Last Updated: June 2026. This Privacy Policy applies to all users of the phmaya platform at phmaya.bio and supersedes all prior versions.
1. Overview
phmaya ("we," "us," "our," or "phmaya") operates the online gaming and sports betting platform accessible at phmaya.bio. We are the data controller responsible for the personal information you provide or that we collect when you access and use phmaya's Services. This Privacy Policy is issued in compliance with the Republic Act No. 10173, otherwise known as the Data Privacy Act of 2012 of the Philippines ("DPA"), its Implementing Rules and Regulations, and the issuances of the National Privacy Commission ("NPC").
This Privacy Policy describes how phmaya collects, uses, stores, shares, and protects personal data in connection with account registration, gaming activity, financial transactions, customer support interactions, and marketing communications. By creating a phmaya account or continuing to use our Services, you acknowledge that you have read and understood this Policy and that you consent to the processing of your personal data as described herein.
If you have questions or concerns about how phmaya handles your personal data, you may contact our Data Protection Officer at [email protected] at any time.
2. Personal Data We Collect
phmaya collects the following categories of personal data, depending on how you interact with our platform:
| Category | Examples | When Collected |
| Identity Data |
Full legal name, date of birth, government-issued ID number (e.g., PhilSys ID, passport, driver's licence) |
KYC verification, account registration |
| Contact Data |
Philippine mobile number, email address, city of residence (e.g., Manila, Cebu, Davao) |
Account registration, support requests |
| Financial Data |
GCash number, Maya account, bank account name and last four digits (BPI, BDO, Metrobank) |
Deposit and withdrawal processing |
| Transactional Data |
Deposit history, withdrawal history, game session records, bet amounts, bonus redemptions |
Ongoing gameplay and account activity |
| Technical Data |
IP address, device type and OS, browser type, session tokens, cookies |
Automatic collection during platform use |
| Usage Data |
Pages visited, games played, time on platform, click-through patterns |
Automatic collection during platform use |
| Communications Data |
Live chat transcripts, email correspondence, SMS OTP logs |
Customer support interactions |
We do not collect sensitive personal information (as defined under the DPA) beyond what is strictly necessary for identity verification and responsible gaming compliance.
3. How We Collect Your Data
phmaya collects personal data through the following means:
- Direct submission: When you register a phmaya account, complete KYC verification, submit a withdrawal request, contact support, or respond to a survey, you directly provide personal information to us.
- Automated technical collection: When you access phmaya.bio, our servers automatically log technical data such as your IP address, browser fingerprint, device identifiers, and session activity through cookies and similar tracking technologies.
- Third-party payment processors: When you transact via GCash, Maya, or bank channels, relevant transaction confirmation data (amount, timestamp, reference number) is shared with phmaya by our payment partners to reconcile your account balance.
- Game and sports data providers: Game result data and in-play event data generated during your phmaya sessions are recorded in our systems as part of the gaming audit trail required by our regulatory framework.
4. How phmaya Uses Your Personal Data
phmaya uses personal data for the following purposes:
- Account management: To register, verify, maintain, and secure your phmaya account, including OTP authentication and password recovery.
- Payment processing: To process deposits and withdrawals via GCash, PayMaya, BPI, BDO, and Metrobank, and to fulfil anti-money laundering (AML) obligations.
- Regulatory compliance: To comply with PAGCOR-aligned requirements, including KYC, AML screening, responsible gaming enforcement, and age verification (21+ requirement).
- Game delivery and personalisation: To operate game sessions, calculate and credit winnings, apply bonus terms, and personalise your phmaya lobby with relevant game recommendations.
- Responsible gaming: To enforce self-imposed deposit limits, session timers, and self-exclusion requests, and to identify patterns of gameplay that may indicate problem gambling.
- Customer support: To respond to your queries, resolve disputes, and maintain communication records as required by our complaints procedure.
- Security and fraud prevention: To detect, investigate, and prevent fraudulent activity, multi-accounting, bonus abuse, and unauthorised access to phmaya accounts.
- Marketing (with consent): To send promotional offers, bonus notifications, and platform updates via email or SMS where you have provided explicit consent. You may opt out at any time.
- Analytics and improvement: To understand how Filipino players use phmaya and to improve platform performance, game selection, and user experience.
5. Legal Basis for Processing
phmaya processes your personal data under the following lawful bases as recognised by the Data Privacy Act of 2012:
- Contractual necessity: Processing required to fulfil the Terms and Conditions you entered into when registering a phmaya account (account management, game delivery, payment processing).
- Legal obligation: Processing required to comply with Philippine law, PAGCOR licensing conditions, and AML regulations.
- Legitimate interest: Processing necessary for phmaya's legitimate interests in fraud prevention, platform security, and responsible gaming enforcement, balanced against your privacy rights.
- Consent: Processing for optional marketing communications, where your freely given, specific, and informed consent has been obtained. You may withdraw consent at any time without affecting prior lawful processing.
6. Data Sharing & Third Parties
phmaya does not sell, rent, or trade your personal data to any third party for their own marketing purposes. We share personal data only in the following circumstances:
- Payment processors: GCash, Maya, BPI, BDO, and Metrobank receive the minimum data necessary to process your financial transactions.
- Game providers: JILI and other certified game providers receive anonymised session data required to operate their game engines within the phmaya platform.
- Regulatory authorities: phmaya may disclose account and transaction records to PAGCOR, the NPC, the Anti-Money Laundering Council (AMLC), or other competent Philippine authorities when required by law or valid legal process.
- Identity verification providers: Third-party KYC and document verification services may process your identity documents on phmaya's behalf under strict data processing agreements.
- IT and hosting providers: Cloud infrastructure and security providers process data solely on our documented instructions and are contractually prohibited from using your data for any other purpose.
