Summary: pluss77 collects personal data to operate your gaming account, comply with PAGCOR regulatory obligations, process payments, and communicate with you. We do not sell your personal data. You retain rights to access, correct, and delete your data under Republic Act No. 10173 (Data Privacy Act of 2012). This policy applies to all users of the pluss77 platform at pluss77.club, including registered players and site visitors.
Who We Are — Data Controller
pluss77 ("pluss77," "we," "us," or "our") is the operator of the online gaming platform accessible at pluss77.club, operating under a licence issued by the Philippine Amusement and Gaming Corporation (PAGCOR). For the purposes of the Republic Act No. 10173, otherwise known as the Data Privacy Act of 2012 (DPA), and its Implementing Rules and Regulations, pluss77 acts as the Personal Information Controller in respect of all personal data collected through and in connection with the pluss77 Platform.
As a Personal Information Controller, pluss77 determines the purposes for which and the manner in which personal data from players and site visitors is processed. Where pluss77 engages third-party service providers to process data on its behalf — such as payment processors, KYC verification services, and game content providers — those parties act as Personal Information Processors and are contractually bound to process data only in accordance with pluss77's instructions and the requirements of the DPA.
Scope & Application of This Policy
This Privacy Policy applies to all personal data collected, processed, stored, or shared by pluss77 in connection with:
- The registration and maintenance of player accounts on the pluss77 Platform;
- All deposits, withdrawals, and financial transactions processed through pluss77;
- All gaming activity conducted on the Platform, including slots, live casino, sports betting, bingo, and instant games;
- KYC (Know Your Customer) identity verification processes;
- Customer support communications via live chat, email, and other channels;
- Marketing and promotional communications sent by pluss77 to consenting players;
- Passive data collection through cookies, analytics tools, and server logs when any person browses the pluss77 website.
This Policy should be read in conjunction with pluss77's Terms & Conditions and Responsible Gaming Policy, both of which are incorporated herein by reference.
Personal Data We Collect
pluss77 collects the following categories of personal data from players and site visitors. Not all categories apply equally to all users — the scope of data collected depends on the depth of the user's engagement with the Platform.
| Data Category | Specific Data Points | Collected When |
|---|---|---|
| Identity Data | Full legal name, date of birth, government-issued ID number and copy, selfie photograph | Registration; KYC verification |
| Contact Data | Philippine mobile number (+63), email address | Registration |
| Financial Data | GCash or Maya account number (first/last digits only retained), bank account name and reference, transaction amounts, deposit and withdrawal history | Deposit / withdrawal processing |
| Gaming Activity Data | Games played, bet amounts and outcomes, session durations, bonus claims and wagering history, wins and losses | All gaming sessions |
| Technical Data | IP address, device type and model, operating system, browser type and version, mobile network carrier | Any Platform visit (logged automatically) |
| Usage Data | Pages visited, clicks, navigation paths, feature interactions, time spent on Platform | Any Platform visit (via analytics) |
| Communications Data | Live chat transcripts, email correspondence, support ticket content | Customer support interactions |
| Responsible Gaming Data | Self-exclusion requests, deposit and loss limit settings, session time configurations, player-reported problem gambling disclosures | Responsible gaming tool usage |
Sensitive Personal Information: pluss77 may collect government-issued ID documents during KYC verification, which may contain sensitive personal information under the DPA (including national ID numbers and facial images). This data is collected solely for identity verification and regulatory compliance purposes and is handled with the heightened protections applicable to sensitive personal information under Philippine law.
How We Collect Personal Data
pluss77 collects personal data through the following means:
- Directly from you: Information you provide when completing the registration form, submitting KYC documents, making deposits or withdrawals, contacting support, or updating your account settings.
- Automatically through the Platform: Technical and usage data captured automatically via server logs, cookies, and analytics tools when you visit pluss77.club, regardless of whether you hold a registered account.
- From payment service providers: Transaction confirmation data and payment reference information received from GCash, Maya, BPI, BDO, and other integrated payment processors when you initiate a deposit or withdrawal.
- From identity verification services: Result data from third-party KYC verification providers engaged to assist in confirming the identity and age of players submitting verification documents.
- From regulatory authorities: Information received from PAGCOR or other Philippine government agencies as required by applicable law, including in response to regulatory inquiries or enforcement actions.
Legal Basis for Processing
pluss77 processes personal data on the following legal bases as recognised under the Data Privacy Act of 2012 and its Implementing Rules and Regulations:
- Contractual necessity: Processing is necessary for the performance of the contract between pluss77 and the registered player — specifically, the operation of the player's account, processing of wagers and game outcomes, and processing of deposits and withdrawals.
