apiso Privacy Policy
Your privacy matters to apiso. This Privacy Policy explains exactly what personal data we collect from Filipino players, why we collect it, how we use it, who we share it with, and what rights you have under Philippine law — specifically the Data Privacy Act of 2012 (Republic Act No. 10173).
Contents
Plain-Language Summary
apiso collects personal data to operate your account, process payments, comply with PAGCOR and anti-money laundering regulations, and improve your gaming experience. We do not sell your personal data to third parties. You have the right to access, correct, and erase your data under Philippine law.
1 Overview & Scope
This Privacy Policy applies to all personal data collected, processed, stored, and used by apiso in connection with your registration, use, and interaction with the apiso platform at apiso.net, including all associated account management tools, wallet functions, game services, and customer support channels.
apiso is committed to protecting your privacy in compliance with the Data Privacy Act of 2012 (Republic Act No. 10173) of the Philippines and its Implementing Rules and Regulations, as administered by the National Privacy Commission (NPC). In addition to Philippine data privacy law, apiso processes data in accordance with the requirements of the Philippine Amusement and Gaming Corporation (PAGCOR) and applicable anti-money laundering (AML) regulations under the Anti-Money Laundering Act (AMLA) and its amendments.
By registering an account or using any part of the apiso platform, you acknowledge that you have read this Privacy Policy and consent to the collection and processing of your personal data as described herein. If you do not consent, you must not register an account or continue using the apiso platform.
This Privacy Policy should be read together with the apiso Terms and Conditions and Responsible Gaming Policy, which form part of the overall agreement governing your use of the platform.
2 Data We Collect
apiso collects the following categories of personal data from players. The specific data collected at each stage is proportionate to the purpose for which it is required.
| Category | Examples | When Collected |
|---|---|---|
| Identity Data | Full legal name, date of birth, gender, nationality, government ID type and number (e.g., PhilSys, passport, driver's license, UMID) | Registration & verification |
| Contact Data | Email address, mobile number, residential address (barangay, city/municipality, province) | Registration |
| Financial Data | GCash or Maya account details, bank account name and number (BPI, BDO, UnionBank, Metrobank), transaction history, deposit and withdrawal records | Wallet setup & transactions |
| Gaming Data | Game session logs, bet amounts, wager history, game outcomes, win/loss records, bonus usage, session duration | During gameplay |
| Technical Data | IP address, device type and model, browser type and version, operating system, screen resolution, time zone | Automatically on access |
| Usage Data | Pages visited, features used, click paths, search terms within the platform, referral source | Automatically on access |
| Communications Data | Support chat transcripts, email correspondence, complaint records, feedback submitted | When you contact support |
| Verification Documents | Scanned or photographed copies of government-issued identification, selfie images submitted for liveness verification, proof of address documents | KYC verification process |
Sensitive Personal Information
Certain data we collect — such as government ID numbers and financial account details — constitutes Sensitive Personal Information (SPI) under RA 10173. apiso handles all SPI with heightened security controls and processes it only where strictly necessary to fulfill a legal or regulatory obligation, or where you have given explicit, informed consent.
3 How We Collect Data
apiso collects personal data through the following methods:
3.1 Direct Collection
You provide data directly to apiso when you register an account, complete identity verification (KYC), make a deposit or withdrawal, contact customer support, participate in a promotion, or submit any form or request on the platform.
3.2 Automated Collection
When you access the apiso platform, our servers and analytics systems automatically collect Technical Data and Usage Data, including your IP address, device identifiers, browser information, and session activity. This data is collected using server logs, cookies, and similar tracking technologies as described in Section 7 of this Policy.
3.3 Third-Party Sources
apiso may receive data about you from third-party sources, including:
- Payment processors (e.g., GCash, Maya, BPI, BDO) confirming transaction status and account holder name.
- Identity verification service providers that assist with document authentication and liveness checks during the KYC process.
- Fraud prevention and AML screening services that cross-reference player data against regulatory watchlists.
- PAGCOR or other regulatory authorities where they share information relevant to licensing compliance or an ongoing investigation.
