This Privacy Policy explains how aha888 collects, uses, stores, and protects your personal information when you use our platform. It is prepared in compliance with the Philippine Data Privacy Act of 2012 (Republic Act No. 10173), its Implementing Rules and Regulations, and PAGCOR's data handling requirements for licensed online gaming operators.
aha888 is committed to protecting the privacy and personal data of every Filipino player who registers and plays on our platform. This Privacy Policy describes in plain terms what personal information aha888 collects, how it is used, who it may be shared with, how long it is kept, and what rights you have over your data.
This Policy applies to all personal data processed by aha888 in connection with the aha888.one website and any related services, applications, or communications, regardless of the device or method through which you access the platform. It covers data collected from players based in the Philippines and is drafted in compliance with Republic Act No. 10173, the Data Privacy Act of 2012 (DPA), its Implementing Rules and Regulations, the directives of the National Privacy Commission (NPC) of the Philippines, and PAGCOR's applicable regulatory standards for licensed online gaming operators.
By registering an account on aha888 or continuing to use the platform after this Policy's effective date, you acknowledge that you have read and understood this Privacy Policy and consent to the processing of your personal data as described herein.
For the purposes of the Philippine Data Privacy Act of 2012 and applicable data protection legislation, the data controller responsible for your personal information processed through the aha888 platform is:
aha888 (aha888.one)
Regulated by the Philippine Amusement and Gaming Corporation (PAGCOR)
Contact Email: [email protected]
Support Channel: 24/7 Live Chat via member dashboard
aha888 has designated a Data Protection Officer (DPO) as required under the Data Privacy Act. Privacy-related requests, complaints, and inquiries should be directed to our support team, which will escalate data protection matters to the DPO as appropriate.
aha888 collects personal data that is necessary, adequate, and not excessive for the purposes described in this Policy. We do not collect sensitive personal information beyond what is strictly required by PAGCOR KYC obligations and AML compliance requirements. The categories of data we collect are described below.
| Category | Examples | Collected When |
|---|---|---|
| Identity Data | Full legal name, date of birth, nationality, government ID number and type | Account registration; KYC verification |
| Contact Data | Philippine mobile number, email address, mailing address | Account registration; KYC |
| Financial Data | GCash number, PayMaya account, bank account name and number (BPI, BDO, Metrobank), transaction history, deposit/withdrawal records | Payment processing; KYC; AML monitoring |
| KYC Documents | Scanned or photographed government-issued Philippine ID, selfie with ID (liveness verification where required) | KYC verification process |
| Gaming Activity Data | Bet history, game session logs, win/loss records, bonus usage, stake amounts, game preferences | Platform use — ongoing |
| Technical Data | IP address, device type, browser type and version, operating system, session timestamps, cookies | Platform access — ongoing |
| Communications Data | Live chat transcripts, support email correspondence, feedback submissions | When you contact aha888 support |
| Marketing Preferences | Opt-in/opt-out status for promotional communications, preferred contact channel | Registration; account settings updates |
aha888 does not intentionally collect sensitive personal information (as defined under Section 3(l) of the DPA) such as racial or ethnic origin, political opinions, religious beliefs, health data, or sexual orientation. To the extent that sensitive data is incidentally disclosed through communications with our support team, it will not be processed beyond what is necessary to address the specific support matter.
aha888 collects personal data through the following means:
4.1 Directly from YouThe majority of personal data we hold is provided directly by you during account registration, the KYC verification process, payment transactions, responsible gaming tool configuration, and communications with our support team. You are not required to provide more information than is necessary to access the Services.
4.2 Automated Technical CollectionWhen you access aha888.one, our servers and analytics infrastructure automatically collect certain technical data about your device and session, including your IP address, device identifiers, browser characteristics, and access timestamps. This data is collected through server logs, session cookies, and similar technologies described in Section 10 of this Policy.
