Your privacy matters to pilwin. This Policy explains what personal data pilwin collects from Filipino players, why it is collected, how it is used and protected, and what rights you have over your own information.
Six core points that summarize how pilwin handles your personal information. The complete legal text below is the binding document.
pilwin collects personal data you provide at registration (name, date of birth, mobile number, email), payment details for GCash and bank transfers, gameplay activity, and device/browser identifiers for security purposes.
Your data is used to operate your pilwin account, verify identity (KYC), process GCash and bank payments, detect fraud, comply with PAGCOR and AML regulations, and — only where you consent — to send you promotional offers.
All data is encrypted in transit using 256-bit SSL. Stored data is protected by access controls, encrypted databases, and regular security audits. pilwin's security framework aligns with Philippine data protection standards under RA 10173.
pilwin does not sell personal data. Data is shared only with payment processors (GCash, PayMaya, banks), licensed game providers, regulatory bodies as required by PAGCOR, and fraud prevention services under strict data processing agreements.
Under the Philippine Data Privacy Act (RA 10173), you have the right to access, correct, delete, object to processing, and port your personal data held by pilwin. Requests may be submitted to pilwin's Data Protection Officer at any time.
pilwin retains your account data for as long as your account is active and for a minimum of five years after closure, as required by Philippine AML and gaming regulations. Marketing data is retained only while consent remains active.
pilwin ("we," "us," or "our") is committed to protecting the privacy and personal data of all players and visitors who interact with the pilwin platform at pilwin.one. This Privacy Policy ("Policy") explains, in accordance with the Republic Act No. 10173, also known as the Philippine Data Privacy Act of 2012 ("DPA") and its Implementing Rules and Regulations, how we collect, use, store, disclose, and otherwise process personal data.
This Policy applies to all personal data collected by pilwin in connection with: the registration and operation of pilwin accounts; the use of pilwin's games, sports betting markets, and other Services; financial transactions including GCash deposits, PayMaya payments, and local bank transfers; and communications between players and pilwin's customer support team.
This Policy should be read in conjunction with pilwin's Terms & Conditions, which govern the overall contractual relationship between pilwin and its players. By accessing or using the pilwin platform, you acknowledge that you have read and understood this Privacy Policy and consent to the processing of your personal data as described herein.
pilwin acts as the data controller in respect of all personal data collected through the pilwin.one platform. As data controller, pilwin determines the purposes and means of processing your personal data and is responsible for ensuring that such processing is carried out lawfully, fairly, and transparently in accordance with the Philippine DPA.
pilwin has appointed a Data Protection Officer (DPO) as required under the Philippine Data Privacy Act. The DPO is responsible for overseeing pilwin's data protection compliance, handling data subject access requests, and serving as the primary point of contact for the National Privacy Commission (NPC) of the Philippines in respect of data protection matters.
Contact details for pilwin's Data Protection Officer are provided in Section 15 of this Policy. All data subject rights requests and privacy-related enquiries should be addressed directly to the DPO.
pilwin collects the following categories of personal data from players and platform visitors:
| Category | Examples | Collected When |
|---|---|---|
| Identity Data | Full legal name, date of birth, nationality, government ID number | Registration & KYC verification |
| Contact Data | Philippine mobile number (+63), email address, home address | Account registration |
| Financial Data | GCash account number, bank account details, transaction history, deposit and withdrawal records | Payment processing |
| Gaming Activity Data | Game history, wager amounts, win/loss records, session duration, bonus utilization | During platform use |
| Technical Data | IP address, device type, browser type and version, operating system, screen resolution | Automatically on access |
| KYC Documents | Copies of government-issued ID (UMID, passport, driver's license), selfie photos for identity matching | Prior to first withdrawal |
| Communications Data | Live chat transcripts, email correspondence with support, SMS messages sent by pilwin | During support interactions |
| Preference Data | Marketing preferences, communication language, favorite game categories, responsible gaming settings | Account settings & platform use |
pilwin may, in limited circumstances, process sensitive personal information as defined under the Philippine DPA, including government-issued identification numbers and financial account information. Such data is processed exclusively for the purposes of KYC verification, fraud prevention, and compliance with PAGCOR regulatory requirements and AML obligations. Sensitive personal information is subject to heightened security controls within pilwin's data infrastructure.
pilwin collects personal data through the following channels:
Under the Philippine DPA, pilwin must have a lawful basis for each processing activity involving your personal data. The following table sets out pilwin's primary processing purposes and the corresponding legal basis under the DPA:
| Purpose | Legal Basis |
|---|---|
| Account registration, maintenance, and closure | Contract performance |
| KYC identity and age verification | Legal obligation (PAGCOR regulations, RA 9160 AMLA) |
| Processing GCash, PayMaya, and bank deposits and withdrawals | Contract performance |
| Fraud detection and prevention | Legitimate interest / Legal obligation |
| Responsible gaming monitoring and self-exclusion management | Legal obligation (PAGCOR responsible gaming rules) |
| Customer support communication | Contract performance / Legitimate interest |
| Regulatory reporting to PAGCOR and other Philippine authorities | Legal obligation |
| Direct marketing (bonuses, promotions, SMS/email campaigns) | Consent (withdrawable at any time) |
| Platform analytics and product improvement | Legitimate interest |
| Security and access logging | Legitimate interest / Legal obligation |
pilwin does not sell, rent, or trade your personal data to any third party for their own commercial purposes. Personal data is shared only in the circumstances described in this Section and only to the extent strictly necessary for the stated purpose.
