Your Privacy Matters: This Privacy Policy ("Policy") describes how 66win ("Company", "Platform", "we", "us", "our") collects, uses, stores, shares, and protects the personal information of players and visitors ("you", "your") on the 66win platform at 66win.vu. This Policy is designed to comply with the Republic Act No. 10173, also known as the Data Privacy Act of 2012 of the Philippines, its Implementing Rules and Regulations, and applicable PAGCOR data governance requirements. By using the 66win platform, you consent to the practices described in this Policy.
1Data Controller
66win operates as the data controller for all personal information processed through the 66win platform. As data controller, 66win determines the purposes and means by which your personal data is processed. For all privacy-related inquiries, requests, and concerns, you may contact us using the support email address published in the footer of this website.
66win has designated a Data Protection Officer (DPO) in accordance with the requirements of the Data Privacy Act of 2012. The DPO is responsible for ensuring that 66win's data processing activities comply with applicable privacy laws and for responding to player data subject requests.
2Personal Data We Collect
66win collects the following categories of personal data from players and platform visitors:
Identity Data:
- Full legal name as appearing on a government-issued identification document;
- Date of birth (for mandatory age verification — players must be 21 or older);
- Government-issued identification number (e.g., PhilSys ID, passport, driver's licence, SSS/GSIS);
- Profile photograph or selfie submitted during KYC verification.
Contact Data:
- Email address;
- Philippine mobile number (for SMS verification and two-factor authentication);
- Residential address (province, city/municipality, barangay).
Financial Data:
- GCash account number or registered mobile number;
- PayMaya / Maya account details;
- Bank account details for BPI, BDO, or Metrobank where used for deposits or withdrawals;
- Transaction history, deposit amounts, withdrawal records, and gaming activity logs.
Technical & Usage Data:
- IP address and approximate geographic location;
- Device type, operating system, browser type and version;
- Session timestamps, login history, and platform activity logs;
- Referral source and marketing attribution data.
3How Personal Data Is Collected
66win collects personal data through the following means:
- Direct provision by you: when you register an account, complete KYC verification, make a deposit or withdrawal request, contact support, or respond to a survey or promotion;
- Automated technical collection: through cookies, web beacons, server logs, and similar tracking technologies as you browse and use the 66win platform (see Section 9 – Cookies & Tracking);
- Third-party payment processors: when you complete a transaction through GCash, PayMaya, or a Philippine bank, 66win receives a confirmation record of the transaction which may include limited account identifiers;
- KYC and identity verification providers: 66win may use approved third-party identity verification services to cross-check the documents you submit during account verification.
4Purpose of Processing Your Data
66win processes your personal data for the following specific, legitimate purposes:
- Account creation and management: to register your 66win account, verify your identity and age, and maintain your player profile;
- Service delivery: to provide access to games, process deposits, execute withdrawals, and deliver promotional bonuses;
- Regulatory compliance: to meet KYC, anti-money laundering (AML), and counter-terrorism financing (CTF) obligations required by PAGCOR and applicable Philippine law;
- Fraud prevention and platform security: to detect, investigate, and prevent fraudulent activity, account abuse, and security breaches;
- Responsible gaming: to monitor for signs of problem gambling and to apply self-exclusion or account restriction requests made by players or required by regulation;
- Customer support: to respond to your inquiries, resolve disputes, and improve the quality of our support service;
- Marketing communications: to send you promotional offers, bonus notifications, and platform updates — only where you have consented to receive such communications and only for 66win's own services;
- Platform improvement: to analyse aggregated usage data to improve the 66win platform, fix technical issues, and enhance the player experience.
5Legal Basis for Processing
66win processes your personal data under the following lawful bases as recognised by the Data Privacy Act of 2012:
- Contractual necessity: processing required to perform the contract between you and 66win (i.e., providing you with gaming services, processing transactions);
- Legal obligation: processing required to comply with applicable Philippine laws, PAGCOR regulations, AML/CTF obligations, and court or regulatory orders;
- Legitimate interests: processing for fraud prevention, platform security, and responsible gaming monitoring, where such interests are not overridden by your fundamental rights;
- Consent: processing for marketing communications and non-essential cookies, where you have given explicit, freely given, and informed consent. You may withdraw this consent at any time.
7Data Retention
66win retains your personal data for as long as necessary to fulfil the purposes described in this Policy and to meet applicable legal retention obligations. Specific retention periods include:
- Account and KYC records: retained for a minimum of five (5) years following account closure, in compliance with AML/CTF record-keeping requirements;
- Transaction records: retained for a minimum of five (5) years following the date of each transaction;
- Support and communication records: retained for three (3) years following the resolution of each inquiry or dispute;
- Marketing consent records: retained until consent is withdrawn and for two (2) years thereafter as proof of consent;
- Technical and usage logs: retained for ninety (90) days for security monitoring purposes, then deleted or anonymised.
