ditowin is committed to protecting the personal data of every Filipino player who uses our platform. This Privacy Policy explains exactly what information we collect, why we collect it, how we use it, who we share it with, and what rights you have under the Philippine Data Privacy Act of 2012 (Republic Act No. 10173).
These cards summarize our core data practices in plain language. They are not a substitute for the full Privacy Policy below, which governs in all circumstances.
ditowin collects only the personal data necessary to operate your account, verify your identity as required by PAGCOR and Philippine law, process your payments, and deliver customer support. We do not collect data speculatively or sell player data to third-party marketers.
All personal and financial data on ditowin is protected by 256-bit SSL encryption in transit and AES-256 encryption at rest. Access to player data is restricted to authorized ditowin staff with a legitimate operational need and is subject to strict internal access controls.
Under the Philippine Data Privacy Act, you have the right to access, correct, and request deletion of your personal data held by ditowin. You can also object to certain processing activities and request data portability. All such requests are handled within 15 business days.
ditowin shares player data only with: (1) PAGCOR and Philippine regulatory bodies as legally required; (2) payment processors (GCash, PayMaya, banks) to process your transactions; and (3) contracted game providers under strict data processing agreements. We never sell your data.
ditowin retains your account data for as long as your account is active and for the minimum statutory period required after closure under Philippine law (currently 5 years under AMLA regulations for financial records). Data not subject to retention obligations is deleted promptly upon account closure.
In the unlikely event of a personal data breach that poses a significant risk to your rights, ditowin will notify you and report the breach to the Philippine National Privacy Commission within 72 hours of becoming aware of it, as required under NPC Circular 16-03.
This Privacy Policy applies to all personal data collected and processed by ditowin in connection with the operation of the ditowin online casino and sports betting platform accessible at ditowin.app (the "Platform"). It applies to all registered players, visitors to the Platform, and any individual who interacts with ditowin's customer support channels.
ditowin acts as the Personal Information Controller (PIC) with respect to the personal data of its players and users, as defined under the Philippine Data Privacy Act of 2012 (Republic Act No. 10173) and its Implementing Rules and Regulations (IRR). This means ditowin is responsible for determining the purposes and means of processing your personal data and for ensuring that such processing complies with applicable Philippine data privacy laws.
ditowin collects the following categories of personal data from players and platform users. Collection is limited to data that is adequate, relevant, and not excessive relative to the stated processing purposes.
| Data Category | Specific Data Points | Collection Point |
|---|---|---|
| Identity Data | Full legal name, date of birth, gender, nationality | Account registration; KYC verification |
| Contact Data | Philippine mobile number, email address (optional) | Account registration |
| Government ID Data | PhilSys ID number, driver's license number, or passport number; ID document images | KYC verification process |
| Financial Data | GCash number, PayMaya number, bank account details (last 4 digits), transaction history, deposit and withdrawal records | Cashier / payment processing |
| Gaming Activity Data | Game session logs, bet history, win/loss records, bonus usage, responsible gaming limit settings | Platform usage (automated) |
| Technical Data | IP address, device type, operating system, browser type, session timestamps | Platform access (automated) |
| Communications Data | Live chat transcripts, support ticket content, SMS OTP logs | Customer support interactions |
| Responsible Gaming Data | Deposit limit settings, loss limit settings, session alerts, self-exclusion records | Responsible gaming tools |
ditowin does not collect sensitive personal information (as defined under Section 3(l) of the DPA) beyond what is strictly necessary for age verification and anti-money laundering compliance, and only with the explicit consent of the player where required.
ditowin collects personal data through the following mechanisms:
ditowin processes personal data only for specific, legitimate purposes with a lawful basis for each. The following table sets out our primary processing purposes and the applicable legal basis under the Philippine Data Privacy Act:
| Processing Purpose | Legal Basis (DPA s. 12 / s. 13) |
|---|---|
| Account creation and management | Performance of contract (s. 12(b)) |
| Age and identity verification (KYC) | Compliance with legal obligation (s. 12(c)); PAGCOR licensing requirement |
| Processing deposits and withdrawals in PHP | Performance of contract (s. 12(b)) |
| Anti-money laundering compliance (AMLA) | Compliance with legal obligation (s. 12(c)); RA 9160 as amended |
| Responsible gaming monitoring and limit enforcement | Legitimate interests (s. 12(f)); PAGCOR responsible gaming requirements |
| Fraud detection and platform security | Legitimate interests (s. 12(f)) |
| Customer support and dispute resolution | Performance of contract (s. 12(b)) |
| Platform improvement and game optimization | Legitimate interests (s. 12(f)); anonymized or aggregated data only |
| Marketing communications (opted-in players only) | Consent (s. 12(a)) |
| Regulatory reporting to PAGCOR and AMLC | Compliance with legal obligation (s. 12(c)) |
ditowin uses cookies and similar local storage technologies on the Platform for the following purposes:
ditowin does not use third-party advertising tracking cookies or behavioral advertising pixels. The Platform does not serve programmatic advertising, and no player behavioral data is shared with advertising networks.