In the event of a merger, acquisition, or sale of all or substantially all of pilwin's assets, personal data held by pilwin may be transferred to the acquiring entity as part of that transaction. Affected players will be notified in advance of any such transfer and of any resulting change to this Privacy Policy.
pilwin's primary data infrastructure is located in facilities serving the Southeast Asia region. Some of pilwin's third-party service providers — including certain game software providers and cloud infrastructure partners — may process data in countries outside the Philippines.
Where personal data is transferred outside the Philippines, pilwin ensures that such transfers are made in compliance with the Philippine DPA, specifically the requirements relating to cross-border data flows under Section 21 and the NPC's implementing issuances. Safeguards employed include: binding contractual clauses requiring recipients to protect personal data to a standard equivalent to that required under Philippine law; and transfer only to jurisdictions recognized by the NPC as providing adequate protection.
Players may request details of the specific safeguards applicable to any cross-border transfer by contacting pilwin's Data Protection Officer.
pilwin retains personal data only for as long as is necessary for the purposes for which it was collected, or as required by applicable Philippine law and PAGCOR regulatory requirements. The following retention periods apply:
Upon expiry of applicable retention periods, personal data is securely deleted or irreversibly anonymized such that it can no longer be associated with any individual player.
Cookies are small text files placed on your device by websites you visit. The pilwin.one website uses cookies and similar technologies (including local storage and session tokens) to operate the platform, maintain your login session, remember your preferences, and collect aggregate analytics data.
On your first visit to pilwin.one, you will be presented with a cookie consent notice. You may manage your cookie preferences at any time through your browser settings. Disabling certain categories of cookies may affect the functionality of the pilwin platform. pilwin does not use third-party advertising or cross-site tracking cookies.
pilwin implements a comprehensive suite of technical and organizational security measures to protect personal data against unauthorized access, disclosure, alteration, destruction, or accidental loss. These measures include:
Under the Philippine Data Privacy Act of 2012 (RA 10173), you have the following rights with respect to your personal data held by pilwin. pilwin is committed to honoring these rights in a timely and transparent manner.
You have the right to be informed about how your personal data is collected, used, stored, and disclosed. This Privacy Policy fulfills pilwin's obligation to provide this information.
You may request a copy of all personal data that pilwin holds about you, including information on how it has been used and with whom it has been shared. Requests will be fulfilled within thirty (30) calendar days.
If any personal data pilwin holds about you is inaccurate or incomplete, you have the right to have it corrected. Some corrections may require re-submission of KYC documentation.
You may request deletion of your personal data where it is no longer necessary for the purpose for which it was collected, or where you withdraw consent. Note that certain data must be retained under Philippine law regardless of an erasure request — see Section 8.
You have the right to object to the processing of your personal data where pilwin relies on legitimate interest as the legal basis. You may also object at any time to the processing of your data for direct marketing purposes.
Where technically feasible, you may request that pilwin provide your personal data in a structured, commonly used, machine-readable format, or transmit it directly to another controller of your choice.
If you believe pilwin has not handled your personal data in accordance with the Philippine DPA, you have the right to lodge a complaint with the National Privacy Commission (NPC) of the Philippines. Details are available on the NPC's official website.
pilwin's age verification procedures — which require submission of a Philippine government-issued identification document showing date of birth — are specifically designed to prevent access by individuals under 21. These procedures are applied uniformly to all players prior to the processing of any withdrawal, and are conducted in compliance with PAGCOR's player protection requirements.
Where you have given your consent during account registration or subsequently updated your communication preferences, pilwin may send you promotional messages regarding bonuses, new games, sports betting markets, and other platform features. Marketing communications are delivered via SMS to your registered Philippine mobile number and/or email to your registered address.
You may withdraw consent to receive marketing communications at any time by:
Withdrawal of marketing consent will not affect the receipt of transactional communications that are necessary for the operation of your account, such as deposit confirmation messages, withdrawal status updates, OTP verification codes, and security alerts.
pilwin may update this Privacy Policy from time to time to reflect changes in applicable Philippine law, regulatory guidance from the National Privacy Commission, changes in pilwin's data processing activities, or improvements in pilwin's privacy practices. The effective date and last updated date at the top of this Policy will be amended accordingly upon each revision.
Where changes to this Policy are material — for example, changes to the categories of data collected, new purposes of processing, or changes to player rights — pilwin will notify registered players via SMS to their registered Philippine mobile number or email to their registered address, not less than fourteen (14) calendar days before the revised Policy takes effect.
Continued use of the pilwin platform following the publication of any revised Privacy Policy constitutes the player's acceptance of the revised terms. Players who do not accept the revised Policy should contact pilwin support to discuss account closure prior to the effective date.
For any questions, concerns, or requests relating to this Privacy Policy or pilwin's data processing activities, please contact pilwin's Data Protection Officer through the following channels:
For general customer support enquiries unrelated to data protection, please use the Live Chat function available 24/7 on the pilwin platform for the fastest response.
For complaints that cannot be resolved through pilwin's internal process, you may escalate the matter to the National Privacy Commission (NPC) of the Philippines. The NPC is the regulatory body responsible for administering and implementing the Data Privacy Act of 2012 in the Philippines.
pilwin is built on trust. 256-bit SSL encryption, strict KYC controls, PAGCOR-aligned compliance, and a dedicated Data Protection Officer — everything you need to play with peace of mind. 21+ only.
Registration confirms acceptance of pilwin's Terms & Conditions and this Privacy Policy. Play responsibly — Sumugal nang may responsibilidad. See Responsible Gaming.