Data Privacy & Security

goldph Privacy Policy

Your privacy is not an afterthought at goldph — it's a core design principle. This Privacy Policy explains exactly what personal data we collect, why we collect it, how we use and protect it, and what rights you have over your own information as a Philippine player on the goldph Platform.

Effective Date: 1 January 2026
Jurisdiction: Philippines
RA 10173 Compliant
PAGCOR Regulated

goldph Privacy Commitment: goldph respects the privacy of every Filipino player who uses our platform. This Privacy Policy is issued in compliance with Republic Act No. 10173, the Data Privacy Act of 2012 (DPA), and its Implementing Rules and Regulations, as enforced by the National Privacy Commission (NPC) of the Philippines. goldph is also subject to PAGCOR's data handling requirements applicable to licensed gaming operators. By registering a goldph Account or using the goldph Platform, you acknowledge that you have read and understood this Privacy Policy and consent to the collection and processing of your personal data as described herein.

1

Overview & Scope

1.1 This Privacy Policy applies to all personal data collected, stored, processed, and used by goldph in connection with the operation of the goldph Platform at goldph.org, including all related services, Account management functions, payment processing, and customer support interactions.

1.2 This Policy applies to all individuals who interact with goldph in any of the following capacities: registered Players holding a goldph Account; visitors browsing the goldph Platform without registering; and individuals who contact goldph through support channels without being registered Players.

1.3 This Policy does not govern the privacy practices of third-party payment processors, game software providers, or any other external service providers whose own privacy policies govern the handling of any data you provide directly to those parties. goldph is not responsible for the data practices of any third-party service whose platform, website, or application you may access in connection with your use of the goldph Platform.

1.4 This Privacy Policy should be read alongside the goldph Terms & Conditions, which govern the overall contractual relationship between goldph and registered Players.

2

Data Controller

2.1 For the purposes of the Data Privacy Act of 2012, goldph acts as the Personal Information Controller (PIC) in respect of personal data collected through the goldph Platform. goldph determines the purposes and means of processing personal data described in this Policy.

2.2 goldph has designated a Data Protection Officer (DPO) responsible for overseeing compliance with the Data Privacy Act of 2012 and this Privacy Policy. The DPO may be contacted via the details set out in Section 15 of this Policy.

2.3 goldph has registered its data processing systems with the National Privacy Commission in compliance with NPC registration requirements applicable to personal information controllers of a significant scale of data processing.

3

Personal Data We Collect

3.1 goldph collects the following categories of personal data from registered Players and Platform visitors. Collection of each category is proportionate to the purpose for which it is processed, consistent with the principle of proportionality under the Data Privacy Act of 2012:

Data Category Specific Data Points When Collected
Identity Data Full legal name, date of birth, gender, nationality, government-issued ID type and number Registration and KYC verification
Contact Data Email address, Philippine mobile number, residential address Registration and KYC
Financial Data GCash account reference, Maya account reference, bank account details for withdrawals, deposit and withdrawal history Payment processing
Gaming Activity Data Bet history, game results, session duration, bonus usage, wagering patterns During gameplay and session activity
Technical Data IP address, device type, browser version, operating system, session timestamps Platform access
Communications Data Live chat transcripts, support ticket content, email correspondence Customer support interactions
KYC Documentation Scanned copies or photographs of government-issued Philippine ID documents submitted for identity verification KYC verification process
Usage & Preference Data Favourite games, marketing preferences, notification settings, responsible gaming limit configurations Ongoing platform use

goldph does not collect biometric data (such as facial recognition or fingerprint data) as part of its standard identity verification process. KYC is conducted through document review only. goldph does not collect sensitive personal information as defined under Section 3(l) of the Data Privacy Act of 2012 except where required to comply with AML obligations (source of funds inquiries).

