Privacy Policy
This Privacy Policy describes how xxhp Casino ("xxhp", "we", "us", "our") collects, uses, stores, discloses, and protects the personal information of every individual who accesses or uses the xxhp platform at xxhp.club. It is issued in compliance with Republic Act No. 10173, the Philippine Data Privacy Act of 2012, and its Implementing Rules and Regulations.
This Privacy Policy applies to all personal information collected and processed by xxhp in connection with:
- The xxhp website accessible at xxhp.club and any mobile-optimised version thereof.
- The account registration and KYC verification process.
- All gaming activities conducted through the xxhp platform, including casino games, sports betting, bingo, and e-sabong.
- All financial transactions processed through xxhp, including deposits via GCash, Maya, BPI, BDO, and other accepted methods.
- Communications between you and xxhp through live chat, email, or any other support channel.
- Any promotional, loyalty, or responsible gaming programme administered by xxhp.
Data Controller: xxhp Casino, operating at xxhp.club, acts as the personal information controller (PIC) for all personal data collected and processed in connection with the xxhp platform, as defined under Section 3(h) of Republic Act No. 10173 — the Philippine Data Privacy Act of 2012.
This Policy does not apply to any third-party websites, services, or platforms that may be linked to from the xxhp platform. xxhp is not responsible for the privacy practices of third parties.
xxhp collects only the personal information that is necessary and proportionate to the purposes set out in Section 4 of this Policy. The categories of personal data collected by xxhp include:
| Category | Data Elements | Collection Trigger |
|---|---|---|
| Identity Data | Full legal name, date of birth, nationality, government ID number, ID document images, selfie photograph | Registration & KYC verification |
| Contact Data | Philippine mobile number, email address, residential address | Account registration |
| Financial Data | GCash or Maya account reference (masked), bank account name, deposit and withdrawal history, transaction timestamps and amounts | Deposit / withdrawal processing |
| Gaming Data | Game session logs, bet amounts, game outcomes, RTP data, win/loss records, session durations | Gameplay |
| Technical Data | IP address, device type, operating system, browser type, session tokens, access timestamps | Platform access |
| Communication Data | Live chat transcripts, email correspondence, support ticket content | Customer support interaction |
| Responsible Gaming Data | Deposit limits set, self-exclusion elections, cool-off periods activated, problem gambling flags | Responsible gaming tool use |
xxhp does not collect full payment card numbers, CVV codes, or online banking credentials. All payment processing is handled through your chosen payment provider's secure interface, and xxhp receives only the reference data necessary to reconcile transactions.
xxhp collects personal data through the following channels:
- Directly from you — when you create an xxhp account, complete the KYC verification process, make a deposit or withdrawal, use responsible gaming tools, contact xxhp support, or participate in any promotion or survey.
- Automatically during platform use — xxhp's servers automatically log technical data such as your IP address, device type, browser version, session duration, and pages visited whenever you access the xxhp platform.
- From payment providers — xxhp receives transaction confirmation data from GCash, Maya, BPI, BDO, Metrobank, InstaPay, and other payment processors when you deposit or withdraw funds. This includes transaction reference numbers and masked account identifiers.
- From identity verification services — where xxhp uses a third-party service to assist with KYC document verification or liveness checks, that service provides xxhp with a verification result and associated identity data.
- Cookies and tracking technologies — as further described in Section 9 of this Policy.
xxhp processes your personal data for the following purposes, each of which has a defined legal basis under the Philippine Data Privacy Act of 2012:
- Account creation and management — necessary for the performance of the contract between you and xxhp. Your identity, contact, and login data are processed to create and maintain your account, authenticate your sessions, and enable you to use the xxhp platform.
- Age verification and KYC compliance — necessary for compliance with PAGCOR regulatory requirements and Philippine law, which mandates that all players must be verified as 21 years of age or older before full access to gaming services is granted.
- Payment processing — necessary for the performance of the contract. Financial data is processed to facilitate deposits, withdrawals, and transaction reconciliation in Philippine Peso.
- Fraud prevention and security — necessary for compliance with legal obligations and for the legitimate interests of xxhp and its players. Technical and financial data are used to detect suspicious activity, prevent money laundering, identify multi-accounting, and protect account security.
- Anti-money laundering (AML) compliance — necessary for compliance with the Philippine Anti-Money Laundering Act (AMLA) and PAGCOR's AML compliance requirements. Transaction data may be retained and disclosed to the AMLC or PAGCOR as required by law.