4.3 Third-Party SourcesIn limited circumstances, aha888 may receive personal data from third-party sources as part of our legal compliance obligations. These include: (a) identity verification service providers used to authenticate KYC documents; (b) payment processors (GCash, PayMaya, and Philippine banking partners) who confirm transaction validity; and (c) public records, sanctions screening databases, and politically exposed persons (PEP) lists that aha888 is required to cross-reference under PAGCOR AML compliance rules.
aha888 processes your personal data only for specific, legitimate purposes. We do not use your data in ways that are incompatible with the purposes for which it was originally collected. The primary purposes for which we process personal data are:
Under the Philippine Data Privacy Act of 2012, aha888 relies on the following lawful bases for processing your personal data:
aha888 does not sell your personal data to third parties. We do not share your personal data with third parties for their own direct marketing purposes. Personal data is shared only in the limited circumstances described below:
7.1 Service Providers (Processors)aha888 engages trusted third-party service providers who process personal data on our behalf and under our instruction. These include: identity verification and KYC technology providers; payment gateway operators (GCash, PayMaya, and banking partners); IT infrastructure and cloud hosting providers; fraud detection and AML screening services; customer support platform providers; and email communication services. All processors are contractually required to maintain appropriate data security standards and may only use your data for the specific purpose for which they were engaged.
7.2 Regulatory and Legal Authoritiesaha888 is required by Philippine law and PAGCOR regulations to disclose certain personal data and transaction records to regulatory and law enforcement bodies. This includes mandatory reporting to the Anti-Money Laundering Council (AMLC) of covered and suspicious transactions, disclosures to PAGCOR in response to regulatory inquiries, and compliance with court orders, subpoenas, or directions from competent Philippine government authorities. Such disclosures are made strictly within the scope required by law.
7.3 Business TransfersIn the event of a merger, acquisition, reorganization, or sale of aha888's business or assets, personal data held by aha888 may be transferred to the acquiring entity, subject to the acquirer maintaining equivalent data protection standards and any required PAGCOR regulatory approvals.
aha888 retains personal data only for as long as is necessary to fulfil the purposes for which it was collected, or for such longer period as is required by Philippine law or PAGCOR regulations. Our general retention practices are as follows:
After the applicable retention period, personal data is securely deleted or anonymized in a manner that prevents reconstruction of the original data subject's identity.
aha888 implements technical and organizational security measures appropriate to the nature of the personal data we hold and the risks associated with its processing. These measures include:
While aha888 takes all reasonable technical precautions, no internet-based platform can guarantee absolute security. You can strengthen the security of your personal data by using a strong, unique password for your aha888 account, enabling two-factor authentication, and logging out of shared devices.
aha888 uses cookies and similar tracking technologies to operate the platform correctly, maintain your session security, and understand how players interact with the platform. Cookies are small text files stored on your device by your browser.
10.1 Types of Cookies UsedYou can configure your browser to block or delete non-essential cookies. Please note that disabling strictly necessary cookies will prevent you from logging into your aha888 account and using core platform features. Instructions for managing cookies are available in your browser's help documentation.
Under the Philippine Data Privacy Act of 2012, you have the following rights with respect to your personal data held by aha888. These rights may be subject to limitations where processing is required for legal compliance or regulatory obligations that override individual privacy interests.
You have the right to be informed about how aha888 processes your personal data. This Privacy Policy is how we fulfil that obligation. You may also request a plain-language summary of our data processing practices at any time by contacting our support team.
You have the right to request a copy of the personal data aha888 holds about you, including your account data, KYC records, transaction history, and gaming activity logs. Access requests will be responded to within 15 business days.
If any personal data aha888 holds about you is inaccurate or incomplete, you have the right to request correction. Corrections to identity data require re-verification through our KYC process.
You may request deletion of your personal data where it is no longer necessary for the purposes for which it was collected. Note that aha888 cannot delete data that must be retained under PAGCOR regulations, the AMLA, or other Philippine law requirements (minimum five-year retention).