4

How We Collect Your Data

4.1 goldph collects personal data through the following means:

  • Direct Collection: Information you provide directly when registering a goldph Account, completing KYC verification, making deposits or withdrawal requests, contacting goldph support, or responding to surveys or promotions.
  • Automated Technical Collection: Technical data (IP address, device information, browser data, session timestamps) collected automatically when you access the goldph Platform through server logs, analytics systems, and security monitoring tools.
  • Payment Processor Data: Transaction reference data and payment status information received from goldph's payment processing partners (GCash, Maya, InstaPay network participants, and banking partners) in connection with deposit and withdrawal processing.
  • Game Platform Data: Game session data, bet history, and results data generated by goldph's game software providers and returned to goldph's systems in connection with your gameplay activity.
  • Cookies and Tracking Technologies: Data collected through cookies and similar technologies as described in Section 9 of this Policy.
  • Third-Party Verification Services: Identity verification data returned by third-party KYC verification service providers used by goldph to validate government-issued Philippine ID documents.
5

Purpose & Legal Basis for Processing

5.1 goldph processes personal data only for specified, legitimate purposes. The following table summarises the primary purposes for which goldph processes your personal data and the legal basis for each under the Data Privacy Act of 2012:

Processing Purpose Legal Basis (DPA 2012)
Account registration and management Contractual necessity (Sec. 12[b])
Identity and age verification (KYC — 21+ enforcement) Legal obligation (Sec. 12[c]) — PAGCOR / AML regulations
Processing deposits and withdrawals Contractual necessity (Sec. 12[b])
Preventing fraud, money laundering, and prohibited conduct Legal obligation (Sec. 12[c]) — RA 9160 as amended (AMLA)
Providing customer support Contractual necessity (Sec. 12[b])
Responsible gaming monitoring and player protection Legal obligation (Sec. 12[c]) — PAGCOR RG requirements
Sending promotional communications (with opt-in consent) Consent (Sec. 12[a])
Platform security, fraud detection, and abuse prevention Legitimate interests (Sec. 12[f])
Compliance with regulatory reporting obligations Legal obligation (Sec. 12[c]) — PAGCOR / NPC / AMLC reporting
Analytics and Platform improvement Legitimate interests (Sec. 12[f]) — anonymised/aggregated only

5.2 goldph will not use your personal data for any purpose materially incompatible with the purposes listed above without obtaining your express prior consent, except where further processing is required to comply with a legal obligation.

6

Data Sharing & Disclosure

6.1 goldph does not sell, rent, or commercially trade your personal data to any third party. Disclosure of your personal data is limited to the following categories of recipients and circumstances:

  • Payment Service Providers: GCash, Maya, GrabPay, BPI, BDO, Metrobank, and InstaPay network participants receive the minimum personal and financial data required to process your deposit or withdrawal transactions. Each provider operates under its own privacy policy and Philippine financial regulations.
  • Game Software Providers: goldph's certified game software partners receive session identifiers and bet data necessary to operate games and return results. These providers do not receive your full identity data unless required for their own regulatory compliance.
  • KYC Verification Services: Third-party identity verification providers receive copies of your submitted government ID documents solely for the purpose of verifying your identity. These providers are contractually bound to handle your data securely and solely for verification purposes.
  • Regulatory Authorities: goldph is legally required to disclose certain player data to PAGCOR, the Anti-Money Laundering Council (AMLC), the National Privacy Commission, and other Philippine governmental authorities pursuant to legal obligations under applicable law. Such disclosures are made without prior notice to the Player where legally required.
  • Law Enforcement: goldph may disclose personal data to Philippine law enforcement agencies in response to valid legal process, court orders, or where disclosure is necessary to prevent an imminent risk of harm.
  • Professional Advisers: goldph's legal, financial, and compliance advisers may access personal data where necessary to provide professional services, subject to professional confidentiality obligations.

goldph is subject to mandatory suspicious transaction reporting obligations under the Anti-Money Laundering Act of the Philippines (RA 9160, as amended). Transactions and player data may be reported to the AMLC without player notification where required by law. This obligation overrides any otherwise applicable data privacy considerations.

7

International Data Transfers

7.1 goldph's primary data processing infrastructure is located within the Philippines. However, certain service providers engaged by goldph — including game software platforms and cloud infrastructure providers — may process data in servers located outside the Philippines.

