Introduction
fb0001 ("the Platform," "we," "us," "our") is committed to protecting the privacy and personal data of every individual who uses or interacts with the fb0001 online gaming platform. This Privacy Policy explains what personal information fb0001 collects, why we collect it, how it is used, who it is shared with, how long it is kept, and what rights you have as a data subject under Philippine law.
This Privacy Policy applies to all personal data processed by fb0001 in connection with the operation of fb0001.org and all associated services — including account registration, KYC verification, payment processing, game participation, customer support interactions, and marketing communications. It applies to all registered Players, visitors to the website, and any individual who contacts fb0001 through any channel.
By registering an account on fb0001 or by continuing to use the Platform after this Privacy Policy has been made available to you, you acknowledge that you have read and understood how fb0001 processes your personal data as described herein. If you do not agree with any part of this Privacy Policy, you should not use the Platform.
This Privacy Policy is to be read together with the fb0001 Terms & Conditions. In the event of any inconsistency between this Privacy Policy and the Terms & Conditions on matters relating to data privacy, this Privacy Policy shall prevail.
Data Controller
For the purposes of the Data Privacy Act of 2012, fb0001 acts as the Personal Information Controller (PIC) in respect of personal data collected from users of the fb0001 platform. As the PIC, fb0001 determines the purposes and means of processing your personal data.
fb0001 has designated a Data Protection Officer (DPO) responsible for overseeing the platform's compliance with the Data Privacy Act, monitoring data processing activities, coordinating with the National Privacy Commission (NPC) where required, and serving as the point of contact for data subject inquiries and complaints. The DPO can be reached at [email protected].
Third-party service providers — including gaming software providers, payment processors, KYC verification services, and cloud infrastructure providers — may act as Personal Information Processors (PIPs) when processing data on behalf of fb0001. Such processors are contractually required to process data only as instructed by fb0001 and in compliance with applicable Philippine data protection law.
Personal Data We Collect
The categories of personal data fb0001 collects depend on your level of interaction with the Platform. The following describes the full scope of data that may be collected:
3.1 Registration Data
- Full legal name
- Date of birth (for age verification purposes)
- Philippine mobile number
- Email address
- Username and encrypted password credentials
- Preferred language and communication preferences
3.2 Identity Verification (KYC) Data
- Government-issued Philippine identification document (type, number, and image)
- Selfie or facial photograph submitted for liveness verification
- Proof of address documentation where required
- Ownership verification documents for payment accounts (GCash, Maya, bank accounts)
3.3 Financial Data
- Deposit and withdrawal transaction records including amounts, timestamps, and payment channel identifiers
- GCash account reference numbers or masked bank account details used for transaction purposes
- Account balance history
3.4 Gaming Activity Data
- Game session records including games played, wagers placed, winnings and losses, and session durations
- Bonus history including bonuses claimed, wagering progress, and expiry
- Responsible gaming tool settings (deposit limits, session limits, self-exclusion status)
3.5 Technical & Device Data
- IP address
- Device type, operating system, and browser version
- Cookie identifiers and session tokens
- Approximate geolocation derived from IP address
- Login timestamps and login history
3.6 Customer Support Data
- Live chat conversation transcripts
- Email correspondence content and metadata
- Complaint and dispute records
fb0001 does not collect full payment card numbers, CVV codes, or full bank account numbers. Payment transactions are processed through certified Philippine payment gateways. fb0001 receives only anonymized transaction identifiers sufficient to reconcile deposits and withdrawals.
How We Collect Personal Data
fb0001 collects personal data through the following channels and mechanisms:
- Directly from you — when you register an account, complete KYC verification, make a deposit or withdrawal, contact customer support, or update your account settings.
- Automatically through the Platform — through cookies, server logs, and session tracking technologies that record your interactions with the fb0001 website and games.
- From third-party verification services — fb0001 uses accredited KYC and identity verification service providers to validate the authenticity of identity documents submitted during verification. These providers may process your data on behalf of fb0001 as Personal Information Processors.
- From payment processors — when you make a deposit or withdrawal, the relevant e-wallet (GCash, Maya) or bank infrastructure transmits transaction metadata to fb0001 for the purpose of confirming payment receipt and matching it to your Account.