You have the right to object to the processing of your personal data for direct marketing purposes. You may withdraw your marketing consent at any time through your aha888 account settings without affecting your access to gaming services.
Where processing is based on your consent or contract performance and is carried out by automated means, you have the right to receive your personal data in a structured, commonly used, machine-readable format.
If you believe aha888 has violated your data privacy rights, you have the right to lodge a complaint with the National Privacy Commission (NPC) of the Philippines. We encourage you to contact us first so we can address your concern directly — but this does not affect your right to contact the NPC at any time.
The aha888 platform is strictly for individuals aged 21 years or older, in compliance with PAGCOR's age requirements for licensed online casino operators in the Philippines. aha888 does not knowingly collect personal data from persons under the age of 21.
The age verification component of our KYC process is specifically designed to identify and reject accounts opened by persons under 21 years of age. Any account subsequently found to have been registered by a minor will be closed immediately, personal data will be handled in accordance with the Data Privacy Act's requirements for data of individuals who lacked legal capacity at the time of collection, and the matter may be referred to PAGCOR.
Some of aha888's service providers — including cloud infrastructure, game software providers, and certain analytics tools — may process personal data in servers located outside the Philippines. Where such cross-border transfers occur, aha888 ensures that:
The majority of your personal data — in particular your KYC documents, financial transaction records, and AMLA-regulated data — is processed and stored within systems accessible to aha888's compliance team under Philippine jurisdiction.
aha888 may update this Privacy Policy from time to time to reflect changes in our data processing practices, applicable Philippine law, NPC guidelines, or PAGCOR regulatory requirements. Material changes to this Policy will be communicated to registered players by email notification to your registered address, or via a prominent notice on the aha888 platform, no less than seven (7) days before the updated Policy takes effect.
The effective date and last updated date at the top of this document will be revised each time the Policy is updated. We recommend reviewing this page periodically. Continued use of the aha888 platform after a Policy update takes effect constitutes your acceptance of the revised Policy. If you do not agree with the changes, you should close your account and cease using the platform before the effective date of the amendment.
For all data privacy matters — including access requests, rectification requests, erasure requests, objections to processing, or general inquiries about this Privacy Policy — please contact the aha888 data protection team through the following channels:
aha888 will verify your identity before processing any data subject request to ensure that personal data is not disclosed to unauthorized parties.
Data privacy at aha888 isn't just a legal checkbox — it's part of what it means to be a properly regulated Philippine casino operator. Here's what that means in practice for Filipino players.
aha888 processes personal data under the full requirements of Republic Act No. 10173, the Philippine Data Privacy Act. Your rights as a Filipino data subject are enforceable through the National Privacy Commission — the same body that oversees all Philippine businesses handling personal data.
Every connection between your device and aha888's servers is protected by the same level of encryption used by Philippine banks and the GCash platform. Your login credentials, GCash number, and KYC documents are never transmitted in plain text.
aha888 does not sell, rent, or trade your personal data to advertisers, data brokers, or any other third party for commercial purposes. Your data is used only to provide and improve the aha888 service, comply with PAGCOR regulations, and protect you from fraud.
aha888 collects identity documents because PAGCOR and the AMLA require it — not to build a marketing profile. KYC data is used exclusively for identity verification, AML compliance, and fraud prevention. Access is restricted to compliance staff only.
Marketing communications from aha888 require your consent, and you can withdraw that consent at any time from your account settings. Opting out of marketing doesn't affect your access to games, bonuses, or support — it just stops the promo messages.
aha888 doesn't hold your data indefinitely. Retention periods are tied to specific legal requirements — primarily the 5-year PAGCOR and AMLA minimum — and data is securely deleted or anonymized at the end of each retention period.
Your data is handled under Philippine law, your funds are regulated by PAGCOR, and your GCash payouts arrive in minutes. aha888 is the online casino Filipino players can actually trust.
Must be 21 years or older to play. Play responsibly. PAGCOR licensed operator.