At 22win, your privacy is not an afterthought. This Privacy Policy explains exactly what personal data we collect from Filipino players, how we use and protect that data, who we share it with, and what rights you have under applicable Philippine privacy law.
Our Privacy Commitments
These cards summarise 22win's six core commitments to the privacy and security of every Filipino player on the platform. The full legal text of each commitment is detailed in the numbered sections further down this page.
Every data exchange between your device and the 22win platform — login credentials, transaction requests, and game data — is protected using 256-bit SSL encryption, the same standard used by major Philippine banks including BPI and BDO.
22win collects only the personal data that is strictly necessary to operate your account, process GCash and PayMaya transactions, meet PAGCOR regulatory requirements, and provide customer support. We do not collect data for its own sake.
22win does not sell, rent, or trade your personal data to any third party for commercial marketing purposes. Data shared with third parties is limited to what is required for payment processing, identity verification, regulatory compliance, and platform operations.
As a Filipino data subject, you have enforceable rights under the Data Privacy Act of 2012 — including the right to access, correct, erase, and port your personal data. 22win provides clear mechanisms to exercise each of these rights directly through your account or via our support team.
22win does not store your GCash or PayMaya login credentials. Payment transactions are handled through tokenised, PCI-DSS compliant payment gateways. Your actual e-wallet credentials never pass through or are stored on 22win's own servers at any point.
22win retains personal data only for as long as necessary to fulfil the purposes for which it was collected, or as required by applicable Philippine law and PAGCOR regulations. Data that is no longer required for these purposes is securely deleted or anonymised.
This Privacy Policy ("Policy") describes how 22win ("22win", "we", "us", or "our") collects, uses, stores, discloses, and protects the personal data of individuals ("you", "your", or "Player") who access or use the 22win online gaming platform at 22win.lat (the "Platform").
22win is committed to protecting the privacy and personal data of all Filipino players in accordance with the Data Privacy Act of 2012 (Republic Act No. 10173) and its implementing rules and regulations, as enforced by the National Privacy Commission (NPC) of the Philippines. This Policy also reflects best practices in online gaming data governance aligned with PAGCOR's regulatory framework.
By registering an account on the 22win Platform, completing a deposit or withdrawal transaction, or otherwise accessing any feature of the Platform, you acknowledge that you have read, understood, and consented to the data practices described in this Policy.
This Policy should be read together with our Terms & Conditions, which govern your use of the 22win Platform. In the event of any conflict between this Policy and the Terms & Conditions on a privacy-related matter, this Policy shall prevail.
For the purposes of the Data Privacy Act of 2012 and this Policy, 22win is the data controller responsible for the personal data collected through the Platform. As data controller, 22win determines the purposes and means by which personal data is processed.
22win has appointed a Data Protection Officer (DPO) who is responsible for overseeing 22win's compliance with applicable data privacy laws and for serving as the primary point of contact for Players exercising their data rights. Contact details for the DPO are provided in Section 15 of this Policy.
22win collects the following categories of personal data from Players in the course of operating the Platform:
| Category | Examples | Primary Purpose |
|---|---|---|
| Identity & Contact | Name, DOB, email, mobile | Account creation, KYC, age verification |
| Account & Gameplay | Game history, bets, VIP status | Platform operations, fair play, loyalty |
| Financial | Deposits, withdrawals, GCash ID | Payment processing, AML compliance |
| Technical & Device | IP address, device type, session logs | Security, fraud detection, analytics |
| Communications | Chat logs, support tickets | Customer support, dispute resolution |
22win collects personal data through the following channels and mechanisms:
22win processes your personal data for the following specific purposes, each supported by one or more legal bases under the Data Privacy Act of 2012:
To create and maintain your 22win account, process deposits and withdrawals via GCash and PayMaya, provide access to the game library, award bonuses and VIP rewards, and deliver customer support — all necessary to perform the services described in the Terms & Conditions.