- Responsible gaming — necessary for compliance with PAGCOR requirements and for the protection of players' vital interests. Responsible gaming data is used to administer limits, self-exclusions, and player protection interventions.
- Customer support — necessary for the performance of the contract. Communication data is processed to resolve queries, investigate complaints, and improve the support service.
- Marketing communications — based on your consent. Where you have opted in to receive marketing communications from xxhp, your contact data and gaming preferences may be used to send you relevant promotions. You may withdraw consent at any time by contacting xxhp support.
- Platform improvement and analytics — based on xxhp's legitimate interests in improving its products. Anonymised or aggregated technical and gaming data may be used to analyse platform performance and user experience.
xxhp does not sell, rent, or trade your personal information to any third party for commercial purposes. xxhp may disclose your personal data to the following categories of recipients, and only to the extent necessary for the stated purpose:
- Payment processors — GCash (GXI), Maya (PayMaya Philippines), BPI, BDO, Metrobank, GrabPay, and other payment service providers receive the minimum transaction data required to process your deposits and withdrawals.
- KYC and identity verification providers — third-party services engaged by xxhp to assist with government ID verification and liveness checks. These providers act as personal information processors (PIPs) under data processing agreements with xxhp.
- Game software providers — providers such as PG Soft, Pragmatic Play, Jili Games, and WM Live may receive a player session token (not your full personal data) to facilitate game loading and session management. These providers do not receive your identity or financial data.
- Regulatory and law enforcement authorities — xxhp may disclose personal data to PAGCOR, the Anti-Money Laundering Council (AMLC), the National Privacy Commission (NPC), or other Philippine government authorities where required by law, legal process, or regulatory directive.
- Legal advisors and auditors — professional advisors engaged by xxhp may have access to personal data on a need-to-know basis, subject to appropriate confidentiality obligations.
- Business successors — in the event of a merger, acquisition, or sale of all or part of xxhp's business, personal data held by xxhp may be transferred to the acquiring entity, subject to the protections provided under this Privacy Policy.
Some of xxhp's service providers and game platform partners may process personal data in servers located outside the Republic of the Philippines. Where such cross-border transfers occur, xxhp ensures that:
- The receiving country, organisation, or entity provides a level of data protection at least equivalent to that required under the Philippine Data Privacy Act of 2012.
- Appropriate safeguards — such as standard contractual clauses, binding corporate rules, or equivalent contractual protections — are in place between xxhp and the receiving party.
- Such transfers are limited to the minimum data necessary for the legitimate operational purpose that requires the transfer.
- xxhp remains accountable for the protection of transferred data and will take appropriate steps to address any data breach occurring at a recipient outside the Philippines.
xxhp retains personal data only for as long as is necessary to fulfil the purpose for which it was collected, or as required by applicable Philippine law. The following retention periods apply as a general guide:
| Data Category | Retention Period | Basis |
|---|---|---|
| Account & Identity Data | Duration of account plus 5 years after closure | PAGCOR regulatory requirement; AMLA |
| Financial Transaction Data | 10 years from transaction date | Anti-Money Laundering Act (AMLA) |
| KYC Documents | Duration of account plus 5 years | PAGCOR compliance |
| Gaming Session Data | 3 years from session date | Dispute resolution; regulatory audit |
| Support Communications | 3 years from last interaction | Legitimate interest; dispute resolution |
| Marketing Preferences | Until consent is withdrawn | Consent |
| Technical / Log Data | 12 months from collection | Security monitoring; fraud prevention |
Upon the expiry of the applicable retention period, xxhp will securely delete or anonymise the relevant personal data in accordance with its internal data lifecycle procedures. Where anonymisation is applied, the resulting data (which no longer identifies you) may be retained indefinitely for statistical and analytical purposes.
xxhp implements a comprehensive set of technical and organisational security measures designed to protect your personal data against unauthorised access, alteration, disclosure, or destruction. These include:
- Transport Encryption: All data transmitted between your device and xxhp's servers is encrypted using TLS 1.2 or higher (HTTPS). The padlock icon in your browser confirms this encryption is active during every xxhp session.
- Data-at-Rest Encryption: Personal and financial data stored in xxhp's databases is encrypted at rest using AES-256 encryption.
- Access Controls: Access to personal data within xxhp's systems is restricted on a strict need-to-know basis. All internal access is logged and subject to regular review.
- Two-Factor Authentication: xxhp offers and recommends two-factor authentication (2FA) for all player accounts, adding an additional verification layer beyond the password.
- Intrusion Detection: xxhp employs automated systems to detect and respond to suspicious access patterns, brute force attempts, and other security threats in real time.
