ggpaldo Privacy Policy
At ggpaldo, your privacy matters as much as your next big win. This Privacy Policy explains exactly what personal data we collect, why we collect it, how we use it, who we share it with, and what rights you have under the Data Privacy Act of 2012 (Republic Act No. 10173). We believe in being upfront — no legal jargon maze, just clear and honest information.
Our Privacy Commitments to You
These six commitments summarize how ggpaldo treats your personal data. The full legal detail is in the sections below — but these are the principles we hold ourselves to every day.
Purpose Limitation
ggpaldo only collects personal data that is genuinely necessary for operating your account, processing transactions, and complying with PAGCOR and AMLC regulations. We do not collect data speculatively or for purposes we cannot clearly justify.
No Selling Your Data
ggpaldo does not sell, rent, or trade your personal information to third-party marketers, data brokers, or advertisers. Your data is used exclusively to deliver and improve the ggpaldo platform and to meet our regulatory obligations — nothing more.
Security First
All data transmitted between your device and ggpaldo's servers is protected by 256-bit SSL/TLS encryption. Sensitive data at rest — including payment details and identity documents — is stored using industry-standard encryption protocols across our secure, access-controlled infrastructure.
Your Rights Are Real
Under the Data Privacy Act of 2012, you have the right to access, correct, delete, and object to the processing of your personal data. ggpaldo has a dedicated process for handling these requests promptly — typically within 15 business days of a verified request.
Minimal Third-Party Sharing
We only share your data with third parties that are strictly necessary to operate the platform: payment processors like GCash and PayMaya, identity verification providers, and government bodies such as PAGCOR and AMLC as required by law. All third-party partners are contractually bound to protect your data.
Retention Limits
ggpaldo does not keep your personal data indefinitely. Retention periods are determined by regulatory requirements, legal obligations, and operational necessity. Once the applicable retention period expires, your data is securely deleted or anonymized in accordance with our data lifecycle policy.
Section 1
Introduction
This Privacy Policy ("Policy") describes how ggpaldo ("the Company," "we," "us," or "our") collects, processes, uses, stores, and protects the personal data of users ("you," "Player," or "User") of the ggpaldo website at https://ggpaldo.net and all associated applications, services, and platforms (collectively, the "Platform").
ggpaldo is committed to protecting the privacy and personal data of all players in the Philippines in full compliance with the Data Privacy Act of 2012 (Republic Act No. 10173) and its Implementing Rules and Regulations, as enforced by the National Privacy Commission (NPC). We are also subject to data-related obligations under PAGCOR's licensing requirements and the Anti-Money Laundering Act of 2001 (Republic Act No. 9160, as amended).
This Policy applies to all personal data collected from registered players, visitors to the Platform, and individuals who contact ggpaldo's support channels. By accessing or using the Platform, you acknowledge that you have read, understood, and agree to the collection and processing of your personal data as described in this Policy.
This Policy should be read together with ggpaldo's Terms & Conditions and Responsible Gaming Policy, both of which are incorporated by reference.
Section 2
Data Controller Information
For the purposes of the Data Privacy Act of 2012, the data controller responsible for your personal data is:
- Brand Name: ggpaldo
- Website: https://ggpaldo.net
- Jurisdiction: Republic of the Philippines
- Regulatory Authority: Philippine Amusement and Gaming Corporation (PAGCOR)
- Privacy Contact: [email protected]
ggpaldo has designated a Data Protection Officer (DPO) in accordance with the requirements of the Data Privacy Act and NPC regulations. The DPO is responsible for overseeing ggpaldo's data protection strategy, ensuring compliance with applicable privacy laws, and serving as the primary point of contact for data subject requests and NPC inquiries. You may reach the DPO at the contact address listed in Section 14 of this Policy.
Section 3
Personal Data We Collect
ggpaldo collects the following categories of personal data, depending on how you interact with the Platform:
| Category | Examples | Required? |
|---|---|---|
| Identity Data | Full name, date of birth, nationality, government-issued ID number (e.g., PhilSys, SSS, UMID, driver's license, passport) | Yes – KYC mandatory |
| Contact Data | Mobile number, email address, residential address (barangay, city, province, postal code) | Yes – account registration |
| Account Data | Username, hashed password, account balance, transaction history, bonus history, account preferences | Yes – account operation |
| Financial Data | GCash number, PayMaya number, BPI/BDO/Metrobank account details (last 4 digits only for display), deposit/withdrawal records | Yes – payment processing |
| Identity Verification Documents | Scanned/photographed copies of government IDs, selfie with ID, proof of billing, source-of-funds documents | Yes – KYC/AML compliance |
| Technical Data | IP address, device type, browser type and version, operating system, screen resolution, session timestamps | Automatic – platform security |
| Usage Data | Pages visited, games played, bet history, wagering patterns, session duration, click events | Automatic – service improvement |
| Communications Data | Live chat transcripts, support email exchanges, dispute records | When you contact support |
| Responsible Gaming Data | Self-exclusion status, deposit limit settings, reality check preferences, session time data | When tools are activated |
Special Category Data: ggpaldo does not intentionally collect sensitive personal information as defined under Section 3(l) of the Data Privacy Act (e.g., health data, religious beliefs, political affiliation) unless strictly required for responsible gaming or regulatory compliance purposes and only with your explicit consent.