To fulfil 22win's obligations under applicable Philippine law and PAGCOR regulations — including age verification (21+ compliance), anti-money laundering (AML) screening, Know Your Customer (KYC) procedures, responsible gaming record-keeping, and reporting obligations to PAGCOR and law enforcement authorities where required by law.
To detect, prevent, and investigate fraud, account abuse, money laundering, and other prohibited conduct; to maintain and improve Platform security; to conduct internal analytics for service improvement; and to manage responsible gaming risk assessments — all conducted with appropriate safeguards and balanced against your privacy interests.
Where your consent has been separately obtained — for example, for receipt of promotional emails or SMS marketing communications from 22win — personal data is processed on the basis of that consent, which you may withdraw at any time through your account notification settings or by contacting support.
22win does not sell, rent, or trade your personal data to any third party for commercial purposes. Personal data is shared with third parties only in the following limited and controlled circumstances:
22win engages carefully selected third-party service providers to assist in operating the Platform, including: payment processors (GCash, PayMaya, bank transfer partners), identity verification (KYC) providers, cloud infrastructure and hosting providers, customer support platform providers, and analytics service providers. All service providers are contractually bound to process personal data only on 22win's documented instructions and to implement appropriate data security measures.
22win may disclose personal data to PAGCOR, the National Privacy Commission, the Anti-Money Laundering Council (AMLC), the Philippine National Police, and other competent regulatory or law enforcement authorities where required by applicable Philippine law, a valid court order, or a lawful regulatory directive.
Game studios and content providers whose games are available on the 22win Platform may receive anonymised or aggregated gameplay data for the purposes of game performance monitoring and certification compliance. Individual Player data is not shared with game providers beyond what is technically necessary for the game session to function.
In the event of a merger, acquisition, restructuring, or sale of all or part of 22win's business, Player personal data may be transferred to the relevant successor entity, subject to that entity assuming the obligations of this Privacy Policy toward existing Players.
22win takes a deliberate approach to payment data that minimises the sensitive financial information stored on its own servers. When you make a deposit or withdrawal using GCash, PayMaya, or a linked bank account, your actual e-wallet login credentials and banking passwords are never transmitted to or stored by 22win. Payment transactions are processed through PCI-DSS compliant payment gateways via a tokenisation model.
What this means in practice: 22win receives only a transaction confirmation token and reference number from the payment provider. Your GCash account credentials, PayMaya PIN, and bank account passwords remain entirely within the respective payment provider's system at all times. Only the linked account identifier (e.g., your registered GCash mobile number or the last four digits of a linked bank account) is stored in your 22win profile for the purpose of routing future withdrawals.
For Visa and Mastercard transactions, payment card details are tokenised by the card payment gateway and 22win stores only the token reference, card type, and last four digits. Full card numbers are never stored on 22win infrastructure.
Cookies are small text files placed on your device when you access a website. 22win uses cookies and similar browser storage technologies to maintain your session, remember your preferences, and support the secure operation of the Platform.
You may adjust your browser settings to refuse or delete non-essential cookies at any time. Note that disabling strictly necessary cookies will affect the functionality of the Platform and may prevent you from accessing your account. Instructions for managing cookies are available in your browser's help documentation.
22win implements a layered approach to data security designed to protect your personal data against unauthorised access, alteration, disclosure, or destruction. The key security measures in place include:
While 22win takes all reasonable precautions, no digital system can guarantee absolute security. In the event of a personal data breach that poses a risk to Player rights, 22win will notify affected Players and the National Privacy Commission in accordance with NPC Circular 16-03 and applicable breach notification obligations.