4 Legal Basis & Purpose
Under the Data Privacy Act of 2012, apiso processes your personal data on one or more of the following lawful bases:
- Consent: You have given free, specific, informed, and unambiguous consent to the processing of your personal data for a defined purpose (e.g., receiving promotional communications).
- Contractual Necessity: Processing is necessary to perform our obligations under the Terms and Conditions you have accepted, including operating your account, processing transactions, and providing gaming services.
- Legal Obligation: Processing is required to comply with applicable Philippine laws, including PAGCOR licensing conditions, the Anti-Money Laundering Act (AMLA), and NPC reporting obligations.
- Legitimate Interests: Processing is necessary for apiso's legitimate interests (e.g., fraud detection, platform security, responsible gaming monitoring), provided these interests are not overridden by your fundamental rights and freedoms.
5 How We Use Your Data
apiso uses the personal data we collect for the following specific purposes:
5.1 Account Management
To create, maintain, verify, and operate your apiso account, including processing your registration, confirming your identity and age (21+ requirement), resetting credentials, and managing account settings.
5.2 Payment Processing
To process deposits, withdrawals, and internal wallet transactions, verify that payment accounts are registered in your name, and maintain accurate financial records as required under Philippine financial regulations.
5.3 Regulatory Compliance
To fulfill apiso's obligations under PAGCOR licensing conditions, the Anti-Money Laundering Act, and the Data Privacy Act — including conducting KYC verification, screening against sanctions and watchlists, filing mandatory regulatory reports, and cooperating with lawful requests from PAGCOR, the AMLC, the NPC, or other competent Philippine authorities.
5.4 Gaming Services
To provide, personalize, and improve the games and features available on the apiso platform, including presenting game recommendations based on your activity, awarding bonuses, and resolving game disputes using session logs.
5.5 Responsible Gaming
To monitor gaming activity for signs of problem gambling behavior, enforce self-imposed limits and self-exclusion requests, and fulfill responsible gaming obligations required under PAGCOR's framework for licensed operators.
5.6 Security & Fraud Prevention
To detect, investigate, and prevent fraudulent transactions, unauthorized account access, bonus abuse, multi-accounting, money laundering, and other prohibited conduct outlined in the apiso Terms and Conditions.
5.7 Customer Support
To respond to your inquiries, process complaints, and maintain records of your support interactions for quality assurance and dispute resolution purposes.
5.8 Marketing Communications
Where you have given explicit consent, to send you information about apiso promotions, new games, and offers via your registered email address or mobile number. You may withdraw this consent at any time by updating your communication preferences in your account settings or by contacting support.
6 Data Sharing & Disclosure
apiso does not sell, rent, or trade your personal data to any third party for commercial purposes. We may share your data only in the following circumstances and only to the extent necessary:
6.1 Service Providers
apiso engages trusted third-party service providers who process personal data on our behalf under strict data processing agreements. These include payment gateway operators, KYC and identity verification providers, cloud hosting and infrastructure providers, fraud detection and AML screening services, and customer support platform operators. All such providers are bound by confidentiality obligations consistent with RA 10173.
6.2 Regulatory & Legal Authorities
apiso will disclose personal data to PAGCOR, the Anti-Money Laundering Council (AMLC), the National Privacy Commission (NPC), the Bureau of Internal Revenue (BIR), law enforcement agencies, or other competent Philippine government authorities where we are legally required to do so, or where disclosure is necessary to prevent fraud, money laundering, or other criminal activity.
6.3 Business Transfers
In the event of a merger, acquisition, sale of assets, or corporate restructuring involving apiso, player data may be transferred to the relevant successor entity, subject to that entity providing equivalent data protection commitments. Players will be notified of any such transfer where required under applicable law.
6.4 With Your Consent
apiso may share your data with third parties in any other circumstance where you have given explicit, informed, and freely given consent to such sharing.
We Do Not Sell Your Data
apiso does not and will not sell, rent, or otherwise commercially exploit your personal data to advertisers, data brokers, or any other third party for their own marketing or commercial purposes.