Section 4
How We Collect Your Data
ggpaldo collects personal data through the following channels and methods:
- Direct Collection: Information you provide when registering an account, completing KYC verification, making deposits or withdrawal requests, submitting support tickets, or participating in promotions and surveys.
- Automated Technical Collection: Data collected automatically when you access and use the Platform, including IP addresses, device identifiers, browser fingerprints, and session activity logs. This is collected via server logs, cookies, and similar tracking technologies.
- Payment Provider Data: Transaction confirmation data received from GCash, PayMaya, BPI, BDO, Metrobank, and other payment partners when you initiate deposits or withdrawals. ggpaldo does not store full card or e-wallet account numbers — only masked references used for transaction reconciliation.
- Identity Verification Providers: Results and data outputs from third-party KYC verification services engaged to validate government-issued identification documents and perform liveness checks.
- Regulatory Databases: Information obtained from PAGCOR's self-exclusion registry and other regulatory databases as required for compliance screening.
- Support Interactions: Transcripts and records of your communications with ggpaldo's 24/7 support team via live chat and email.
Section 5
Legal Basis for Processing
Under the Data Privacy Act of 2012, ggpaldo processes your personal data on the following legal grounds:
- Contractual Necessity: Processing required to perform the contract between you and ggpaldo — specifically, to register and manage your player account, process deposits and withdrawals, and deliver gaming services.
- Legal Obligation: Processing required to comply with Philippine law, including PAGCOR licensing requirements, Anti-Money Laundering Act obligations (AMLA/R.A. 9160), and NPC data breach notification requirements.
- Legitimate Interests: Processing necessary for ggpaldo's legitimate business interests, including fraud prevention, security monitoring, platform performance optimization, and responsible gaming oversight — provided these interests are not overridden by your data protection rights.
- Consent: Processing based on your freely given, specific, informed, and unambiguous consent — for example, for direct marketing communications. You may withdraw consent at any time by contacting support or updating your account preferences; withdrawal of consent does not affect the lawfulness of processing conducted prior to withdrawal.
Section 6
How We Use Your Personal Data
ggpaldo uses your personal data for the following specific purposes:
- Account Registration & Management: Creating and maintaining your player account, verifying your identity and eligibility (age 21+), managing your account preferences, and processing account closure requests.
- KYC & AML Compliance: Verifying your identity documents, screening against PAGCOR exclusion lists, performing source-of-funds checks for large transactions, and filing mandatory reports to the Anti-Money Laundering Council (AMLC) as required by R.A. 9160.
- Payment Processing: Facilitating deposits and withdrawals via GCash, PayMaya, and local bank channels; reconciling transactions; and investigating disputed transactions.
- Gaming Services: Delivering casino games, live dealer tables, sports betting markets, bingo, slots, and all other Platform features; tracking bet and wagering history for settlement purposes.
- Responsible Gaming: Monitoring wagering patterns for indicators of problem gambling; enforcing deposit limits, self-exclusion periods, and cooling-off requests; complying with PAGCOR's Responsible Gaming Framework.
- Promotions & Bonuses: Determining eligibility for and administering bonuses, free spins, cashback offers, and loyalty rewards.
- Customer Support: Responding to your inquiries, complaints, and dispute escalations; maintaining support records for quality assurance and regulatory audit purposes.
- Security & Fraud Prevention: Detecting and preventing unauthorized account access, fraudulent transactions, collusion, bonus abuse, and use of prohibited software or bots.
- Platform Improvement: Analyzing aggregated usage data to improve game performance, fix bugs, enhance the user interface, and optimize the overall player experience.
- Marketing Communications (Consent-Based): Sending promotional emails or SMS messages about new games, special offers, and tournaments — only where you have provided consent and only via channels you have authorized.
- Legal & Regulatory Compliance: Responding to lawful requests from PAGCOR, NPC, AMLC, or other Philippine government authorities; complying with court orders and legal proceedings.
No Automated Decision-Making with Legal Effects: ggpaldo does not make decisions that produce significant legal effects on you — such as permanent account closure — using fully automated processing without human review. Our compliance and risk teams manually review all cases before taking material action against a player account.