- Legal obligation: Processing is required to comply with pluss77's legal and regulatory obligations under PAGCOR regulations, the Anti-Money Laundering Act (AMLA) as amended, the Data Privacy Act of 2012, and other applicable Philippine laws. This includes KYC verification, transaction monitoring, and record-keeping obligations.
- Legitimate interests: Processing is necessary for legitimate interests pursued by pluss77, including fraud prevention, platform security, responsible gaming monitoring, and business analytics — provided such interests are not overridden by the player's fundamental rights.
- Consent: Where pluss77 relies on consent as the legal basis for processing — primarily in relation to direct marketing communications — we will obtain your express consent in advance. You may withdraw consent at any time by following the opt-out procedures described in Section 14 of this Policy.
How We Use Your Personal Data
pluss77 uses the personal data it collects for the following purposes:
- Account administration: Creating, managing, verifying, and securing your pluss77 player account, including processing login authentication and two-factor verification requests.
- Provision of gaming services: Operating and delivering all games, sports betting markets, and other features available on the Platform; recording game histories and account activity.
- Payment processing: Processing deposits from and withdrawals to your registered payment methods; reconciling transaction records; managing GCash, Maya, and bank transfer integrations.
- Identity verification and KYC compliance: Verifying that players meet the minimum age requirement of 21 years and satisfy all eligibility requirements under PAGCOR regulations and applicable Philippine law.
- Anti-money laundering (AML) compliance: Monitoring transactions and account activity for patterns indicative of money laundering, terrorist financing, or other financial crimes, as required by the Anti-Money Laundering Act and PAGCOR directives.
- Responsible gaming: Monitoring gaming patterns to identify players who may be exhibiting signs of problem gambling; administering self-exclusion, deposit limit, and loss limit tools; maintaining exclusion registers.
- Customer support: Responding to account queries, complaints, and technical issues submitted through live chat, email, or other support channels.
- Platform security and fraud prevention: Detecting and investigating suspicious account activity, unauthorised access attempts, bonus abuse, multi-accounting, and other prohibited conduct.
- Marketing communications: Sending promotional offers, bonus notifications, and platform updates to players who have consented to receive such communications.
- Platform improvement: Analysing aggregated usage and gaming data to improve the platform's design, game selection, and player experience.
- Legal proceedings and regulatory compliance: Retaining records for the purposes of legal proceedings, regulatory audits, or as otherwise required by applicable law.
Data Sharing & Disclosure
pluss77 does not sell, rent, or trade personal data to third parties for their own marketing purposes. We share personal data only in the following limited circumstances and with the categories of recipients described below:
- Payment processors: GCash, Maya, BPI, BDO, UnionBank, 7-Eleven (CLiQQ), Coins.ph, and USDT processing providers receive transactional data necessary to process your deposits and withdrawals. Each payment processor operates under its own privacy policy and applicable regulatory requirements.
- KYC and identity verification services: Third-party identity verification providers receive identity documents and biometric data submitted during KYC verification, solely for the purpose of verifying identity and age on pluss77's behalf.
- Game content providers: JILI, Pragmatic Play, PG Soft, and other game providers integrated into the pluss77 Platform receive game session data (including bet amounts and outcomes) necessary to operate their games. They do not receive unnecessary personal identification data.
- IT infrastructure and cloud services: pluss77 uses cloud infrastructure and hosting providers to operate the Platform. These providers may process technical and operational data as part of providing infrastructure services.
- Regulatory and law enforcement authorities: PAGCOR, the Anti-Money Laundering Council (AMLC), the National Privacy Commission (NPC), courts, and law enforcement agencies in the Philippines, as required by applicable law, court order, or regulatory directive.
- Professional advisers: Legal, audit, accounting, and compliance professionals engaged by pluss77, subject to professional confidentiality obligations.
Where personal data is shared with third-party processors, pluss77 executes Data Processing Agreements that bind those processors to process data only in accordance with pluss77's instructions and the requirements of the Data Privacy Act of 2012.
International Data Transfers
Some of pluss77's third-party service providers — including certain game content providers and cloud infrastructure providers — may be located outside the Philippines. Where personal data is transferred to a country or territory outside the Philippines, pluss77 ensures that appropriate safeguards are in place to protect the transferred data in accordance with Section 21 of the Data Privacy Act of 2012 and the relevant NPC Circulars governing cross-border data transfers.