All third-party processors engaged by phmaya are bound by data processing agreements that comply with the DPA and impose equivalent data protection obligations.
7. Cookies & Tracking Technologies
phmaya uses cookies and similar technologies (pixel tags, local storage) on phmaya.bio to ensure platform functionality, maintain session security, and gather analytics. The categories of cookies we use are:
- Essential cookies: Required for login session management, account authentication, and basic platform functionality. These cannot be disabled without impairing core Services.
- Analytics cookies: Used to understand aggregate usage patterns on phmaya.bio and improve the platform experience. Data collected is anonymised at the earliest practicable point.
- Security cookies: Used to detect and prevent fraudulent activity, bot traffic, and unauthorised access attempts.
You may manage cookie preferences through your browser settings. Blocking essential cookies may affect your ability to log in and use phmaya's Services. phmaya does not use third-party advertising cookies or cross-site tracking technologies.
8. Data Retention
phmaya retains personal data for as long as your account is active and for the periods required by applicable law and our regulatory obligations:
- Account and identity records: Retained for a minimum of five (5) years following account closure, as required under Philippine AML regulations.
- Financial transaction records: Retained for a minimum of five (5) years from the date of each transaction.
- Game session records: Retained for three (3) years for regulatory audit purposes.
- Customer support records: Retained for two (2) years from the date of the last interaction.
- Marketing consent records: Retained for as long as you remain subscribed, plus three (3) years following opt-out to evidence prior consent.
After the applicable retention period expires, personal data is securely deleted or anonymised in accordance with phmaya's data lifecycle management procedures.
9. Data Security
phmaya implements appropriate technical and organisational security measures to protect your personal data against unauthorised access, accidental loss, destruction, or alteration. These measures include:
- TLS encryption for all data transmitted between your device and phmaya's servers.
- Bcrypt one-way hashing for account passwords — phmaya staff cannot view your password in plain text.
- SMS-based two-factor authentication for account login on new or unrecognised devices.
- Role-based access controls ensuring phmaya staff access personal data only on a strict need-to-know basis.
- Regular security audits and vulnerability assessments of the phmaya platform infrastructure.
- Segregated player fund accounts to ensure your balance is not commingled with phmaya's operational funds.
In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, phmaya will notify the National Privacy Commission and affected users within the timeframes prescribed by the DPA and NPC regulations.
10. Your Data Rights
Under the Data Privacy Act of 2012, you have the following rights with respect to your personal data held by phmaya:
- Right to be informed: The right to know what personal data phmaya collects, why, and how it is used — as set out in this Policy.
- Right of access: The right to request a copy of the personal data phmaya holds about you.
- Right to rectification: The right to correct inaccurate or incomplete personal data associated with your phmaya account.
- Right to erasure: The right to request deletion of your personal data where it is no longer necessary for the purpose for which it was collected, subject to phmaya's legal retention obligations.
- Right to object: The right to object to the processing of your personal data, including for direct marketing purposes. Opting out of marketing communications does not affect your ability to use phmaya's Services.
- Right to data portability: The right to receive a copy of your personal data in a structured, commonly used, machine-readable format where technically feasible.
- Right to lodge a complaint: The right to lodge a complaint with the National Privacy Commission (NPC) if you believe phmaya has processed your personal data in violation of the DPA.
To exercise any of the above rights, contact phmaya's Data Protection Officer at [email protected]. We will respond to all data subject requests within thirty (30) days.
11. Children & Minors
phmaya's Services are strictly intended for persons aged 21 years and older. phmaya does not knowingly collect personal data from individuals below the age of 21. Age verification is a mandatory step in the phmaya registration and KYC process. If phmaya becomes aware that personal data has been collected from a person below the minimum age requirement, such data will be deleted immediately and the associated account will be permanently closed.
If you are a parent or guardian and you believe that a minor in your care has registered a phmaya account, please contact us immediately at [email protected].
12. Changes to This Privacy Policy
phmaya reserves the right to update or amend this Privacy Policy at any time to reflect changes in our data practices, regulatory requirements, or platform features. Material changes will be communicated to registered users via their registered email address or via a prominent notice on the phmaya platform at least seven (7) days before the amended Policy takes effect. We encourage you to review this page periodically. Your continued use of phmaya's Services following the effective date of any update constitutes your acceptance of the revised Policy.
13. Contact Our Data Protection Officer
If you have any questions, requests, or complaints regarding this Privacy Policy or phmaya's data practices, please contact us through the following channels:
- Email: [email protected]
- Live Chat: Available 24/7 on the phmaya platform
- Languages: English and Filipino
All formal privacy requests and complaints will receive a substantive response within thirty (30) calendar days of receipt.
How phmaya Protects Your Privacy
Six commitments every phmaya player can count on
🔐
TLS Encryption
Every phmaya session and transaction is protected by industry-standard TLS encryption end-to-end.
🇵🇭
DPA-Compliant
phmaya's data practices are aligned with the Philippine Data Privacy Act of 2012 and NPC regulations.
🚫
No Data Selling
phmaya never sells or rents your personal data to third parties for their own commercial purposes.
🛡️
Hashed Passwords
Your phmaya password is stored as a one-way hash. No staff member can view it in plain text.
📋
Your Rights Protected
Access, correct, or delete your data. phmaya responds to all data subject requests within 30 days.
💬
24/7 DPO Access
Contact phmaya's Data Protection Officer anytime via live chat or email — in English or Filipino.
Your Privacy Is Safe With phmaya
Play on a platform that respects your data as much as you enjoy your games. Fast GCash payouts, fair play, and DPA-compliant privacy practices — that's the phmaya promise.
21+ only. For entertainment purposes only. Please gamble responsibly.