perawin ("we," "us," "our") is the operator of the online gaming platform available at https://perawin.win (the "Platform"). For the purposes of Philippine data privacy law, perawin is the Personal Information Controller (PIC) in respect of the personal data of its members and users collected through and in connection with the Platform.
perawin operates in accordance with the Philippine Amusement and Gaming Corporation's (PAGCOR) regulatory requirements. As part of its licensing obligations, perawin maintains data governance practices that comply with both PAGCOR standards and the Philippine Data Privacy Act of 2012 (Republic Act No. 10173, or "DPA").
This Privacy Policy applies to all personal data that perawin collects, processes, stores, or shares in connection with:
- The registration, maintenance, and closure of a perawin member account;
- Your use of any game, feature, or service available through the Platform;
- Any deposit, withdrawal, or financial transaction processed through your perawin Wallet;
- Your communications with perawin's customer support or responsible gaming teams;
- Your participation in any perawin promotion, bonus program, or loyalty scheme; and
- Your general browsing of the perawin website, including data collected via cookies and analytics tools.
This Policy does not apply to third-party websites or services that may be referenced on the Platform. perawin is not responsible for the privacy practices of any third party whose services are integrated into or linked from the Platform.
perawin collects personal data across the following categories:
- Full legal name, date of birth, and nationality
- Government-issued identification number (e.g., Philippine National ID, passport, driver's license)
- Registered email address and Philippine mobile number
- Home address and city of residence within the Philippines
- Username and encrypted account credentials
- GCash and PayMaya mobile wallet numbers (masked after registration)
- Bank account details for BPI, BDO, Metrobank, and other supported Philippine bank transfers
- Payment card details (last four digits only; full card numbers are not stored by perawin)
- Transaction history including all deposits, withdrawals, bets, wins, and bonus activities
- IP address and approximate geographic location derived from IP
- Device type, operating system, and browser type and version
- Session duration, pages visited, and game activity logs
- Login timestamps and authentication event records
- Cookies and similar tracking technology data (see Section 10)
- Records of live chat conversations with perawin support agents
- Email correspondence with perawin including complaint and support records
- Responses to surveys, feedback requests, and responsible gaming questionnaires
perawin collects your personal data through the following channels:
| Collection Method | Examples |
|---|---|
| Directly from you | Account registration form, identity verification documents, deposit and withdrawal requests, support communications |
| Automatically via technology | Cookies, session tokens, IP address logging, device fingerprinting for fraud prevention |
| Third-party payment processors | Transaction confirmation data from GCash, PayMaya, BPI, BDO, Metrobank, and card networks |
| Identity verification providers | KYC (Know Your Customer) document verification results, AML screening outcomes |
| Social login providers | Basic profile data (name, email, profile picture) if you use Google or Facebook sign-in |
| Regulatory authorities | PAGCOR self-exclusion register data; court or law enforcement orders |
perawin processes your personal data for the following purposes and on the following legal bases under the Philippine Data Privacy Act:
| Purpose | Legal Basis |
|---|---|
| Account registration and management | Performance of contract (your membership agreement with perawin) |
| Identity verification (KYC) | Legal obligation (PAGCOR AML and player protection requirements) |
| Processing deposits and withdrawals | Performance of contract; legal obligation |
| Fraud prevention and security monitoring | Legitimate interest of perawin and its members |
| Responsible gaming compliance and intervention | Legal obligation (PAGCOR responsible gaming framework) |
| Customer support and dispute resolution | Performance of contract; legitimate interest |
| Regulatory reporting and compliance | Legal obligation (PAGCOR; AMLC; NPC) |
| Platform analytics and improvement | Legitimate interest; consent where required |
| Marketing and promotional communications | Consent (opt-in); you may withdraw at any time |
perawin does not sell, rent, or trade your personal data to any third party for commercial purposes. We share your data with third parties only in the following limited circumstances:
perawin engages trusted third-party service providers to support the operation of the Platform. These parties process your data only on perawin's instructions and are contractually bound to protect it:
- Payment processors (GCash, PayMaya, BPI, BDO, Metrobank, card networks)
- Identity and age verification service providers
- Game software providers whose titles are offered on the Platform
- Cloud hosting and data storage infrastructure providers
- Anti-fraud and cybersecurity service providers
- Customer support platform providers
perawin may be required to disclose your personal data to regulatory and law enforcement authorities in the Philippines, including PAGCOR, the Anti-Money Laundering Council (AMLC), the National Privacy Commission (NPC), and any court of competent jurisdiction, where disclosure is required by applicable law or a valid legal order.
Some of the third-party service providers engaged by perawin — including certain game providers and cloud infrastructure partners — may process or store personal data outside of the Republic of the Philippines. Where such international transfers occur, perawin takes reasonable steps to ensure that the receiving party provides an adequate level of data protection, including through contractual safeguards equivalent to those required under the Philippine Data Privacy Act.
