ditowin is committed to protecting the personal data of every Filipino player on our platform. This Privacy Policy explains what data we collect, why we collect it, how we use it, and the rights you have over your information under Philippine law.
Six concrete commitments ditowin makes to every Filipino player regarding the handling of personal information.
ditowin collects only the personal data necessary to operate your account, process your transactions, and comply with regulatory requirements. We do not collect data for data's sake.
All personal data stored by ditowin is protected using industry-standard encryption. Data in transit between your device and our servers is protected by TLS. Passwords are stored as salted cryptographic hashes — never in plain text.
ditowin does not sell your personal data to third parties. Data is shared only with service providers essential to platform operations (payment processors, KYC verification providers, game studios) and only to the extent necessary.
As a Filipino data subject under Republic Act No. 10173 (Data Privacy Act of 2012), you have specific rights over your personal data. ditowin provides clear, accessible mechanisms to exercise each of those rights.
ditowin does not retain personal data indefinitely. Retention periods are defined by the purpose of collection and by applicable Philippine law. Account data is deleted or anonymised upon account closure in accordance with our retention schedule.
ditowin's data practices align with both PAGCOR's player data requirements and the National Privacy Commission's (NPC) guidelines under the Data Privacy Act of 2012. Our Data Protection Officer oversees ongoing compliance.
This Privacy Policy ("Policy") describes how ditowin ("Company," "Platform," "we," "us," or "our"), accessible at ditowin.co, collects, processes, stores, and protects the personal data of users ("Player," "Data Subject," or "you") in connection with the provision of online gaming and betting services. This Policy is issued in compliance with Republic Act No. 10173, otherwise known as the Data Privacy Act of 2012 of the Philippines, and its Implementing Rules and Regulations. By registering an account on ditowin or continuing to use the Platform after the effective date of this Policy, you acknowledge that you have read and understood its contents.
This Policy applies to all personal data collected by ditowin in connection with the operation of the ditowin Platform, including but not limited to data collected during account registration, identity verification (KYC), deposit and withdrawal processing, gameplay activity, customer support interactions, and marketing communications.
This Policy applies to all Players registered on ditowin, regardless of whether they access the Platform from Metro Manila, Cebu, Davao, Quezon City, Makati, or any other location in the Philippines. It applies equally to access via desktop browser and mobile browser. All data processing activities described in this Policy are conducted in respect of natural persons only — corporate or legal entity accounts are not offered on the ditowin Platform.
This Policy does not apply to the privacy practices of third-party websites linked from the ditowin Platform, including payment processors, game studio portals, or any other external service. We encourage you to review the privacy policies of any third-party services you interact with in connection with your ditowin account.
For the purposes of the Data Privacy Act of 2012, ditowin acts as the Personal Information Controller in respect of the personal data collected from Players through the ditowin Platform at ditowin.co.
ditowin is responsible for determining the purposes and means of processing personal data collected through the Platform. Where ditowin engages third-party service providers to process personal data on its behalf, those providers act as Personal Information Processors and are bound by written data processing agreements that require them to maintain confidentiality and implement appropriate security measures.
Data Protection Officer: ditowin has designated a Data Protection Officer (DPO) responsible for overseeing compliance with this Policy and with the Data Privacy Act. Players may contact the DPO via the support email set out in Section 15 of this Policy, marking the communication for the attention of the Data Protection Officer.
ditowin collects the following categories of personal data from Players. Collection occurs only to the extent necessary for the specific purposes identified in Section 5 of this Policy:
| Data Category | Specific Data Elements | Collection Point |
|---|---|---|
| Identity Data | Full legal name, date of birth, nationality, gender | Registration & KYC |
| Contact Data | Email address, Philippine mobile number | Registration |
| Verification Documents | Government-issued Philippine ID (front and back), selfie verification image | KYC process |
| Financial Data | GCash account reference, PayMaya reference, bank account name and number (BPI, BDO, Metrobank), USDT wallet address | Deposit / Withdrawal |
| Transaction Data | Deposit history, withdrawal history, bet records, win/loss records, bonus usage | Platform activity |
| Technical Data | IP address, device type and OS, browser type and version, session identifiers, login timestamps | Automated collection |
| Behavioural Data | Game preferences, session duration, navigation paths, feature interactions | Platform activity |
| Communications Data | Live chat transcripts, support ticket contents, email correspondence | Support interactions |
ditowin does not collect sensitive personal information as defined in Section 3(l) of the Data Privacy Act (e.g., health data, political affiliation, religious belief) unless specifically required by applicable law or regulatory directive.
ditowin collects personal data through the following means:
Under the Data Privacy Act of 2012, ditowin processes personal data on the following legal bases:
ditowin uses the personal data collected from Players for the following specific purposes:
7.1 Service Providers. ditowin shares personal data with carefully selected third-party service providers who process data on our behalf solely for the purposes described in this Policy. These providers include:
All service providers are required to process personal data only on ditowin's documented instructions, to maintain appropriate security measures, and to delete or return data upon termination of the service relationship.
7.2 Regulatory Authorities. ditowin will disclose personal data to competent Philippine government authorities — including PAGCOR, the Anti-Money Laundering Council (AMLC), and the National Privacy Commission (NPC) — where required to do so by applicable law, court order, or regulatory direction.
7.3 No Sale of Data. ditowin does not sell, rent, or otherwise transfer personal data to third parties for their own marketing or commercial purposes under any circumstances.