Purposes & Lawful Basis for Processing
fb0001 processes personal data only for specific, legitimate, and explicitly stated purposes. The table below summarizes the primary purposes of processing and the lawful basis under the Data Privacy Act of 2012:
| Purpose | Data Categories Used | Lawful Basis |
|---|---|---|
| Account registration & authentication | Registration data, device data | Contract |
| Identity & age verification (KYC) | KYC data, registration data | Legal Obligation |
| Processing deposits & withdrawals | Financial data, KYC data | Contract |
| Providing gaming services | Gaming activity data, financial data | Contract |
| Anti-money laundering compliance | Financial data, KYC data, transaction records | Legal Obligation |
| Responsible gaming monitoring | Gaming activity data, responsible gaming settings | Legal Obligation |
| Fraud prevention & security | Technical data, login history, financial data | Legitimate Interest |
| Customer support & dispute resolution | Support data, account data | Contract |
| Platform improvement & analytics | Technical data, gaming activity (aggregated) | Legitimate Interest |
| Marketing & promotional communications | Registration data, gaming preferences |
Data Sharing & Disclosure
fb0001 does not sell, rent, or trade your personal data to unaffiliated third parties for their own commercial marketing purposes. Personal data is disclosed to third parties only in the circumstances described below:
6.1 Service Providers (Personal Information Processors)
fb0001 engages accredited third-party service providers to perform specific functions on its behalf. These include: KYC verification platforms, payment processing infrastructure (GCash, Maya, bank payment gateways), cloud hosting and data storage providers, anti-fraud and security monitoring services, and customer support software operators. All such providers are contractually bound to process personal data solely as directed by fb0001 and in compliance with applicable Philippine privacy law.
6.2 Gaming Software Providers
Third-party game providers whose titles are offered on fb0001 may receive limited technical data (session tokens, anonymized player identifiers) necessary to operate and authenticate game sessions. These providers do not receive your full name, identification documents, financial account details, or Philippine mobile number.
6.3 Regulatory & Law Enforcement Authorities
fb0001 will disclose personal data to PAGCOR, the National Privacy Commission, the Anti-Money Laundering Council (AMLC), or any other Philippine government authority where required to do so by applicable law, court order, or lawful regulatory demand. fb0001 will, where legally permissible, notify the affected account holder of such disclosure.
6.4 Business Transfers
In the event of a merger, acquisition, restructuring, or sale of all or part of the assets of fb0001, personal data held by fb0001 may be transferred to a successor entity. Any such transfer will be subject to equivalent privacy protections, and registered users will be notified before their personal data is transferred and becomes subject to a materially different privacy policy.
fb0001 does not share personal data with advertisers, data brokers, social media platforms, or any entity for the purpose of targeted advertising outside the fb0001 platform.
Data Retention & Deletion
fb0001 retains personal data for as long as is necessary to fulfill the purpose for which it was collected, or as required by applicable Philippine law, whichever is longer. The key retention periods are as follows:
- Account and registration data: Retained for the duration of the active Account and for a minimum of five (5) years after Account closure, in compliance with anti-money laundering record-keeping requirements under Philippine law.
- KYC and identity verification data: Retained for a minimum of five (5) years from the date of verification, or from the date of Account closure, in line with AMLC requirements.
- Financial transaction records: Retained for a minimum of five (5) years in compliance with AMLC regulations and BSP guidelines applicable to online payment processors.
- Gaming activity data: Retained for three (3) years from the date of each gaming session, or the lifetime of the Account plus three (3) years following closure.
- Customer support records: Retained for two (2) years from the date of the last interaction.
- Marketing consent records: Retained until consent is withdrawn and for one (1) year thereafter to demonstrate compliance.
Upon expiry of the applicable retention period, personal data is securely deleted or anonymized such that it can no longer be linked to an individual. Anonymized, aggregated data may be retained indefinitely for statistical and platform analytics purposes.
Security Measures
fb0001 implements a comprehensive set of technical and organizational security measures designed to protect personal data against unauthorized access, disclosure, alteration, loss, or destruction. Key security measures include:
- SSL/TLS Encryption: All data transmitted between your device and fb0001 servers is encrypted using Transport Layer Security (TLS) with a minimum 256-bit cipher. This applies to all login sessions, transactions, and account management interactions.