Section 7
Data Sharing & Disclosure
ggpaldo does not sell your personal data. We share your data only with the following categories of recipients, and only to the extent necessary for the stated purpose:
- Payment Service Providers: GCash, PayMaya, BPI, BDO, Metrobank, UnionBank, and other Philippine payment partners — for the sole purpose of processing your deposits and withdrawals.
- Identity Verification & KYC Providers: Third-party providers engaged to verify government-issued identification documents and conduct liveness checks as part of our KYC process. These providers are contractually prohibited from using your data for any purpose other than the KYC service rendered for ggpaldo.
- Regulatory Authorities: PAGCOR (as licensing authority), AMLC (for mandatory AML reports under R.A. 9160), the National Privacy Commission (NPC), and other Philippine government agencies as required by law or by lawful order.
- IT Infrastructure & Cloud Service Providers: Providers of hosting, database, and cloud infrastructure services used to operate the Platform. These providers are bound by strict data processing agreements and are not permitted to process your data for their own purposes.
- Game Content Providers: In limited cases, game providers whose titles are integrated into the Platform may receive anonymized session and bet data for game performance and integrity monitoring purposes. Personally identifiable data is not shared with game providers.
- Legal & Compliance Advisors: Philippine legal counsel and compliance consultants engaged to advise ggpaldo on regulatory matters, where access to specific player data is necessary and subject to professional confidentiality obligations.
Any third party that receives personal data from ggpaldo is required to handle it in accordance with the Data Privacy Act of 2012 and is contractually bound via a Data Sharing Agreement (DSA) or Data Processing Agreement (DPA) as applicable under NPC regulations.
ggpaldo does not transfer your personal data to recipients outside the Philippines unless there is a legal basis for the transfer and adequate data protection safeguards are in place, consistent with NPC guidelines on cross-border data transfers.
Section 8
Cookies & Tracking Technologies
ggpaldo uses cookies and similar tracking technologies to operate the Platform, enhance your experience, and fulfill our security and compliance obligations. A cookie is a small text file stored on your device by your browser when you visit the Platform.
| Cookie Type | Purpose | Can Be Disabled? |
|---|---|---|
| Strictly Necessary | Session management, login authentication, security token validation, fraud prevention signals | No – Platform cannot function without these |
| Functional | Remembering your language preferences, display settings, and responsible gaming tool configurations | Yes – via browser settings |
| Performance / Analytics | Aggregated, anonymized data on page load times, feature usage, and navigation patterns used to improve the Platform | Yes – via browser settings |
| Security | Device fingerprinting and IP consistency checks to detect account takeover attempts and unauthorized access | No – required for account security |
ggpaldo does not use third-party advertising or behavioral tracking cookies. You can manage or delete cookies through your browser settings; however, disabling strictly necessary or security cookies may prevent you from logging into or using the Platform correctly.
Section 9
Data Retention
ggpaldo retains personal data only for as long as necessary to fulfill the purposes for which it was collected, or as required by Philippine law and PAGCOR regulations. The following retention periods apply:
- Account and KYC Records: Retained for a minimum of five (5) years following account closure, as required by PAGCOR licensing conditions and AMLA record-keeping obligations.
- Financial Transaction Records: Retained for a minimum of five (5) years from the date of each transaction, in compliance with R.A. 9160 and Bureau of Internal Revenue requirements.
- AML Suspicious Transaction Reports: Retained for a minimum of five (5) years from the date of the report, as mandated by AMLC regulations.
- Support and Communications Records: Retained for three (3) years from the date of the last interaction, for dispute resolution and quality assurance purposes.
- Technical and Usage Logs: Retained for twelve (12) months, after which logs are either deleted or anonymized for aggregated analytics purposes.
- Marketing Consent Records: Retained for the duration of the consent plus three (3) years following withdrawal of consent, to demonstrate compliance with consent requirements.
At the end of the applicable retention period, personal data is securely deleted, anonymized, or archived using methods that render re-identification impossible. Physical documents containing personal data are shredded; digital records are cryptographically erased.
Section 10
Security Measures
ggpaldo implements a comprehensive set of technical and organizational security measures to protect your personal data against unauthorized access, disclosure, alteration, or destruction. These measures include:
- Encryption in Transit: All data exchanged between your device and ggpaldo's servers is encrypted using TLS 1.2 or higher (256-bit SSL). The Platform enforces HTTPS exclusively — unencrypted HTTP connections are redirected automatically.
- Encryption at Rest: Sensitive data stored in ggpaldo's databases — including identity documents and financial records — is encrypted at rest using AES-256 encryption.
- Access Controls: Access to personal data within ggpaldo's internal systems is restricted on a strict need-to-know basis. All staff with access to personal data undergo background screening and regular data privacy training as required by NPC regulations.