Third-Party Privacy: When ditowin shares data with service providers, those providers are contractually bound by data processing agreements. We conduct due diligence on the security and compliance practices of service providers before engagement and on a periodic basis thereafter.
ditowin uses cookies and similar technologies on the Platform. A cookie is a small data file placed on your device by a website. ditowin uses the following categories of cookies:
You may manage cookie settings through your browser's privacy controls. Note that disabling strictly necessary cookies will prevent you from logging in to your ditowin account.
ditowin retains personal data only for as long as necessary to fulfil the purposes described in this Policy, or as required by applicable Philippine law. The following retention periods apply:
| Data Category | Retention Period | Basis |
|---|---|---|
| Account and identity data | 5 years after account closure | AMLC regulatory requirement |
| KYC documents | 5 years after account closure | AMLC / PAGCOR requirement |
| Transaction records | 5 years after the date of transaction | AMLC regulatory requirement |
| Support communications | 3 years after case closure | Legitimate interests (dispute resolution) |
| Technical / session logs | 12 months from collection | Security monitoring |
| Marketing consent records | Until consent is withdrawn + 1 year | Proof of consent |
Upon expiry of the applicable retention period, personal data is securely deleted or anonymised such that it can no longer be attributed to an identifiable individual. Anonymised data may be retained indefinitely for statistical and platform improvement purposes.
ditowin implements a comprehensive set of technical and organisational security measures to protect personal data against unauthorised access, loss, destruction, or alteration. Key measures include:
While ditowin implements robust security measures, no system is completely immune to security risks. Players are encouraged to use strong, unique passwords for their ditowin accounts and to enable two-factor authentication from their account security settings.
Under Republic Act No. 10173 (Data Privacy Act of 2012), Filipino data subjects have the following rights in respect of their personal data. ditowin provides mechanisms to exercise each of these rights through your account dashboard or via the support team:
Request a copy of the personal data ditowin holds about you and information about how it is processed.
Request correction of inaccurate or incomplete personal data. Some corrections require re-submission of verification documents.
Request deletion of personal data where there is no longer a lawful basis for its retention. Note: legal retention obligations may limit the scope of erasure.
Object to specific types of processing — in particular, direct marketing communications. Marketing opt-out is available from your account settings.
Request suspension of processing of your personal data pending resolution of an objection or inaccuracy dispute.
Request your personal data in a structured, machine-readable format for transfer to another service provider, where technically feasible.
Seek compensation for damages suffered as a result of inaccurate, incomplete, or unauthorised use of your personal data by ditowin.
File a complaint with the National Privacy Commission (NPC) of the Philippines if you believe ditowin has violated your data rights.
To exercise any of the above rights, contact ditowin's Data Protection Officer via the support email set out in Section 15. ditowin will respond to data rights requests within thirty (30) days of receipt. We may request proof of identity before processing a data rights request.
The ditowin Platform is strictly intended for persons aged 21 years and above. ditowin does not knowingly collect or process the personal data of persons under the age of 21. Account registration by persons under 21 is prohibited, and ditowin conducts age verification as part of the KYC process for all accounts.
If ditowin becomes aware that personal data of a person under 21 has been collected — whether through fraudulent registration by the minor or a third party — that data will be deleted and the associated account will be permanently closed in accordance with the ditowin Terms & Conditions.
21+ Only. Gambling services on ditowin are restricted to players aged 21 and above in compliance with PAGCOR regulations. If you are aware of a person under 21 accessing the Platform, please report it to the ditowin support team immediately.
Some of the third-party service providers engaged by ditowin — including cloud hosting infrastructure providers and international game studios — may process personal data outside the Philippines. Where personal data is transferred to a jurisdiction outside the Philippines, ditowin ensures that the transfer is subject to appropriate safeguards, which may include:
Players who wish to obtain further information about cross-border data transfers or the applicable safeguards may contact ditowin's Data Protection Officer at the contact details provided in Section 15.
ditowin reserves the right to update or amend this Privacy Policy at any time to reflect changes in applicable law, regulatory requirements, or ditowin's data processing practices. Material changes to this Policy will be communicated to Players via one or more of the following methods: a notice on the Platform upon login; an email to the Player's registered email address; or a notification within the Player's account dashboard.
The date of the most recent update is displayed at the top of this Policy. Continued use of the ditowin Platform following the effective date of a Policy update constitutes your acknowledgement of the revised Policy. If you do not agree with any update, you must cease using the Platform and request account closure.
For all matters relating to this Privacy Policy, the exercise of data rights, or data protection concerns, Players may contact ditowin through the following channels. All privacy-related communications should be marked for the attention of the Data Protection Officer:
ditowin will acknowledge receipt of privacy-related requests within five (5) business days and will endeavour to resolve all requests within thirty (30) days of receipt. Complex or multi-faceted requests may require a longer resolution period, in which case ditowin will notify you of the extended timeframe and the reasons therefor.
Players also have the right to lodge a complaint directly with the National Privacy Commission (NPC) of the Philippines if they believe that ditowin has violated their data privacy rights. Further information about filing a complaint with the NPC is available at the NPC's official website.
ditowin is built to protect your privacy and deliver a fast, fair gaming experience. Slots, live baccarat, sports betting, and bingo — all in one account. GCash and PayMaya deposits in under a minute. For Filipino players aged 21 and above.
500+ titles with published RTPs. From ₱1 per spin.
80+ live tables — baccarat, blackjack, roulette. 24/7.
PBA, NBA, UFC, boxing, sabong — live and pre-match.
For players aged 21 and above only. Gambling can be addictive. Play responsibly.
See also: Terms & Conditions · Responsible Gaming