openph is committed to protecting your personal data. This Privacy Policy explains what information we collect, why we collect it, how we use and protect it, and what rights you have over your data under Philippine law.
A plain-English overview of how openph approaches data privacy. The complete legal text appears below — this summary does not replace it.
openph processes personal data in strict compliance with Republic Act 10173, the Data Privacy Act of 2012, and its implementing rules and regulations. Our data processing activities are registered with the National Privacy Commission (NPC) of the Philippines, as required under applicable regulations.
All personal data transmitted between your device and the openph Platform is protected by 256-bit SSL/TLS encryption. Sensitive data including passwords and payment details are stored using industry-standard encryption and hashing practices. openph does not store full payment card numbers on its servers — payment processing is handled by certified third-party payment processors.
openph does not sell, rent, or trade your personal data to third parties for their own marketing or commercial purposes. Your data is shared only with service providers and partners necessary for operating the Platform and complying with legal obligations — always under contractual data protection obligations.
openph collects only the personal data that is necessary for the specific, legitimate purposes described in this Privacy Policy. We do not use your data for purposes incompatible with those for which it was originally collected, and we do not retain data longer than necessary to fulfill those purposes or comply with applicable legal retention requirements.
Under the Philippine Data Privacy Act, you have the right to access your personal data, correct inaccuracies, object to certain processing, request erasure in applicable circumstances, and data portability. openph has established processes to honor these rights. Requests can be submitted to our designated Data Protection Officer at [email protected].
As a PAGCOR-licensed operator, openph is legally required to collect and process certain personal data for identity verification (KYC), anti-money laundering compliance (AMLC), and regulatory reporting. These obligations exist independently of your consent and are governed by mandatory provisions of Philippine gaming, anti-money laundering, and financial regulation law.
The Data Privacy Act of 2012 (RA 10173) grants Philippine residents specific rights over their personal data. Here is how openph honors each right.
You may request a copy of the personal data openph holds about you, including information on how it is being used, with whom it has been shared, and for how long it will be retained.
If any personal data openph holds about you is inaccurate or incomplete, you have the right to request correction. Minor corrections (email, phone number) can be made directly through Account Settings.
You may request deletion of your personal data where it is no longer necessary for its original purpose, subject to openph's legal obligations to retain data under PAGCOR and AMLC regulations.
You have the right to object to processing of your personal data for direct marketing purposes. You may opt out of marketing communications at any time through Account Settings or by contacting our Data Protection Officer.
You may request your personal data in a structured, commonly used, machine-readable format where technically feasible, allowing you to transfer it to another data controller.
In certain circumstances you may request that openph restricts the processing of your data — for example, while a dispute about accuracy is being resolved — without requiring full erasure.
You have the right to be informed about how your personal data is processed, on what legal basis, for what purposes, and with whom it is shared. This Privacy Policy serves as openph's primary instrument for fulfilling this right.
If you believe openph has violated your data privacy rights, you may file a complaint with the National Privacy Commission (NPC) of the Philippines, the regulatory body responsible for enforcing the Data Privacy Act.
⚠️ Important Notice: This Privacy Policy applies to all personal data collected and processed by openph in connection with the openph.org Platform and related services. By registering an openph Account or continuing to use the Platform, you acknowledge that you have read and understood this Privacy Policy. Please read it carefully alongside the openph Terms & Conditions and Responsible Gaming Policy.
openph ("the Company," "we," "us," "our") values the privacy of every Filipino player who uses the openph Platform. This Privacy Policy describes how openph collects, uses, discloses, stores, and protects personal data in connection with the operation of the online gaming platform accessible at openph.org.
This Privacy Policy applies to:
This Privacy Policy does not apply to third-party websites, applications, or services that may be linked from or accessible through the openph Platform. openph is not responsible for the data privacy practices of third parties.
This Privacy Policy is written in English in accordance with the openph Terms & Conditions. In the event of any conflict between the English version and any translation, the English version shall prevail.
For the purposes of the Philippine Data Privacy Act of 2012 (Republic Act 10173) and its Implementing Rules and Regulations, openph acts as the Data Controller in respect of personal data collected through the Platform.
openph has appointed a Data Protection Officer (DPO) responsible for overseeing compliance with this Privacy Policy and applicable data protection law. The DPO may be contacted at:
📧 Data Protection Officer — openph
Email: [email protected] (Subject: "Data Privacy — DPO Request")
Postal: openph Data Protection Officer, Metro Manila, Philippines
Response Time: Within ten (10) business days of verified request receipt
openph's data processing activities are registered with the National Privacy Commission (NPC) of the Philippines as required under applicable regulations. The NPC may be contacted at the official government website of the National Privacy Commission should you wish to file a complaint.