7.2 Where personal data is transferred outside the Philippines, goldph ensures that such transfers are conducted in accordance with Section 21 of the Data Privacy Act of 2012 and applicable NPC regulations, including through the use of appropriate contractual safeguards (such as data processing agreements incorporating data protection clauses) to ensure that transferred data receives a standard of protection equivalent to that afforded under Philippine law.

7.3 By using the goldph Platform, you acknowledge and consent to the cross-border transfer of your data to the extent necessary for goldph to provide its services, subject to the safeguards described in this Section.

8

Data Retention

8.1 goldph retains personal data for the period necessary to fulfil the purposes for which it was collected, as described in this Policy, and to comply with applicable legal retention obligations. The following retention schedule applies:

  • Account and Identity Data: Retained for the duration of the active Account relationship and for a minimum of five (5) years following Account closure, consistent with PAGCOR record-keeping requirements and AML retention obligations under RA 9160.
  • Financial and Transaction Data: Retained for a minimum of five (5) years from the date of the transaction, as required under Philippine AML regulations and tax record-keeping requirements.
  • KYC Documentation: Retained for a minimum of five (5) years following Account closure or the date of the most recent transaction, whichever is later.
  • Gaming Activity Data: Retained for a minimum of three (3) years from the date of the gaming session, and longer where required for responsible gaming monitoring or dispute resolution.
  • Technical and Log Data: Retained for up to twelve (12) months in standard logs and up to five (5) years in security and fraud monitoring archives.
  • Marketing Preference Data: Retained until you withdraw consent for marketing communications, at which point your preferences are updated and marketing is ceased promptly.

8.2 At the end of applicable retention periods, personal data is securely deleted or anonymised in a manner that prevents reconstruction of the original personal information, in accordance with NPC guidelines on data disposal.

9

Cookies & Tracking Technologies

9.1 The goldph Platform uses cookies and similar tracking technologies to provide essential functionality, maintain your login session, and support security and fraud prevention. The following categories of cookies are used:

  • Strictly Necessary Cookies: Essential for the goldph Platform to function. These include session authentication cookies, security tokens, and load-balancing cookies. These cannot be disabled without rendering the Platform inoperable. No consent is required for strictly necessary cookies under applicable law.
  • Functional Cookies: Remember your preferences (such as language settings and notification preferences) to provide a personalised experience. These are set with your implicit consent through continued Platform use.
  • Analytics Cookies: Used to collect aggregated, anonymised data about how Players use the goldph Platform — which pages are visited, how long sessions last, and which features are used. This data is used to improve Platform performance and user experience. Analytics cookies are set only with your consent.
  • Security and Fraud Prevention Cookies: Used to detect unusual access patterns, prevent automated attacks, and identify potentially fraudulent sessions. These are operationally necessary for the security of the goldph Platform and Player Accounts.

9.2 Most web browsers allow you to control cookies through browser settings. Disabling cookies beyond strictly necessary cookies may affect the functionality of the goldph Platform, including your ability to maintain a login session.

9.3 goldph does not use third-party behavioural advertising cookies or cross-site tracking technologies that profile your browsing activity outside the goldph Platform.

10

Security Measures

10.1 goldph implements a layered security framework to protect personal data against unauthorised access, disclosure, alteration, and destruction. Key security measures include:

  • Encryption in Transit: All data transmitted between your device and goldph servers is encrypted using TLS 1.2 or higher (256-bit SSL). This applies to all login sessions, payment transactions, and any other data exchange on the goldph Platform.
  • Encryption at Rest: Sensitive personal data stored in goldph's databases — including identity information and financial data — is encrypted at rest using industry-standard encryption protocols.
  • Password Security: goldph stores Player passwords using one-way cryptographic hashing with salting. goldph staff cannot read any Player's actual password.
  • Access Controls: Access to personal data within goldph's systems is restricted on a need-to-know basis using role-based access controls. All internal access to personal data is logged and audited.
  • Two-Factor Authentication (2FA): goldph offers 2FA to all registered Players, adding a second verification layer (SMS OTP to your registered Philippine mobile number) to the login process.
  • Penetration Testing: goldph's security infrastructure undergoes periodic third-party penetration testing to identify and remediate vulnerabilities.
  • Incident Response: goldph maintains a data breach response procedure in compliance with NPC Circular 16-03 on Security Incident Notification, including notification to the NPC and affected Players within the timeframes prescribed by applicable regulations.