Essential cookies cannot be disabled and are placed on the basis of contract performance. Analytics and security cookies are placed on the basis of ditowin's legitimate interests in operating a secure and well-functioning platform. Players who wish to disable non-essential cookies may do so through their browser settings; however, this may affect the performance of certain Platform features.
ditowin does not sell, rent, or trade player personal data to any third party. Personal data is shared only in the following limited circumstances:
Where ditowin shares player data with third-party game providers or technology partners whose operations or servers are located outside the Philippines, such transfers are conducted only under the following safeguards:
Players may request information about the specific safeguards in place for any cross-border transfers affecting their personal data by contacting ditowin's Data Protection Officer (see Section 15).
ditowin retains personal data for the minimum period necessary to fulfill the purposes for which it was collected, subject to the following minimum statutory retention obligations under Philippine law:
Upon expiry of the applicable retention period, personal data is securely deleted or anonymized so that it can no longer be associated with an individual player. Anonymized aggregate data may be retained indefinitely for platform analytics purposes.
ditowin implements technical and organizational security measures appropriate to the risk level associated with processing player personal data in the online gaming sector. Key measures include:
Under Republic Act No. 10173 (Data Privacy Act of 2012) and its Implementing Rules and Regulations, ditowin players who are Philippine citizens or residents have the following data subject rights with respect to their personal data:
You have the right to be informed of how your personal data is collected, used, retained, and disposed of. This Privacy Policy fulfills that obligation.
You may request a copy of the personal data ditowin holds about you, including the purpose of processing and the identity of third parties with whom it has been shared.
You may request correction of inaccurate or incomplete personal data held by ditowin. Corrections are subject to identity re-verification where the corrected data is used for KYC or AML compliance.
You may request deletion or blocking of personal data where it is no longer necessary for the original purpose, where consent has been withdrawn, or where processing is unlawful. Statutory retention obligations may limit this right.
You may object to the processing of your personal data for direct marketing purposes or processing carried out on the basis of legitimate interests, where ditowin cannot demonstrate a compelling legitimate ground that overrides your rights.
You may request a copy of the personal data you provided to ditowin in a structured, commonly used, machine-readable format, for transmission to another service provider where technically feasible.
If you believe ditowin has violated your data privacy rights, you may file a complaint with the Philippine National Privacy Commission (NPC) at privacy.gov.ph. You may also first raise the matter with ditowin's Data Protection Officer.
You are entitled to be indemnified for damages sustained due to inaccurate, incomplete, outdated, false, unlawfully obtained, or unauthorized use of your personal data, in accordance with Section 16(f) of the DPA.
ditowin does not knowingly collect personal data from individuals under 21 years of age. The Platform is strictly for adults who meet the PAGCOR-mandated minimum gambling age of 21 years. ditowin's account registration process includes a date-of-birth declaration and is backed by mandatory KYC age verification before real-money play is permitted.
If ditowin becomes aware that personal data has been collected from a minor, the affected account will be closed immediately, all personal data associated with the account will be securely deleted, and the matter will be reported to PAGCOR in accordance with the Platform's licensing obligations.
Parents and guardians who believe their child has registered an account on ditowin should contact ditowin support immediately via the 24/7 live chat for urgent account investigation and closure.
ditowin may send promotional communications — including bonus offers, new game announcements, and VIP program updates — to players who have opted in to receive such communications at registration or through their account settings.
You may withdraw consent to receive marketing communications at any time by: (a) updating your notification preferences in your ditowin account settings; or (b) requesting opt-out through the 24/7 live chat or by contacting [email protected]. Withdrawal of marketing consent does not affect the lawfulness of prior communications or ditowin's ability to send transactional communications (such as deposit confirmations, OTP messages, or account security alerts) that are necessary for the operation of your account.
The ditowin Platform may contain references to payment service providers and game providers that operate their own platforms and privacy policies. ditowin does not control the data practices of these third-party services and is not responsible for the content of their privacy policies. When interacting with a third-party service (such as accessing a GCash deposit interface or a third-party game lobby), you are subject to that service provider's own terms and privacy policy in addition to ditowin's policy.
ditowin reserves the right to update this Privacy Policy at any time to reflect changes in applicable Philippine law, NPC guidance, PAGCOR regulatory requirements, or ditowin's data processing practices. Material changes will be communicated to active players via in-platform notification or registered mobile number at least 14 days before taking effect.
The effective date of the current version of this Privacy Policy is displayed at the top of this page. Players are encouraged to review this Policy periodically. Continued use of the ditowin Platform following any update to this Policy constitutes acknowledgment of the updated terms.
Prior versions of this Privacy Policy are available upon request from ditowin's Data Protection Officer.
ditowin has designated a Data Protection Officer (DPO) as required under Section 21 of the Data Privacy Act of 2012. The DPO is responsible for overseeing ditowin's compliance with applicable data privacy laws and serves as the primary contact for data subject rights requests and privacy-related inquiries.
For complaints that cannot be resolved through ditowin's internal process, players may also contact the Philippine National Privacy Commission:
ditowin is PAGCOR-regulated and compliant with the Philippine Data Privacy Act. Play 1,200+ games in Philippine Peso — safely, securely, fairly.
21+ Only · PAGCOR Regulated · DPA Compliant