addressed.