7 Cookies & Tracking Technologies
The apiso platform uses cookies and similar tracking technologies to deliver a functional, secure, and personalized experience. The following types of cookies may be in use:
- Strictly Necessary Cookies: Required for the platform to function. These include session authentication cookies, security tokens, and load-balancing cookies. These cannot be disabled without breaking core platform functionality.
- Functional Cookies: Remember your preferences such as language settings, preferred game categories, and responsible gaming limit configurations.
- Analytics Cookies: Collect anonymized or pseudonymized data about how players use the platform — such as pages visited and session duration — to help us improve the user experience.
- Security Cookies: Support fraud detection and platform security functions, including identifying suspicious login patterns or anomalous transaction behavior.
You may manage cookie preferences through your browser settings. Please note that disabling strictly necessary cookies will affect your ability to use the apiso platform. apiso does not use third-party advertising or cross-site tracking cookies.
8 Data Security
apiso implements technical, organizational, and physical security measures appropriate to the sensitivity of the personal data we hold. These measures include, but are not limited to:
- 256-bit SSL/TLS encryption for all data transmitted between your device and the apiso platform.
- Encryption at rest for sensitive personal data stored in apiso's databases, including government ID numbers and financial account details.
- Role-based access controls limiting access to personal data to apiso personnel with a verified need-to-know for their specific job function.
- Multi-factor authentication (MFA) for all apiso staff accessing systems containing player personal data.
- Regular security audits and penetration testing by qualified information security professionals.
- Incident response procedures aligned with NPC breach notification requirements under RA 10173 — apiso will notify affected players and the NPC within the required timeframes in the event of a personal data breach.
Your Responsibility
While apiso maintains robust platform-side security, you are responsible for keeping your account credentials confidential. Never share your apiso username, password, or OTP with anyone — including individuals claiming to represent apiso support. apiso staff will never ask for your password.
9 Data Retention
apiso retains personal data only for as long as is necessary to fulfill the purposes for which it was collected, or as required by applicable Philippine law. The following general retention periods apply:
- Account and identity data: Retained for a minimum of five (5) years from the date of account closure, in compliance with PAGCOR licensing obligations and AMLA record-keeping requirements.
- Transaction and financial records: Retained for a minimum of five (5) years from the date of each transaction, consistent with BIR and AMLC record-keeping rules.
- Game session logs: Retained for a minimum of one (1) year for dispute resolution purposes, and for longer periods where required by PAGCOR.
- Customer support communications: Retained for two (2) years from the date of last contact, or longer where a dispute or regulatory matter remains unresolved.
- Marketing consent records: Retained for the duration of your consent plus two (2) years, to demonstrate compliance with consent obligations.
Upon expiry of the applicable retention period, personal data will be securely deleted or anonymized in a manner that prevents re-identification, unless a legal hold or ongoing regulatory obligation requires continued retention.
10 Your Rights
Under the Data Privacy Act of 2012 (RA 10173), you have the following rights with respect to your personal data held by apiso. To exercise any of these rights, contact our Data Protection Officer as described in Section 14.
Your Data Rights Under Philippine Law
As a Filipino player on the apiso platform, you hold these rights over your personal data. Contact our Data Protection Officer to exercise any of them.
Right to Access
Request a copy of the personal data apiso holds about you, along with information about how it is being processed and for what purposes.
Right to Rectification
Request correction of any inaccurate or incomplete personal data apiso holds about you, including outdated contact details or incorrectly recorded information.
Right to Erasure
Request deletion of your personal data where it is no longer necessary for the purposes collected, subject to overriding legal or regulatory retention obligations.
Right to Object
Object to the processing of your personal data for direct marketing purposes or on grounds relating to your particular situation where processing is based on legitimate interests.
Right to Data Portability
Request your personal data in a structured, commonly used, machine-readable format where technically feasible, to transfer to another service provider of your choice.
Right to Withdraw Consent
Withdraw consent for any data processing activity based on your consent (such as marketing communications) at any time, without affecting the lawfulness of prior processing.
To exercise any of the above rights, contact our Data Protection Officer at [email protected] with the subject line "Data Privacy Request." We will respond within fifteen (15) working days as required under RA 10173.