22win retains personal data for the following periods, after which data is securely deleted or irreversibly anonymised:
| Data Category | Retention Period | Basis |
|---|---|---|
| Account identity & KYC documents | 5 years after account closure | AMLC and PAGCOR regulatory requirements |
| Financial transaction records | 5 years from transaction date | Anti-money laundering obligations (RA 9160) |
| Game session and betting history | 3 years from account closure | PAGCOR audit trail requirements |
| Customer support communications | 2 years from last interaction | Dispute resolution and contract performance |
| Marketing consent records | Until consent is withdrawn + 1 year | Evidence of lawful processing basis |
| Technical / session log data | 90 days from collection | Security monitoring and fraud detection |
| Self-exclusion records | 10 years from exclusion date | Responsible gaming compliance |
Where retention beyond the standard periods is required for ongoing legal proceedings, regulatory investigations, or unresolved disputes, data will be retained for the duration of such proceedings plus a reasonable additional period.
As a data subject under the Data Privacy Act of 2012 (RA 10173) of the Philippines, you have the following rights in respect of your personal data held by 22win. To exercise any of these rights, contact our support team or Data Protection Officer using the details in Section 15.
Request a copy of the personal data 22win holds about you, including information on how it is processed. Requests are processed within 30 days.
Request correction of inaccurate or incomplete personal data held in your 22win account. Basic profile updates may be made directly from your account settings.
Request deletion of your personal data where it is no longer necessary for the purposes for which it was collected, subject to 22win's legal retention obligations under Philippine law.
Request a structured, machine-readable copy of the personal data you have provided to 22win, which may be transmitted to another data controller of your choosing.
Object to or request restriction of processing of your personal data in certain circumstances, including processing based on legitimate interests or for direct marketing purposes.
Where processing is based on consent (e.g., marketing communications), withdraw that consent at any time without affecting the lawfulness of processing before the withdrawal.
22win will respond to rights requests within 30 calendar days of receipt. In complex cases, this period may be extended by a further 30 days with notification. If you are unsatisfied with how 22win handles your request, you have the right to lodge a complaint with the National Privacy Commission of the Philippines.
The 22win Platform and all its services are strictly restricted to individuals who are 21 years of age or older, in compliance with PAGCOR's age requirements for online gaming in the Philippines. 22win does not knowingly collect personal data from individuals under 21 years of age.
Age verification is conducted at account registration and may be repeated through documentary KYC verification at any time. Where 22win discovers that an account has been created by or is being used by a person under 21, the account will be immediately suspended, all associated funds will be quarantined, and any winnings may be forfeited in accordance with the 22win Terms & Conditions.
If you are a parent or guardian and believe your child or ward has created an account on the 22win Platform, please contact our support team immediately so that the account can be identified, closed, and the matter properly handled.
22win's primary data infrastructure is located in Southeast Asia. In the course of operating the Platform, some personal data may be processed by service providers located outside the Philippines — for example, cloud infrastructure providers or international game content studios.
Where personal data is transferred outside the Philippines, 22win takes appropriate steps to ensure that the transfer is lawful and that the recipient provides an adequate level of data protection consistent with the requirements of the Data Privacy Act of 2012. These steps may include the use of standard contractual clauses approved by the National Privacy Commission, or reliance on the recipient's certification under a recognised data protection framework.
22win reserves the right to update this Privacy Policy at any time to reflect changes in data practices, new regulatory requirements, or platform developments. The revised Policy will be published on this page with an updated "Last Updated" date.
Where a material change is made to the Policy — such as a new category of data collection, a new sharing arrangement, or a change to Player rights — 22win will notify registered Players via email or in-platform notification at least 14 days before the change takes effect, except where an immediate change is required by law.
Your continued use of the 22win Platform after the effective date of any revised Policy constitutes your acceptance of the updated terms. If you do not agree with the revised Policy, you should cease using the Platform and may request account closure in accordance with the Terms & Conditions.
For any questions, concerns, or requests relating to this Privacy Policy or the processing of your personal data by 22win, please contact us using the following details:
When contacting the DPO regarding a data rights request, please include: your registered email address, the specific right you wish to exercise (access, erasure, portability, etc.), and sufficient information to allow us to identify your account. This helps us handle your request promptly and accurately.
22win acknowledges all data rights requests within 5 business days of receipt and provides a substantive response within 30 calendar days, as required by RA 10173.