By using the perawin Platform and accepting this Privacy Policy, you acknowledge and consent to the transfer of your personal data to jurisdictions outside the Philippines where necessary for the operation of the Platform, subject to the protections described above.
perawin retains your personal data for as long as is necessary to fulfil the purposes for which it was collected, or as required by applicable Philippine law and regulatory requirements. The following general retention periods apply:
| Data Category | Retention Period |
|---|---|
| Account registration and identity data | Duration of account plus 5 years after account closure |
| Financial transaction records | Minimum 5 years (AMLC and PAGCOR requirement) |
| KYC and verification documents | Duration of account plus 5 years after account closure |
| Game activity and session logs | 3 years from date of activity |
| Customer support communications | 3 years from date of communication |
| Marketing consent records | Until consent is withdrawn, plus 2 years thereafter |
| Responsible gaming records | Duration of any exclusion period plus 5 years |
After the applicable retention period has elapsed, perawin will securely delete or anonymise your personal data unless a longer retention period is required by applicable law.
perawin implements a range of technical and organizational security measures designed to protect your personal data against unauthorized access, accidental loss, alteration, and disclosure:
- 256-bit SSL/TLS encryption for all data transmitted between your browser and perawin's servers
- Encrypted storage of passwords using bcrypt hashing — perawin staff cannot view plaintext passwords
- Encrypted storage of sensitive personal data at rest on secured infrastructure
- Strict role-based access controls limiting staff access to personal data on a need-to-know basis
- Two-factor authentication (2FA) available for member accounts and required for internal administrative access
- Regular security assessments, vulnerability scanning, and penetration testing
- Automated monitoring and alerting for suspicious access patterns and potential data breaches
- Personal data breach notification procedures compliant with NPC requirements
perawin uses cookies and similar tracking technologies to operate the Platform and improve your experience. Cookies are small text files stored on your device when you access the Platform.
| Cookie Type | Purpose | Can Be Disabled? |
|---|---|---|
| Strictly Necessary | Session management, login authentication, security tokens, responsible gaming session controls | No — required for Platform to function |
| Functional | Remembering your language, display preferences, and game lobby layout settings | Yes — via browser settings |
| Analytics | Understanding how members use the Platform to improve features and performance; aggregated and anonymised where possible | Yes — via cookie consent settings |
| Security / Fraud | Device fingerprinting and anomaly detection to protect against account takeover and fraudulent activity | No — required for Platform security |
You can manage cookie preferences through your browser settings. Disabling certain cookies may affect the functionality of the Platform. perawin does not use third-party advertising cookies or share cookie data with ad networks.
Under the Philippine Data Privacy Act of 2012, you have the following rights in respect of your personal data held by perawin. These rights may be exercised by contacting perawin's Data Protection Officer (see Section 16).
To exercise any of these rights, please contact perawin's Data Protection Officer at the address listed in Section 16. perawin will respond to all valid data subject requests within fifteen (15) business days.
The perawin Platform is strictly intended for persons aged 21 years and above. perawin does not knowingly collect, process, or retain personal data from individuals under 21 years of age. If perawin becomes aware that personal data has been collected from a person who does not meet the age requirement, the relevant account will be immediately closed and all associated data will be deleted, except to the extent retention is required by applicable law.
perawin may send you promotional emails, SMS messages, and in-platform notifications about bonuses, new games, and perawin events. This will only occur where you have provided explicit consent to receive such communications at the time of registration or through your account notification settings.
- You may opt out of marketing communications at any time by adjusting your notification preferences in your perawin account settings.
- Transactional communications — such as deposit confirmations, withdrawal notices, security alerts, and account notices — are not marketing communications and cannot be opted out of while your account is active.
- perawin does not share your contact details with third-party marketers for their own marketing purposes.
perawin processes certain personal data specifically in connection with its responsible gaming obligations under PAGCOR's regulatory framework. This includes monitoring gaming patterns that may indicate problem gambling behaviours, administering self-exclusion periods requested by members, and sharing self-exclusion data with PAGCOR's responsible gaming register where required.
Where a member seeks support through perawin's responsible gaming tools — including setting deposit limits, loss limits, or requesting self-exclusion — the data associated with those interactions is processed on the legal basis of legal obligation and legitimate interest in player protection, and is retained for a minimum of five years following the end of any exclusion period to prevent circumvention.
perawin reserves the right to amend this Privacy Policy at any time to reflect changes in applicable law, PAGCOR regulatory requirements, our data processing practices, or the features and services available on the Platform.
When material changes are made to this Policy, perawin will notify registered members via their registered email address and by displaying a prominent notice on the Platform. The "Last updated" date at the top of this Policy will be revised accordingly. Your continued use of the Platform after the effective date of any revised Policy constitutes your acceptance of the changes.
We encourage you to review this Privacy Policy periodically. The current version will always be available at https://perawin.win/privacy-policy.
perawin has designated a Data Protection Officer (DPO) in accordance with the requirements of the Philippine Data Privacy Act. If you have any questions, concerns, or requests regarding this Privacy Policy or the processing of your personal data, please contact our DPO through the following channels:
- Live Chat: Available 24/7 within your logged-in perawin account. Fastest channel for general account-related data queries.
- Email: [email protected] — subject line "Data Privacy Request." The DPO will acknowledge your request within 48 hours and respond fully within 15 business days.
- Jurisdiction: This Policy is governed by the laws of the Republic of the Philippines. Complaints not resolved by perawin may be escalated to the National Privacy Commission (NPC) of the Philippines.