When you create an openph Account, we collect the following categories of personal data:
To comply with PAGCOR licensing requirements and Anti-Money Laundering Council (AMLC) obligations, openph collects:
openph collects records of all financial transactions associated with your Account, including:
openph does not store full payment card numbers. Card payment processing is handled by certified third-party payment processors who are independently PCI-DSS compliant. GCash and Maya transaction data is processed through their respective APIs under the terms of openph's agreements with those payment providers.
openph collects personal data through the following channels:
openph processes your personal data on the following legal bases under the Data Privacy Act of 2012 (RA 10173):
| Purpose of Processing | Legal Basis |
|---|---|
| Account registration and management | Performance of contract (Terms & Conditions) |
| Age verification (21+ requirement) | Legal obligation (PAGCOR regulations) |
| KYC identity verification | Legal obligation (PAGCOR, AMLC, RA 9160) |
| Processing deposits and withdrawals | Performance of contract |
| Fraud detection and prevention | Legitimate interest; legal obligation |
| Anti-money laundering monitoring | Legal obligation (RA 9160, as amended) |
| Customer support and dispute resolution | Performance of contract; legitimate interest |
| Platform security and abuse prevention | Legitimate interest |
| Responsible gaming monitoring | Legal obligation (PAGCOR responsible gaming standards) |
| Marketing communications (opted-in Players only) | Consent (withdrawable at any time) |
| Platform improvement and analytics | Legitimate interest (anonymized / aggregated data) |
| Legal and regulatory reporting | Legal obligation |
📌 Note on Consent: Where openph processes your data on the basis of consent — specifically for marketing communications — you may withdraw that consent at any time without affecting the lawfulness of processing carried out prior to withdrawal. Withdrawal of consent for marketing does not affect openph's ability to process your data for contractual or legal purposes.
openph does not sell, rent, or trade your personal data. We share your data only in the following circumstances:
openph engages carefully selected third-party service providers who process data on our behalf under contractual data processing agreements consistent with the Data Privacy Act. These include:
openph is required by Philippine law to disclose personal data to:
In the event of a merger, acquisition, restructuring, or sale of all or part of openph's business, your personal data may be transferred to the acquiring entity as part of that transaction. openph will notify affected Players of any such transfer via email to the registered email address, and will ensure that any successor entity is bound by privacy obligations consistent with this Policy.
Cookies are small text files placed on your device by the openph Platform when you visit. They allow the Platform to recognize your device, remember your preferences, maintain your login session, and collect analytical data about Platform usage. openph uses both session cookies (deleted when you close your browser) and persistent cookies (retained for a specified period).
You may configure your browser to reject or delete cookies. Note that disabling essential cookies will significantly impair the functionality of the openph Platform — including the ability to remain logged in and process transactions. Browser-level cookie management settings vary by browser and device — consult your browser's help documentation for specific instructions.
openph implements a comprehensive set of technical and organizational security measures to protect your personal data against unauthorized access, loss, destruction, alteration, or disclosure:
⚠️ Your Role in Security: While openph implements robust security measures on the Platform side, the security of your Account also depends on your actions. Use a strong, unique password for your openph Account. Enable Two-Factor Authentication. Do not share your login credentials with anyone — including persons claiming to represent openph. Our staff will never ask for your password. Report suspected unauthorized account access immediately to [email protected].
openph retains personal data for as long as necessary to fulfill the purposes for which it was collected, and to comply with mandatory legal retention periods under Philippine law. The following retention periods apply:
| Data Category | Retention Period | Legal Basis for Retention |
|---|---|---|
| Account registration data | Duration of Account + 5 years post-closure | PAGCOR requirements; AMLC (RA 9160) |
| KYC identity documents | Duration of Account + 5 years post-closure | AMLC mandatory retention (RA 9160) |
| Financial transaction records | Duration of Account + 5 years post-closure | AMLC; BIR tax records requirements |
| Gaming activity logs | Duration of Account + 2 years post-closure | PAGCOR audit requirements |
| Customer support records | 3 years from last interaction | Legitimate interest; dispute resolution |
| Marketing preferences & consents | Until withdrawal of consent + 1 year | NPC compliance; consent records |
| Security and access logs | 12 months from log creation | Security monitoring; fraud investigation |
Upon expiry of the applicable retention period, openph will securely delete or anonymize personal data in a manner consistent with applicable security standards and regulatory guidance.
openph's primary data processing operations are conducted within the Philippines. However, certain service providers — including cloud hosting infrastructure, game software providers, and identity verification services — may process data in data centers located outside the Philippines.
Where personal data is transferred outside the Philippines, openph ensures that such transfers are conducted in compliance with Section 21 of the Data Privacy Act of 2012 and applicable NPC guidelines, including through one or more of the following safeguards:
Information about the specific safeguards applicable to any cross-border transfer of your personal data may be requested from the openph Data Protection Officer.