While goldph implements robust security measures, no system is entirely immune to security risks. You also play an important role in securing your account — using a strong unique password, enabling 2FA, and never sharing your goldph credentials with anyone are essential steps that only you can take.

11

Your Rights Under the Data Privacy Act of 2012

11.1 As a data subject under Republic Act No. 10173, you have the following rights with respect to your personal data held by goldph. goldph is committed to facilitating the exercise of these rights in a timely and transparent manner:

Right to Be Informed

You have the right to be informed about how your personal data is being collected and processed — which this Policy fulfils.

Right to Access

You may request a copy of the personal data goldph holds about you at any time, together with information about how it is used.

Right to Rectification

You may request correction of inaccurate or incomplete personal data held by goldph. Some corrections require re-verification.

Right to Erasure

You may request deletion of your personal data where it is no longer necessary for the purpose it was collected, subject to legal retention obligations.

Right to Object

You may object to certain processing activities, including direct marketing communications. Objection to essential processing may require Account closure.

Right to Data Portability

You may request a structured, machine-readable copy of personal data you have provided to goldph for portability purposes.

Right to Withdraw Consent

Where processing is based on your consent (such as marketing communications), you may withdraw consent at any time through your Account settings.

Right to Complain

You have the right to lodge a complaint with the National Privacy Commission (NPC) of the Philippines if you believe goldph has mishandled your data.

11.2 To exercise any of the above rights, please contact the goldph Data Protection Officer using the contact details in Section 15. goldph will respond to your request within the timeframe prescribed by applicable NPC regulations — generally within 30 calendar days. We may request identity verification before processing your request to ensure we do not disclose or modify your data in response to an unauthorised request.

11.3 Certain rights — particularly erasure — are subject to overriding legal obligations. goldph cannot delete personal data that is required to be retained under PAGCOR regulations, AML law, or other applicable Philippine legal requirements, even upon your request.

12

Children, Minors & the 21+ Requirement

12.1 The goldph Platform is strictly intended for adults 21 years of age and older in accordance with Philippine gaming regulations enforced by PAGCOR. goldph does not knowingly collect personal data from individuals under 21 years of age.

12.2 goldph enforces age verification through KYC processes at the Account registration stage. Any Account found to belong to a person under 21 years of age will be immediately closed, and any personal data collected in connection with such Account will be securely deleted, except where retention is required for fraud prevention, AML compliance, or regulatory reporting purposes.

12.3 If you have reason to believe that a minor has registered a goldph Account using false age information, please contact the goldph Data Protection Officer immediately at the contact details in Section 15. goldph will investigate and take appropriate action promptly.

goldph takes the 21+ age restriction seriously as both a legal requirement and a responsible gaming obligation. Parents and guardians who suspect that a minor has accessed the goldph Platform should contact goldph support immediately. Parental controls on devices and home internet connections are also recommended as an additional safeguard.

13

Third-Party Links & Services

13.1 The goldph Platform may contain references to payment providers and game software platforms operated by third parties. Interactions with these services — such as initiating a GCash payment or launching a game powered by a third-party software provider — involve data exchanges governed by those providers' own privacy policies, which are separate from and independent of this goldph Privacy Policy.

13.2 goldph is not responsible for the data handling practices of any third-party service provider. goldph recommends that you review the privacy policies of any third-party service you interact with in connection with your use of the goldph Platform.

13.3 goldph does not operate social media plug-ins or embedded social sharing features on the goldph Platform that would result in your social media account data being shared with goldph without your explicit action.

14

Amendments to This Privacy Policy

14.1 goldph may update this Privacy Policy from time to time to reflect changes in applicable Philippine law, NPC guidance, PAGCOR requirements, or goldph's data processing practices. The most current version will always be published at goldph.org/privacy-policy, with the effective date prominently displayed.

