Last Updated: June 2026 | Effective Date: June 2026
1. About This Policy
This Privacy Policy ("Policy") is issued by 21ph ("21ph," "we," "us," or "our") and describes how 21ph collects, uses, stores, discloses, and protects personal data obtained from players and visitors ("you," "your," or "data subject") who access or use the 21ph online gaming platform at https://21ph.asia ("Platform").
21ph is committed to protecting your personal data in accordance with Republic Act No. 10173, otherwise known as the Data Privacy Act of 2012 ("DPA"), its Implementing Rules and Regulations, and the issuances of the National Privacy Commission ("NPC") of the Philippines. By registering an account or using the Platform, you acknowledge that you have read and understood this Policy and consent to the processing of your personal data as described herein.
This Policy should be read together with our Terms & Conditions and Responsible Gaming Policy. In the event of any conflict between this Policy and the Terms & Conditions on matters of data privacy, this Policy shall prevail.
2. Personal Data We Collect
21ph collects the following categories of personal data from players and Platform visitors:
- Identity Data: Legal full name, date of birth, gender, nationality, and copies of government-issued identification documents (e.g., PhilSys National ID, UMID, Passport, Driver's License) submitted for KYC verification;
- Contact Data: Philippine mobile number, email address, and residential address;
- Account Data: Username, encrypted password, account preferences, communication preferences, and marketing opt-in status;
- Financial Data: GCash account number (masked), Maya account number (masked), bank account details provided for withdrawal processing, transaction history, deposit amounts, and withdrawal records. 21ph does not store full payment card numbers;
- Gaming Data: Game session history, bet amounts, wagering records, game results, bonus activity, and responsible gaming limit settings;
- Technical Data: IP address, device type, operating system, browser type and version, session tokens, and login timestamps;
- Communications Data: Records of your interactions with 21ph customer support, including live chat transcripts and any correspondence sent to our support email address.
Providing certain personal data — particularly Identity Data and Contact Data — is a mandatory condition of registering and maintaining a 21ph account. Failure to provide required data will prevent 21ph from completing KYC verification, which is a prerequisite for processing withdrawal requests.
3. How We Collect Your Data
21ph collects your personal data through the following methods:
- Direct collection: Data you provide when registering your 21ph account, completing KYC verification, making deposits or withdrawal requests, contacting customer support, or participating in promotions;
- Automated collection: Technical data collected automatically when you access or use the Platform, including through cookies, server logs, and similar tracking technologies (see Section 9);
- Third-party sources: Identity verification data from KYC service providers and fraud prevention agencies engaged by 21ph; payment data from GCash, Maya, and banking partners solely to the extent necessary to process transactions; and publicly available information used for fraud detection and anti-money laundering compliance purposes.
4. How We Use Your Personal Data
21ph uses the personal data it collects for the following purposes:
- To create, verify, and manage your 21ph account;
- To process deposits, withdrawals, and other financial transactions via GCash, Maya, and Philippine banking partners;
- To conduct mandatory KYC identity verification and comply with Anti-Money Laundering Council ("AMLC") reporting obligations under Republic Act No. 9160 (Anti-Money Laundering Act) and its amendments;
- To provide access to games and betting services offered on the Platform;
- To administer bonuses, promotions, and loyalty program benefits;
- To detect, investigate, and prevent fraudulent activity, bonus abuse, and prohibited conduct as defined in our Terms & Conditions;
- To provide customer support and resolve disputes or complaints;
- To monitor gaming activity for responsible gaming purposes, including enforcing deposit limits, loss limits, and self-exclusion requests;
- To send transactional communications — including account notifications, security alerts, and OTP verification messages — via SMS and email;
- To send marketing communications where you have provided consent or where permitted under applicable Philippine law;
- To improve the Platform's functionality, user experience, and game offering through anonymised analytics;
- To comply with all applicable Philippine laws, regulations, and regulatory directives.
5. Legal Basis for Processing
21ph processes your personal data on the following legal bases under the Data Privacy Act of 2012:
- Consent: Where you have provided express consent to processing, including for marketing communications. You may withdraw consent at any time without affecting the lawfulness of prior processing;
- Contractual necessity: Where processing is necessary to perform our obligations under the Terms & Conditions, including account management, payment processing, and game service delivery;
- Legal obligation: Where processing is required to comply with applicable Philippine laws and regulations, including AMLC reporting obligations and NPC directives;
- Legitimate interests: Where processing is necessary for the legitimate interests of 21ph, including fraud detection, security monitoring, and platform improvement, provided such interests do not override your fundamental rights and freedoms.
6. Data Sharing & Disclosure
21ph does not sell your personal data to any third party. 21ph may share your personal data with the following categories of recipients only to the extent strictly necessary:
- Payment processors: GCash (Mynt/Globe Fintech Innovations), Maya (Voyager Innovations), BPI, BDO, UnionBank, and other financial institutions — solely for the purpose of processing your deposit and withdrawal transactions;
- KYC and identity verification providers: Third-party identity verification services engaged to process government ID submissions and biometric checks as part of the KYC process;
- Gaming software providers: Game providers whose software is integrated on the 21ph Platform may receive limited session data necessary for game delivery and certification compliance;
- Regulatory authorities: The Anti-Money Laundering Council, National Privacy Commission, and other Philippine government authorities where disclosure is required by law, court order, or regulatory directive;
- Professional advisers: Legal, accounting, and auditing firms engaged by 21ph under professional confidentiality obligations.