The openph Platform is strictly intended for persons who are at least twenty-one (21) years of age. openph does not knowingly collect, process, or retain personal data from persons under the age of twenty-one (21).
If openph discovers or is notified that personal data of a person under the age of twenty-one has been collected — whether as a result of misrepresentation during registration or any other means — openph will:
🔞 Age Enforcement: openph enforces the 21+ age requirement through mandatory government ID verification during the KYC process. Persons who misrepresent their age to gain access to the Platform violate the openph Terms & Conditions and applicable PAGCOR regulations. Any person who suspects that a minor has accessed the openph Platform is encouraged to report this immediately to [email protected].
openph sends marketing communications — including promotional offers, bonus notifications, and new game announcements — only to Players who have provided explicit consent to receive such communications during registration or through their Account Settings.
Marketing communications from openph may be delivered via:
You may withdraw consent for marketing communications at any time by:
Withdrawal of consent for marketing communications does not affect your receipt of transactional communications — such as deposit confirmations, withdrawal notifications, account security alerts, or mandatory regulatory communications — which are sent on the basis of contract performance and legal obligation rather than consent.
The openph Platform integrates third-party game content from licensed game providers. When you launch and play a game from a third-party provider through the openph Platform, that provider's software processes certain gameplay data — including bet amounts, game outcomes, and session duration — as part of normal game operation. This data is shared between openph and the game provider under contractual terms that include data protection obligations.
Similarly, payment providers (GCash, Maya, BPI, BDO, etc.) operate under their own privacy policies in connection with transactions processed through their systems. openph's Privacy Policy governs only the data that openph itself collects and processes — the privacy practices of payment providers and game suppliers in respect of their own systems are governed by their respective privacy policies, which are available from those providers directly.
In the event of a personal data breach — meaning a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to personal data — openph will:
Breach notifications to Players will be sent to the registered email address associated with the affected Account. Notifications will describe the nature of the breach, the categories of data affected, the likely consequences, and the measures openph is taking to address the breach.
To exercise any of the data rights described in this Privacy Policy and under the Data Privacy Act of 2012, please submit a written request to the openph Data Protection Officer at [email protected] with the subject line "Data Privacy Request — [Right Being Exercised]."
Your request should include:
openph will acknowledge receipt of your request within three (3) business days and will respond substantively within ten (10) business days of receipt of a complete, verified request. In complex cases, this period may be extended by a further ten (10) business days, with notice to you of the extension and the reasons for it.
⚖️ NPC Complaints: If you are not satisfied with openph's response to your data rights request, or if you believe openph has violated the Data Privacy Act, you have the right to lodge a complaint with the National Privacy Commission of the Philippines. The NPC is the independent government body responsible for enforcing data privacy rights in the Philippines.
openph reserves the right to update or amend this Privacy Policy at any time to reflect changes in our data processing practices, applicable law, NPC guidance, or PAGCOR regulatory requirements. Material changes to this Privacy Policy will be communicated to registered Players via email to the registered email address no less than fourteen (14) days before the amended Policy takes effect.
The effective date at the top of this Privacy Policy reflects the date of the most recent revision. The version history of this Privacy Policy is maintained by the openph Data Protection Officer and is available upon written request.
Continued use of the openph Platform following the effective date of any amendment constitutes acceptance of the revised Privacy Policy.
All data privacy queries, requests, and complaints should be directed to the openph Data Protection Officer:
🔒 openph — Data Protection Officer
Email: [email protected]
Subject Line: "Data Privacy — [Nature of Query]"
Availability: Monday to Sunday, Philippine Standard Time
Response Commitment: Within 10 business days of verified request
For general Account and Platform support inquiries unrelated to data privacy, please use the Live Chat function accessible through the openph Platform after login, or email [email protected] with your Account-related query. Live Chat is available 24 hours per day, 7 days per week.
📋 Document Version: This Privacy Policy was last updated on 1 January 2026 and supersedes all prior versions. This Policy should be read alongside the openph Terms & Conditions and Responsible Gaming Policy, all of which are accessible via the footer links on this website.
openph is built on a foundation of compliance — PAGCOR licensing, Data Privacy Act registration, and AMLC obligations. Filipino players can enjoy the Platform knowing their personal and financial data is handled to the standards Philippine law requires.
🔞 Must be 21+ to use openph. Play responsibly. PAGCOR-regulated.
The full legal framework governing your use of the openph Platform — account rules, bonus terms, withdrawal conditions, and PAGCOR compliance details.
openph's tools for safe play — deposit limits, session controls, cooling-off periods, and permanent self-exclusion. All accessible from your Account dashboard.
Common questions about KYC, data requests, account security, GCash deposits, and withdrawal processing answered plainly on the openph FAQ page.
Already registered? Log in to openph to review your privacy settings, manage marketing preferences, and update your account information.