14.2 Where amendments are material — meaning they significantly affect the manner in which goldph processes your personal data or your rights in relation to that data — goldph will provide advance notice via the email address registered to your Account, with a minimum of 14 calendar days' notice prior to the effective date, except where immediate amendment is required by law or regulatory direction.

14.3 Continued use of the goldph Platform following the effective date of any amendment to this Privacy Policy constitutes your acknowledgment of the updated Policy. If you do not agree with an amendment, you should discontinue use of the goldph Platform and may request Account closure in accordance with the goldph Terms & Conditions.

15

Contact & Data Protection Officer

15.1 For any questions, concerns, or requests relating to this Privacy Policy or the handling of your personal data by goldph — including requests to exercise your rights under the Data Privacy Act of 2012 — please contact the goldph Data Protection Officer using the following details:

  • Data Protection Officer: goldph DPO
  • Email (plain text — not clickable): [email protected] — please mark the subject line "Data Privacy Request" for fastest routing to the DPO team
  • Correspondence: goldph, Philippines
  • Live Chat: Available 24/7 through the goldph Platform after logging in to your Account

15.2 goldph will acknowledge your data privacy request within 5 business days and will endeavour to resolve it within 30 calendar days of receipt. Complex requests may require additional time, in which case goldph will notify you of the extended timeline.

15.3 If you are not satisfied with goldph's response to your data privacy concern, you have the right to file a complaint with the National Privacy Commission of the Philippines (NPC) through the official NPC complaint mechanisms. goldph supports your right to seek independent regulatory review of any data privacy concern.

This Privacy Policy was last reviewed and updated on 1 January 2026. goldph is committed to transparent, compliant, and player-protective data practices that meet the full requirements of the Philippine Data Privacy Act of 2012 and PAGCOR regulatory standards.

goldph's Commitment to Your Privacy

Beyond the legal language, here's what data privacy actually means in practice for every Filipino player on the goldph Platform.

We Never Sell Your Data

goldph does not sell, rent, or commercially trade your personal information to any third party, ever. Your data is used only to operate your goldph Account and comply with Philippine regulatory obligations — nothing else.

256-Bit SSL on Everything

Every connection between your device and the goldph Platform is encrypted to the same standard used by Philippine banks and GCash. Your login, your deposits, your support chats — all encrypted end-to-end.

RA 10173 Compliant

goldph's data practices are designed to meet the full requirements of the Philippine Data Privacy Act of 2012 and the NPC's Implementing Rules and Regulations. We have a registered DPO and NPC-compliant data processing systems.

Your Rights, Fully Supported

goldph supports all eight data subject rights under the Data Privacy Act — access, rectification, erasure, objection, portability, and more. Submit a request to the goldph DPO and we'll respond within 30 days.

Minimal Data Collection

goldph collects only the personal data that is genuinely necessary to operate your Account, process payments, comply with PAGCOR and AML regulations, and keep the platform secure. We don't collect data we don't need.

Breach Notification Ready

goldph maintains a tested data breach response procedure in compliance with NPC Circular 16-03. In the unlikely event of a breach affecting your data, we will notify you and the NPC within the timeframes prescribed by Philippine law.

🇵🇭
Philippine Law First

goldph complies with the Data Privacy Act of 2012, PAGCOR regulations, and the Anti-Money Laundering Act — the full stack of Philippine laws that govern how your data is handled.

🔐
Security Without Compromise

Multiple layers of technical and organisational security protect your goldph Account and personal data — from encrypted databases to role-based access controls and regular security audits.

💬
Always Accessible DPO

The goldph Data Protection Officer is reachable via live chat 24/7 and by email. Data privacy requests are acknowledged within 5 business days and resolved within 30 days.

Know Your Rights. Play with Confidence.

Understanding how goldph handles your personal data is part of being an informed player. If you have questions about your privacy rights or want to explore what goldph offers, our support team and full platform are available 24/7.