11 Children & Minors
The apiso platform is strictly prohibited for individuals under the age of twenty-one (21) years. apiso does not knowingly collect personal data from individuals under 21 years of age. The age verification conducted at registration is specifically designed to prevent underage access.
If apiso becomes aware that personal data has been collected from a person under the age of 21 without appropriate parental or guardian consent, we will immediately suspend the relevant account, delete the personal data collected, and report the matter to PAGCOR as required under applicable regulations. If you believe that a minor has registered an account on the apiso platform, please notify us immediately at [email protected].
12 International Data Transfers
apiso primarily processes personal data within the Philippines. Where it is necessary to transfer personal data to a third-party service provider located outside the Philippines — for example, a cloud infrastructure provider or an international KYC verification service — apiso will ensure that such transfers are conducted in compliance with RA 10173 and its Implementing Rules and Regulations.
Specifically, apiso will only transfer personal data internationally where:
- The receiving country has been recognized as providing an adequate level of data protection by the National Privacy Commission; or
- Appropriate safeguards are in place, such as contractual clauses approved by the NPC or binding corporate rules; or
- The transfer is necessary to perform the contract between apiso and you, and you have been informed of the transfer.
You may request details of any international data transfers affecting your personal data by contacting our Data Protection Officer.
13 Amendments to This Policy
apiso reserves the right to update or amend this Privacy Policy at any time to reflect changes in our data processing practices, applicable Philippine law, PAGCOR regulatory requirements, or NPC guidance. The effective date of the current version is stated at the top of this page.
Where amendments are material — meaning they significantly affect your rights or how we process your data — apiso will notify you by email to your registered address, or through a prominent notice on the platform, at least fourteen (14) days before the changes take effect. For non-material updates such as clarifications or formatting corrections, the revised policy will be published without prior notice.
Your continued use of the apiso platform following the effective date of any amended Privacy Policy constitutes your acceptance of the updated terms. If you do not agree with the changes, you may close your account in accordance with the Terms and Conditions.
14 Contact & Data Protection Officer
apiso has designated a Data Protection Officer (DPO) in accordance with the requirements of the Data Privacy Act of 2012. If you have any questions, concerns, or requests relating to this Privacy Policy or to apiso's handling of your personal data, please contact the DPO using the details below.
apiso Data Protection Officer
Email: [email protected]
Subject line: "Data Privacy Request" or "DPO Inquiry"
Response time: Within 15 working days (Philippine Standard Time)
Operating hours: Monday to Friday, 9:00 AM – 6:00 PM PST
You also have the right to lodge a complaint with the National Privacy Commission (NPC) of the Philippines if you believe your data privacy rights under RA 10173 have been violated. Information on how to file a complaint with the NPC is available on the official NPC website through official Philippine government channels.
How apiso Protects Your Data
From registration to withdrawal, apiso applies privacy and security measures at every step of your journey on the platform.
256-Bit SSL Encryption
Every data exchange between your device and the apiso platform is protected by 256-bit SSL/TLS encryption — the same standard used by Philippine commercial banks for their online banking portals.
Strict KYC Verification
Identity verification protects both you and the platform. We verify every player's age and identity using Philippine government-issued IDs — keeping underage players out and your account secure from impersonation.
Encrypted Data at Rest
Sensitive personal information stored in apiso's systems — including ID numbers and financial account details — is encrypted at rest, meaning it cannot be read even in the event of unauthorized server access.
RA 10173 Compliance
apiso processes all player data in accordance with the Philippine Data Privacy Act of 2012, with a designated Data Protection Officer and documented data processing procedures registered with the NPC.
You Control Marketing Consent
Promotional emails and SMS messages are sent only with your explicit consent. You can update your communication preferences from your account settings at any time — no hoops to jump through.
No Data Selling — Ever
apiso does not sell, rent, or commercially exploit your personal data. Your information stays within the apiso platform and with trusted service providers bound by strict confidentiality obligations.
Your Data Is Safe With apiso
Explore the full apiso platform with confidence — your personal data is protected at every step. 500+ games, live casino, bingo, and virtual sports — built for Filipino players. Must be 21 years or older. PAGCOR regulated.