All third parties with whom 21ph shares personal data are required to handle that data in accordance with applicable Philippine data privacy laws and contractual data processing obligations.
7. Data Retention
21ph retains personal data for as long as is necessary to fulfil the purposes for which it was collected, subject to the following retention principles:
- Active accounts: Personal data is retained for the duration of the account relationship;
- Closed accounts: Following account closure, 21ph retains personal data for a minimum of five (5) years to comply with AMLC record-keeping requirements under the Anti-Money Laundering Act;
- KYC documents: Identity verification documents are retained for the period required by applicable AMLC and gaming regulatory requirements;
- Self-excluded accounts: Records of self-exclusion requests are retained for the duration of the exclusion period and for a reasonable period thereafter to prevent inadvertent re-registration;
- Marketing data: Where processing is based solely on consent, data will be deleted promptly upon withdrawal of consent, subject to legal retention obligations.
8. Data Security
21ph implements comprehensive technical and organisational security measures to protect your personal data against unauthorised access, disclosure, alteration, or destruction. These measures include:
- 256-bit SSL/TLS encryption for all data transmitted between your device and the 21ph Platform;
- Hashed and salted password storage — your 21ph password is never stored in readable plain text;
- Two-factor authentication ("2FA") via SMS OTP, available and encouraged for all 21ph accounts;
- Real-time login monitoring with automated alerts for suspicious access patterns or logins from new devices;
- Access controls restricting internal access to personal data on a strict need-to-know basis;
- Regular security assessments and penetration testing of Platform infrastructure.
While 21ph employs industry-standard security measures, no online platform can guarantee absolute security. You are responsible for maintaining the confidentiality of your account credentials and for notifying 21ph immediately if you suspect unauthorised access to your account.
9. Cookies & Tracking Technologies
21ph uses cookies and similar tracking technologies to operate and improve the Platform. Cookies are small data files placed on your device when you access the Platform. 21ph uses the following categories of cookies:
- Strictly necessary cookies: Required for the Platform to function, including session management, login authentication, and security tokens. These cannot be disabled without preventing Platform access;
- Functional cookies: Remember your preferences such as language settings and responsible gaming limits;
- Analytics cookies: Collect anonymised data about how players interact with the Platform to help 21ph improve performance and user experience. 21ph uses only first-party analytics data and does not share raw analytics data with third-party advertising networks.
You may configure your browser to reject or delete cookies. Note that disabling strictly necessary cookies will impair Platform functionality, including the ability to log in to your 21ph account.
10. Your Data Subject Rights
As a data subject under the Data Privacy Act of 2012, you have the following rights in relation to your personal data held by 21ph:
- Right to be informed: The right to receive clear information about how your data is being processed, as provided in this Policy;
- Right of access: The right to request a copy of the personal data 21ph holds about you;
- Right to rectification: The right to request correction of inaccurate or incomplete personal data held in your 21ph account;
- Right to erasure: The right to request deletion of your personal data where processing is no longer necessary, subject to 21ph's legal retention obligations under AMLC and gaming regulations;
- Right to object: The right to object to processing based on legitimate interests, including the right to opt out of direct marketing communications at any time;
- Right to data portability: The right to receive your personal data in a commonly used, machine-readable format;
- Right to lodge a complaint: The right to lodge a complaint with the National Privacy Commission of the Philippines if you believe 21ph has breached your data privacy rights.
To exercise any of the above rights, please contact 21ph customer support via live chat. 21ph will respond to data rights requests within thirty (30) days of receipt, or within such shorter period as may be required by applicable NPC regulations.
11. Marketing Communications
21ph may send promotional communications — including bonus offers, new game announcements, and platform updates — to players who have consented to receive such communications. You may withdraw your consent to marketing communications at any time by contacting 21ph customer support via live chat or by updating your communication preferences in your account settings.
Withdrawal of marketing consent will not affect your access to the 21ph Platform or the processing of essential account and transactional communications, which are sent regardless of marketing preferences.
12. Children & Minors
The 21ph Platform is strictly intended for adults aged 21 years and above, consistent with PAGCOR regulations on online gambling in the Philippines. 21ph does not knowingly collect personal data from any person under the age of 21. If 21ph becomes aware that personal data has been submitted by a person under 21 years of age, the associated account will be suspended immediately and the personal data will be deleted subject to any applicable legal retention requirements.
If you are a parent or guardian and believe that a minor has registered on the 21ph Platform, please contact 21ph customer support immediately via live chat.
13. Changes to This Policy
21ph reserves the right to update or amend this Privacy Policy at any time to reflect changes in our data processing practices, applicable Philippine law, or regulatory requirements. When material changes are made to this Policy, 21ph will notify registered players via their registered email address or via an in-platform notification. The revised Policy will be effective from the date indicated at the top of this page.
Continued use of the 21ph Platform following notification of a revised Policy constitutes your acceptance of the updated terms. If you do not agree to the revised Policy, you should close your 21ph account and cease use of the Platform.
14. Contact & Data Privacy Officer
If you have questions, concerns, or requests relating to this Privacy Policy or the processing of your personal data by 21ph, please contact us through the following:
- Live Chat: Available 24/7 via the 21ph Platform — the fastest way to reach us for privacy-related matters
- Email: [email protected]
For formal data privacy complaints or requests that cannot be resolved through 21ph's internal process, you have the right to contact the National Privacy Commission of the Philippines directly. Information on how to file a complaint with the NPC is available on the NPC's official government website.