Upon expiry of the applicable retention period, 66win will securely delete or anonymise your personal data in a manner that prevents reconstruction or identification.
8Data Security Measures
66win implements appropriate technical and organisational security measures to protect your personal data against unauthorised access, disclosure, alteration, or destruction. These measures include:
- Transport Layer Security (TLS/SSL) encryption for all data transmitted between your device and the 66win platform;
- AES-256 encryption for sensitive data stored in 66win databases;
- Multi-factor authentication requirements for administrative access to systems holding personal data;
- Regular penetration testing and vulnerability assessments by independent security professionals;
- Strict role-based access controls limiting staff access to personal data on a need-to-know basis;
- Documented incident response and data breach notification procedures in accordance with NPC requirements.
In the event of a personal data breach that poses a real risk to your rights and freedoms, 66win will notify the National Privacy Commission and, where required, affected data subjects within the timeframes prescribed by the Data Privacy Act of 2012.
10Your Data Subject Rights
Under the Data Privacy Act of 2012, you have the following rights with respect to your personal data held by 66win:
- Right to be informed: the right to know what personal data 66win holds about you and how it is processed;
- Right to access: the right to request a copy of the personal data 66win holds about you;
- Right to rectification: the right to have inaccurate or incomplete personal data corrected;
- Right to erasure: the right to request deletion of your personal data where it is no longer necessary for the purpose for which it was collected, subject to legal retention obligations;
- Right to object: the right to object to the processing of your personal data for direct marketing purposes or on grounds relating to your particular situation;
- Right to data portability: the right to receive your personal data in a structured, commonly used format for transfer to another controller;
- Right to lodge a complaint: the right to lodge a complaint with the National Privacy Commission (NPC) of the Philippines if you believe your data privacy rights have been violated.
To exercise any of these rights, please contact 66win's Data Protection Officer using the support email address in the footer of this page. We will respond to verified requests within thirty (30) days of receipt, in accordance with applicable law.
11Minors & Age Restriction
The 66win platform is strictly for individuals who are 21 years of age or older. 66win does not knowingly collect personal data from individuals under the age of 21. Age verification is a mandatory step before any gaming activity or withdrawal is permitted on the platform.
If 66win becomes aware that personal data has been collected from an individual under the age of 21, such data will be deleted immediately and the associated account will be permanently closed. If you are a parent or guardian and believe that your minor child has accessed or registered on the 66win platform, please contact our support team immediately.
12Changes to This Privacy Policy
66win reserves the right to update this Privacy Policy at any time to reflect changes in our data processing practices, legal obligations, or regulatory requirements. The "Last Updated" date at the top of this Policy indicates when the most recent revision was made.
Where changes are material, 66win will notify registered players by email or through an in-platform notification prior to the changes taking effect. Your continued use of the 66win platform after the effective date of any revised Policy constitutes your acceptance of the updated terms.
For questions about this Privacy Policy or to exercise your data subject rights, please contact us using the email address in the footer of this page. Our Data Protection Officer and support team are available to assist you.
Your Privacy Rights at a Glance
Right to Access
Request a copy of your data at any time
Right to Correct
Fix inaccurate data we hold about you
Right to Erase
Request deletion where legally permitted
Right to Object
Opt out of direct marketing anytime
Data Portability
Receive your data in a portable format
Right to Complain
Lodge a complaint with the NPC Philippines
How 66win Protects Your Data
SSL Encryption on All Pages
Every page on 66win is served over HTTPS with TLS encryption. Your login credentials, personal details, and payment information are never transmitted in plain text.
DPA 2012 Compliant
66win's data practices are aligned with Republic Act 10173 (Data Privacy Act of 2012) and its Implementing Rules. We have a designated Data Protection Officer on record.
Encrypted Data Storage
Personal and financial data stored in 66win systems is encrypted at rest using AES-256. Access to player data is strictly limited to authorised personnel with a documented business need.
No Data Sales — Ever
66win does not sell, rent, or license your personal data to any third party for their own marketing. Your data is used exclusively for the purposes described in this Policy.
Breach Notification Protocol
In the unlikely event of a data breach affecting your personal information, 66win will notify the NPC and affected players within the timeframes mandated by the Data Privacy Act of 2012.
Defined Retention Periods
66win does not hold your data indefinitely. Clear retention schedules are in place — once data is no longer needed, it is securely deleted or anonymised in accordance with legal requirements.
Questions About Your Privacy at 66win?
Our Data Protection Officer and 24/7 support team are here to help with any data privacy concerns, access requests, or account questions. You are always in control of your data at 66win. 21+ only. Play responsibly.
Must be 21 or older. PAGCOR regulations apply.