Such safeguards include, where applicable: contractual clauses approved by the National Privacy Commission, binding corporate rules, or transfer to jurisdictions that the NPC has recognised as providing an adequate level of protection for personal data. Players may request information about the specific safeguards applied to international transfers of their data by contacting the pluss77 Data Privacy Officer.
Data Retention Periods
pluss77 retains personal data only for as long as necessary for the purposes for which it was collected, including the fulfilment of any legal, regulatory, or reporting requirements. The following retention periods apply:
| Data Category | Retention Period | Basis |
|---|---|---|
| Account and identity data | 5 years from account closure or last activity | PAGCOR regulatory requirements; AMLA record-keeping |
| Financial transaction records | 5 years from transaction date | Anti-Money Laundering Act record-keeping obligations |
| KYC verification documents | 5 years from account closure | PAGCOR KYC requirements; AMLA compliance |
| Gaming activity data | 2 years from activity date (aggregated thereafter) | PAGCOR audit requirements; dispute resolution |
| Customer support records | 2 years from resolution of the relevant matter | Dispute resolution; quality management |
| Responsible gaming records | Duration of exclusion period plus 5 years | PAGCOR responsible gaming compliance |
| Marketing consent records | Until consent is withdrawn, plus 2 years | Proof of consent compliance under DPA |
| Technical/server logs | 90 days | Security monitoring; fraud detection |
At the end of the applicable retention period, personal data is securely deleted or anonymised in accordance with pluss77's data disposal procedures.
Cookies & Tracking Technologies
pluss77 uses cookies and similar tracking technologies on the Platform to enable core functionality, improve performance, and — where consent has been obtained — deliver relevant content and analytics. The following categories of cookies are used:
- Strictly necessary cookies: Required for the Platform to function. These include session management cookies that keep you logged in during a gaming session, security tokens, and preference storage. These cookies cannot be disabled without impairing Platform functionality.
- Performance and analytics cookies: Used to collect aggregated data about how visitors use the Platform — including pages visited, session duration, and error occurrences — to help pluss77 improve the Platform. This data is aggregated and does not identify individual players.
- Functional cookies: Store your Platform preferences, such as language settings and game display options, to personalise your experience across sessions.
Most modern browsers allow you to manage or block cookies through browser settings. Disabling strictly necessary cookies will impair your ability to use core Platform features, including the ability to remain logged in to your pluss77 account. pluss77 does not use cookies to track your activity on third-party websites not connected to the pluss77 Platform.
Security Measures
pluss77 implements technical, organisational, and administrative security measures designed to protect personal data against unauthorised access, disclosure, alteration, destruction, and accidental loss. These measures include, but are not limited to:
- Encryption in transit: All data transmitted between your device and pluss77 servers is encrypted using TLS 1.2 or higher with 256-bit encryption. This applies to account login, financial transactions, and all API communications.
- Encryption at rest: Sensitive data stored on pluss77 systems — including KYC documents and financial records — is encrypted at rest using industry-standard symmetric encryption.
- Access controls: Access to personal data within pluss77's systems is restricted on a need-to-know basis and enforced through role-based access controls and multi-factor authentication for administrative accounts.
- Data minimisation: pluss77 collects and retains only the personal data necessary for the specific purpose for which it is collected, and avoids retention of raw sensitive data beyond the minimum required period.
- Regular security assessments: pluss77 conducts periodic security reviews, vulnerability assessments, and penetration testing on Platform infrastructure.
- Staff training: Personnel with access to personal data receive data privacy and security training commensurate with their role and level of data access.
Your responsibility: pluss77's security measures protect your data at the platform level. You also have a role in keeping your account secure — use a strong, unique password for your pluss77 account, enable two-factor authentication, never share your login credentials or OTP codes, and ensure you log out after each session on shared devices. See our Login Guide for detailed security tips.
Your Data Rights Under Philippine Law
As a data subject under the Data Privacy Act of 2012, you hold the following rights in respect of personal data that pluss77 holds about you. You may exercise any of these rights at any time by contacting the pluss77 Data Privacy Officer using the details in Section 18.
pluss77 will respond to data rights requests within thirty (30) days of receipt of a valid, verified request, as required by the Data Privacy Act and NPC regulations. In complex cases, this period may be extended by a further thirty (30) days, with written notification provided to the requestor.
Identity verification is required before pluss77 processes any data rights request. This is to protect against fraudulent requests from parties who are not the data subject. Requests must be submitted in writing to the Data Privacy Officer contact detailed in Section 18.