- Multi-Factor Authentication: Internal administrative access to production systems containing personal data requires multi-factor authentication (MFA). Players are also encouraged to enable MFA on their ggpaldo accounts.
- Intrusion Detection & Monitoring: ggpaldo's infrastructure is monitored 24/7 for anomalous activity, unauthorized access attempts, and potential data breaches using automated security information and event management (SIEM) tools.
- Penetration Testing: Regular third-party penetration testing is conducted to identify and remediate security vulnerabilities before they can be exploited.
- Data Breach Response: In the event of a personal data breach, ggpaldo will notify affected players and the National Privacy Commission (NPC) within 72 hours of discovery, as required under NPC Circular 16-03, where the breach is likely to result in harm to affected individuals.
Your Role in Security: While ggpaldo takes all reasonable measures to protect your data on our end, you also play an important role. Keep your ggpaldo password confidential, enable MFA, and contact our support team immediately if you notice any suspicious activity on your account. ggpaldo will never ask for your password via email, SMS, or live chat.
Section 11
Your Data Subject Rights
Under the Data Privacy Act of 2012, you have the following rights with respect to your personal data held by ggpaldo. These rights are real and enforceable — ggpaldo has a dedicated process for handling each type of request:
To exercise any of these rights, please submit a written request to our Data Protection Officer at [email protected] with the subject line "Data Subject Request." Please include your full name, registered email address, and a description of the right you wish to exercise. We may ask for additional verification to confirm your identity before processing the request. We will respond within 15 business days of receiving a complete, verified request.
Section 12
Minors & Age Restriction
The ggpaldo Platform is strictly for individuals who are 21 years of age or older, in accordance with Philippine law governing casino-style gambling and PAGCOR's regulatory requirements. ggpaldo does not knowingly collect, process, or store personal data from individuals under the age of 21.
During account registration, all applicants are required to declare their date of birth and provide government-issued identification confirming they meet the 21+ age requirement. ggpaldo's KYC process includes age verification as a mandatory step, and accounts found to belong to individuals under 21 will be immediately suspended and all associated funds returned after investigation.
If you are a parent or guardian and believe that a minor has accessed ggpaldo and provided personal data without your consent, please contact us immediately at [email protected]. We will investigate the matter promptly and delete any personal data collected from the individual if they are confirmed to be under 21.
Parental Advisory: ggpaldo strongly encourages parents and guardians to use parental control software to restrict access to online gambling platforms on shared or family devices. Age verification during registration is mandatory, but no digital control is a substitute for parental supervision.
Section 13
Changes to This Privacy Policy
ggpaldo reserves the right to update or amend this Privacy Policy at any time to reflect changes in applicable Philippine law, NPC guidelines, PAGCOR requirements, or our operational practices. The date at the top of this Policy indicates when it was last revised.
When we make material changes to this Policy — particularly changes that affect how we collect, use, or share your personal data — we will notify you by:
- Displaying a prominent notice on the Platform upon your next login, summarizing the key changes.
- Sending a notification to your registered email address at least seven (7) days before the updated Policy takes effect, where practicable.
Your continued use of the Platform after the effective date of any revision constitutes your acceptance of the updated Privacy Policy. If you do not agree with the revised Policy, you must discontinue use of the Platform and may request account closure in accordance with our Terms & Conditions.
We encourage you to review this Privacy Policy periodically. The current version is always available at https://ggpaldo.net/privacy-policy. Previous versions of this Policy are available upon written request to our Data Protection Officer.
Section 14
Contact & Data Protection Officer
For any questions, concerns, or requests relating to this Privacy Policy or the processing of your personal data by ggpaldo, please contact us through the following channels:
- Email (DPO & Privacy Requests): [email protected] — use subject line "Privacy Policy Inquiry" or "Data Subject Request" as appropriate.
- Live Chat: Available 24/7 via the chat widget on the Platform. For data subject requests, please follow up in writing via email to ensure a proper audit trail.
- Support Hours: Monday through Sunday, 24 hours a day.
ggpaldo aims to acknowledge all privacy-related inquiries within 24 hours and to provide a substantive response within 15 business days. Complex requests may take longer; in such cases, we will inform you of the extended timeline and the reason for the delay.
If you are not satisfied with ggpaldo's response to your privacy inquiry, you have the right to escalate your complaint to the National Privacy Commission (NPC), the regulatory authority responsible for enforcing the Data Privacy Act of 2012 in the Philippines. This Privacy Policy was last reviewed and updated in January 2026.
Your Data Is Safe With ggpaldo
We're built on trust — transparent about how we handle your data, compliant with the Philippine Data Privacy Act, and committed to giving you full control over your personal information. Ready to experience a platform that puts Filipino players first?
21+ only · PAGCOR Regulated · DPA 2012 Compliant · Play Responsibly