- Password Hashing: Account passwords are stored as salted cryptographic hashes. fb0001 does not store or have access to plaintext passwords at any time.
- Two-Factor Authentication (2FA): Players may enable OTP-based 2FA for their Account, adding a second layer of verification for each login session.
- Access Controls: Access to personal data within fb0001's internal systems is restricted to personnel with a legitimate need-to-know, governed by role-based access control policies and activity logging.
- Penetration Testing: fb0001's platform undergoes regular security assessments and vulnerability scanning by independent security professionals.
- Suspicious Login Detection: The platform monitors for unusual login patterns and issues immediate notifications to Players when an unrecognized device or location is detected.
No internet-based system is completely immune to security risks. While fb0001 takes all reasonable precautions, Players are encouraged to use strong, unique passwords and to enable 2FA on their Account to maximize personal account security.
Cookies & Tracking Technologies
fb0001 uses cookies and similar tracking technologies on its website to enable core platform functionality, improve the user experience, and analyze aggregate usage patterns. The cookies used by fb0001 fall into the following categories:
- Strictly Necessary Cookies: Essential for the Platform to function. These include session authentication tokens, security cookies, and cookies that remember your login state. These cannot be disabled without impairing Platform functionality.
- Functional Cookies: Remember your preferences such as language settings, notification preferences, and last-visited game category. Disabling these may affect the user experience but will not prevent Platform access.
- Analytics Cookies: Used by fb0001 to understand how the Platform is used in aggregate — which pages are visited most, how long sessions last, and which features are most utilized. Analytics data is aggregated and does not identify individual Players.
- Security Cookies: Support fraud prevention and suspicious activity detection by tracking login patterns and device consistency across sessions.
fb0001 does not use third-party advertising cookies or retargeting cookies that track your activity across websites other than fb0001.org.
Most web browsers allow you to control cookies through browser settings. Blocking strictly necessary cookies may prevent you from logging in to your fb0001 Account. Instructions for managing cookies are available in the help documentation of your browser.
Minors & Age Restriction
fb0001 does not knowingly collect personal data from any individual under the age of twenty-one (21) years. The fb0001 platform is strictly restricted to Filipino adults aged 21 and above, in compliance with PAGCOR's minimum age requirement for online gaming in the Philippines.
Age is verified as part of the mandatory KYC process using a government-issued Philippine identification document. Accounts where the registered holder is found to be under 21 are immediately suspended and any associated personal data is segregated pending review. If no legitimate entitlement exists, the Account is permanently closed and personal data is deleted to the extent permitted by any applicable legal retention obligations.
If a parent or guardian believes their child under 21 has registered or attempted to register on fb0001, please contact the fb0001 Data Protection Officer immediately at [email protected]. fb0001 will take prompt action to verify, close the Account, and delete any improperly collected data.
Your Data Subject Rights
Under the Data Privacy Act of 2012 and its Implementing Rules, you have the following rights in relation to your personal data held by fb0001. To exercise any of these rights, contact the fb0001 Data Protection Officer at [email protected]. fb0001 will respond to data subject requests within fifteen (15) business days of receipt.
- Right to be Informed: The right to know what personal data fb0001 collects about you, the purposes for which it is processed, and to whom it has been disclosed. This Privacy Policy is the primary means by which fb0001 fulfills this obligation.
- Right to Access: The right to request a copy of the personal data fb0001 holds about you, including the categories of data, purposes of processing, and third parties to whom data has been disclosed.
- Right to Rectification: The right to request correction of inaccurate or incomplete personal data in your Account. Basic account details can be updated directly through Account settings; corrections to KYC-verified data require contacting the DPO with supporting documentation.
- Right to Erasure ("Right to be Forgotten"): The right to request deletion of your personal data where it is no longer necessary for the purpose for which it was collected, where you withdraw consent (and no other lawful basis applies), or where processing is unlawful. Note that deletion may be limited where legal retention obligations apply (e.g., AML record-keeping).
- Right to Object: The right to object to processing based on fb0001's legitimate interests, and the right to object unconditionally to processing for direct marketing purposes.