- Penetration Testing: xxhp conducts periodic security assessments, including penetration testing by qualified security professionals, to identify and remediate vulnerabilities.
- Staff Training: All xxhp staff who handle personal data receive regular training on data protection obligations and security best practices.
- Data Breach Response: xxhp maintains a data breach response procedure. In the event of a personal data breach that poses a real risk of serious harm, xxhp will notify the National Privacy Commission and affected individuals in accordance with the timelines prescribed by the Philippine Data Privacy Act and its Implementing Rules and Regulations.
xxhp uses cookies and similar tracking technologies on the xxhp platform. Cookies are small text files stored on your device by your browser when you visit xxhp. The following categories of cookies are used:
- Strictly Necessary Cookies: These cookies are essential for the xxhp platform to function correctly. They maintain your login session, preserve your account preferences, and enable core platform features such as the game lobby and wallet. These cookies cannot be disabled without impairing the functionality of xxhp.
- Performance and Analytics Cookies: These cookies collect anonymised information about how players use xxhp — which pages are visited most, how long sessions last, and where technical errors occur. This data is used to improve the xxhp platform experience. You may opt out of performance cookies without affecting core platform functionality.
- Functional Cookies: These cookies remember your preferences — such as your preferred language, last game played, or display settings — to provide a more personalised experience on xxhp.
- Security Cookies: These cookies assist xxhp's fraud prevention and security monitoring systems by flagging sessions that exhibit unusual patterns consistent with automated bot activity or account takeover attempts.
You can manage or delete cookies through your browser settings. Please note that disabling strictly necessary cookies will impair your ability to log in and use the xxhp platform. For further information on managing cookies in your specific browser, refer to your browser's help documentation.
Under the Philippine Data Privacy Act of 2012, you have the following rights with respect to your personal data held by xxhp. To exercise any of these rights, contact xxhp's Data Protection Officer using the contact details in Section 14:
xxhp will respond to all data subject rights requests within 30 calendar days of receipt. Where a request is complex or involves a large volume of data, xxhp may extend this period by up to a further 30 days, with prior notice to you. xxhp will not charge a fee for processing rights requests unless the request is manifestly unfounded or excessive.
The xxhp platform is strictly intended for individuals who are 21 years of age or older, in accordance with PAGCOR's regulatory framework and Philippine gaming law. xxhp does not knowingly collect or process personal data from individuals under 21 years of age.
Where xxhp discovers or reasonably suspects that an account has been created by or for an individual under the age of 21, xxhp will immediately:
- Suspend access to the account pending investigation.
- Delete any personal data collected from the underage individual to the extent permitted by applicable law.
- Refund any real-money deposits made to the account in accordance with PAGCOR's applicable procedures.
- Report the matter to PAGCOR where required by regulation.
Parents and guardians who become aware that a minor under their care has registered for an xxhp account should contact xxhp support immediately at [email protected].
The xxhp platform does not contain links to third-party websites or services. In the event that any third-party content becomes accessible from the xxhp platform in the future, this Privacy Policy will be updated accordingly. xxhp is not responsible for the data protection practices of any third-party platform. Users are advised to review the privacy policy of any external service before providing personal information to that service.
xxhp reserves the right to update this Privacy Policy at any time to reflect changes in applicable law, regulatory requirements, or xxhp's data processing practices. Where amendments are material, xxhp will provide notice through one or more of the following channels: in-platform notification, email to your registered address, or a prominent notice on the xxhp website.
The effective date displayed at the top of this document reflects the date of the most recent revision. Your continued use of the xxhp platform after the effective date of a revised Privacy Policy constitutes your acknowledgment of the revised terms. Prior versions of this Policy are available on request from the xxhp Data Protection Officer.
For any questions, concerns, or formal requests relating to this Privacy Policy or xxhp's handling of your personal data, please contact the xxhp Data Protection Officer (DPO) through the following channels:
If you are not satisfied with xxhp's response to a data privacy concern, you have the right to escalate the matter to the National Privacy Commission of the Philippines (NPC) at privacy.gov.ph. The NPC is the independent authority responsible for administering and implementing the Philippine Data Privacy Act of 2012.
How xxhp Protects Your Data
Six core commitments that define how xxhp handles every Filipino player's personal information.
Ready to Play with Confidence?
Your personal data is protected at every step on xxhp. Join Filipino players who trust xxhp for secure, regulated, and responsible online gaming.
xxhp is strictly for players aged 21 and above. Gambling involves risk. Visit Responsible Gaming if you need support.