Children & Minors
The pluss77 Platform is strictly intended for adults aged 21 years and older, as required under PAGCOR regulations governing online gaming in the Philippines. pluss77 does not knowingly collect personal data from individuals under the age of 21.
If pluss77 becomes aware that personal data has been collected from an individual who is under 21 years of age, the relevant account will be immediately suspended, all collected personal data will be deleted as soon as practicable, and the matter will be reported to PAGCOR as required. Any funds deposited by an underage player will be handled in accordance with PAGCOR's directives on underage account closure.
If you believe that a minor has registered on the pluss77 Platform using false age information, please contact pluss77 support immediately via live chat or email at [email protected].
Marketing & Communications
pluss77 sends promotional and informational communications to players who have provided consent to receive them. These may include bonus and promotion notifications, game updates, and platform news delivered via SMS and email.
Transactional communications — including account security alerts, deposit and withdrawal confirmations, OTP verification codes, KYC status updates, and responses to support requests — are sent as a necessary part of operating your pluss77 account. These communications do not require additional consent and cannot be fully opted out of while your account is active, as they are required for the security and administration of your account.
Marketing communications are sent only where you have provided express opt-in consent. You may withdraw consent to marketing communications at any time by:
- Clicking the "Unsubscribe" link in any pluss77 marketing email;
- Adjusting your communication preferences in your pluss77 Account Settings;
- Contacting pluss77 support via live chat or email with a request to unsubscribe.
Withdrawal of marketing consent will take effect within 5 business days. This will not affect the lawfulness of any processing that occurred before consent was withdrawn.
Third-Party Links
The pluss77 Platform may contain references to third-party services, including game content providers and payment processors, whose interfaces may be displayed within the pluss77 environment. pluss77 is not responsible for the privacy practices of third-party services. Each third party operates under its own privacy policy, which governs the personal data those third parties collect directly from you. pluss77 does not control the data practices of third-party providers integrated into the Platform.
Data Breach Notification
In the event of a personal data breach that is likely to result in a real risk of serious harm to affected data subjects, pluss77 will:
- Notify the National Privacy Commission (NPC) within seventy-two (72) hours of becoming aware of the breach, in accordance with NPC Circular 16-03 and subsequent circulars on mandatory breach notification;
- Notify affected data subjects without undue delay where the breach is likely to result in a high risk to their rights and freedoms, providing information about the nature of the breach, the likely consequences, and the measures taken to address it;
- Document all personal data breaches in pluss77's internal breach register, including breaches that do not require NPC notification, in accordance with the DPA's accountability requirements.
If you suspect that your pluss77 account has been subject to unauthorised access or that your personal data may have been compromised, contact pluss77 support immediately via live chat. Change your account password immediately and review your recent account activity for any unauthorised transactions.
Updates to This Privacy Policy
pluss77 reserves the right to update or amend this Privacy Policy from time to time to reflect changes in applicable law, NPC guidance, PAGCOR requirements, or pluss77's data processing practices. The "Last Updated" date at the top of this Policy reflects the date of the most recent revision.
Where a revision materially affects how pluss77 processes your personal data or the rights available to you, pluss77 will notify registered players by email or via a prominent notice on the Platform at least seven (7) days before the revised Policy takes effect. Your continued use of the pluss77 Platform following the effective date of any revision constitutes your acceptance of the updated Policy.
The current version of this Privacy Policy is always accessible at pluss77.club/privacy-policy.
Data Privacy Officer & Contact
pluss77 has designated a Data Privacy Officer (DPO) responsible for overseeing the Platform's compliance with the Data Privacy Act of 2012 and this Privacy Policy. The DPO serves as the primary point of contact for data subjects exercising their rights under the DPA and for regulatory communications from the National Privacy Commission.
To exercise your data rights, raise a privacy concern, request information about pluss77's data processing practices, or report a suspected data breach affecting your personal data, please contact the pluss77 Data Privacy Officer through the following channels:
- Email (Data Privacy matters): [email protected] — clearly state "Data Privacy Request" or "DPO Enquiry" in the subject line. Response target: within 4 hours for general queries; formal rights requests addressed within 30 days.
- Live Chat: Available 24/7 on the pluss77 Platform. For data rights requests requiring formal written handling, the live chat team will direct you to submit your request in writing by email.
If you are not satisfied with pluss77's response to a data rights request or privacy concern, you have the right to escalate the matter to the National Privacy Commission of the Philippines (NPC) at privacy.gov.ph. The NPC is the independent regulatory authority responsible for enforcing the Data Privacy Act of 2012 and handling complaints from Filipino data subjects.