- Right to Data Portability: The right to receive a copy of the personal data you provided to fb0001 in a structured, commonly used, machine-readable format, and to transmit it to another controller, where technically feasible.
- Right to Withdraw Consent: Where processing is based on your consent, you have the right to withdraw that consent at any time without affecting the lawfulness of processing prior to withdrawal.
- Right to File a Complaint: You have the right to lodge a complaint with the National Privacy Commission (NPC) of the Philippines if you believe fb0001 has violated your privacy rights.
Cross-Border Data Transfers
Some of the third-party service providers used by fb0001 — including cloud infrastructure providers, KYC platforms, and game software operators — may process or store personal data on servers located outside the Republic of the Philippines.
Where personal data is transferred to a jurisdiction outside the Philippines, fb0001 ensures that appropriate safeguards are in place to protect your data to a standard equivalent to that provided under the Data Privacy Act of 2012. These safeguards include: contractual clauses imposing data protection obligations on the receiving party, transfer impact assessments where required, and engagement with providers that maintain certifications under recognized international security and privacy frameworks.
fb0001 does not transfer your KYC identity documents or financial account details to jurisdictions outside the Philippines or to providers that have not agreed to process such sensitive data under terms equivalent to Philippine data protection law.
Marketing Communications
With your consent, fb0001 may send you promotional communications regarding bonuses, new game launches, platform updates, and relevant offers via your registered email address and Philippine mobile number (SMS or push notifications).
Marketing consent is obtained separately from the acceptance of these Terms during the Account registration process. You may withdraw consent for marketing communications at any time by:
- Updating your communication preferences in your Account settings under "Notification Preferences."
- Clicking the unsubscribe link included in any marketing email from fb0001.
- Contacting the fb0001 DPO at [email protected] with a written opt-out request.
Withdrawal of marketing consent does not affect your ability to use the Platform or receive service-related communications (e.g., deposit confirmations, withdrawal notifications, security alerts, and Account management notices). Service communications are sent based on the contractual relationship and cannot be opted out of while maintaining an active Account.
Data Breach Response Procedures
In the event of a personal data breach — defined as a security incident resulting in the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, personal data — fb0001 has the following response obligations and procedures:
- fb0001 will conduct an immediate internal investigation to contain the breach, assess its scope, and identify affected individuals.
- Where the breach is likely to result in a real risk of serious harm to any affected data subject, fb0001 will notify the National Privacy Commission (NPC) within seventy-two (72) hours of becoming aware of the breach, in accordance with NPC Circular 16-03.
- Affected individuals will be notified directly — via their registered email address and Philippine mobile number — as soon as reasonably practicable, with details of: the nature of the breach, the categories of personal data affected, the likely consequences, and the steps fb0001 is taking to address the breach and mitigate harm.
- fb0001 will maintain an internal Data Breach Register documenting all breaches regardless of severity, for audit and compliance review purposes.
If you suspect that your fb0001 Account or personal data has been compromised, please contact the DPO immediately at [email protected]. Change your password and enable 2FA as immediate protective steps.
Amendments to This Policy
fb0001 may update this Privacy Policy from time to time to reflect changes in our data processing practices, regulatory requirements, or platform functionality. Where changes are material — including changes to the types of data collected, purposes of processing, retention periods, or data subject rights procedures — fb0001 will provide advance notice to registered users via email and/or a prominent notice on the Platform, no less than fourteen (14) calendar days before the amended policy takes effect.
The "Effective Date" at the top of this document indicates when the current version entered into force. The most current version of this Privacy Policy is always available at fb0001.org/privacy-policy. Your continued use of the Platform following the effective date of any amendment constitutes your acknowledgment of the updated Privacy Policy.
Contact the Data Protection Officer
For any questions, concerns, or requests related to this Privacy Policy or to the processing of your personal data by fb0001, please contact the fb0001 Data Protection Officer (DPO):
fb0001 also maintains a 24/7 live chat support channel for all Account-related inquiries. For formal data subject rights requests, email contact with the DPO is the appropriate channel to ensure a documented response in compliance with NPC requirements.
If you are dissatisfied with fb0001's response to a data privacy concern, you have the right to lodge a complaint with the National Privacy Commission (NPC) of the Philippines, the supervisory authority for data protection matters in the Republic of the Philippines.