bossph Privacy Policy
bossph is committed to handling your personal information with care, transparency, and full compliance with the Philippine Data Privacy Act of 2012 (Republic Act No. 10173) and PAGCOR regulatory requirements. This Privacy Policy explains what data we collect, why we collect it, how we use and protect it, and what rights you hold as a bossph account holder.
Effective Date: January 1, 2026 · Last Updated: January 1, 2026How bossph Protects Your Data
These cards summarize bossph's core privacy commitments. The full legal detail is in the policy sections below — please read the complete document.
DPA 2012 Compliant
bossph operates in full compliance with Republic Act No. 10173 — the Philippine Data Privacy Act of 2012. Your personal information is collected, processed, and stored only for lawful, specified, and legitimate purposes, with your informed consent at the core of every data activity.
Encrypted & Secured
All data transmitted between your device and bossph is protected by industry-standard 256-bit SSL/TLS encryption. Sensitive account data — including payment information and KYC documents — is stored on encrypted servers with access controls that limit exposure to authorised personnel only.
You Control Your Data
As a bossph account holder, you hold specific rights over your personal data under Philippine law — including the right to access, correct, object to processing, and request erasure where applicable. These rights are not buried in fine print; they are enforceable and bossph will honor them promptly.
No Unauthorised Selling
bossph does not sell your personal information to third-party advertisers or data brokers. Data is shared with third parties only where required for platform operations (such as payment processors and game providers), regulatory compliance, or where you have provided explicit consent.
Defined Retention Periods
bossph does not retain personal data indefinitely. Retention periods are defined by regulatory requirements — PAGCOR mandates certain records be kept for a minimum period — and by legitimate operational needs. Data is securely disposed of once its retention purpose has been fulfilled.
Breach Notification
In the unlikely event of a personal data breach that poses a real risk to your rights and freedoms, bossph will notify affected account holders and the National Privacy Commission (NPC) within the timeframes required by Philippine law. Transparency in an adverse event is a non-negotiable commitment.
Introduction
This Privacy Policy (hereinafter "Policy") is issued by bossph, the operator of the online gaming platform accessible at bossph.cam (hereinafter "bossph," "we," "us," or "our"). This Policy describes how bossph collects, uses, processes, stores, shares, and protects the personal information of individuals who access or use the bossph platform — including registered players, website visitors, and anyone who contacts bossph's customer support team.
This Policy is issued in compliance with Republic Act No. 10173, otherwise known as the Data Privacy Act of 2012 (hereinafter "DPA"), its Implementing Rules and Regulations, and the applicable issuances of the National Privacy Commission (NPC) of the Philippines. bossph also processes data in accordance with its PAGCOR licensing obligations, which impose independent requirements on the handling of player information.
By registering for a bossph account, accessing the platform, or otherwise providing your personal information to bossph, you acknowledge that you have read and understood this Privacy Policy and consent to the collection and processing of your data as described herein. If you do not agree with this Policy, you should not use the bossph platform.
Policy Scope
This Policy applies to all personal data collected by bossph through its website at bossph.cam, its customer support channels, and any related digital touchpoints operated by bossph. It does not apply to third-party websites, applications, or services that may be linked from the bossph platform — those are governed by their own respective privacy policies.
Data Controller
Under the Philippine Data Privacy Act of 2012, bossph acts as the Personal Information Controller (PIC) in respect of the personal data it collects from platform users. As PIC, bossph is responsible for determining the purposes and means by which personal information is processed.
bossph has designated a Data Protection Officer (DPO) responsible for overseeing compliance with the DPA and this Policy, and for serving as the primary point of contact for data privacy matters. Queries, concerns, and exercise of data subject rights may be directed to the DPO through the contact details set out in Section 14 of this Policy.
Platform Operator
bossph is an online gaming platform operated under PAGCOR regulatory oversight and accessible at bossph.cam. All data processing activities described in this Policy are conducted by bossph in its capacity as operator of that platform.
Personal Data We Collect
bossph collects personal data that is necessary and proportionate to the purposes for which it is collected. The categories of personal data we process include the following:
3.1 Registration & Identity Data
When you create a bossph account, we collect information necessary to establish and verify your identity, including:
- Full legal name as it appears on government-issued identification;
- Date of birth (for age verification — all players must be 21 years of age or older);
- Email address and Philippine mobile number;
- Username and encrypted password;
- Nationality and country of residence.
3.2 KYC & Verification Documents
In compliance with PAGCOR requirements and anti-money laundering obligations, bossph collects:
- Government-issued Philippine ID (e.g., PhilSys ID, passport, driver's license, SSS/GSIS card, Voter's ID);
- Proof of address documents;
- Source of funds documentation where required by law or risk assessment.
3.3 Financial & Transaction Data
- GCash or PayMaya account reference numbers linked to your bossph wallet;
- Bank account details for withdrawals via BPI, BDO, Metrobank, or other supported banks;
- Deposit and withdrawal transaction history;
- Wagering history, game participation records, and account balance information.
3.4 Technical & Usage Data
- IP address, device type, operating system, and browser type;
- Login timestamps and session duration;
- Pages visited, games accessed, and in-platform navigation patterns;
- Cookies and similar tracking technologies as described in Section 11.
3.5 Communications Data
- Records of live chat, email, and support ticket communications with bossph customer service;
- Responses to surveys, promotions, and feedback requests.
Sensitive Personal Information
Where bossph processes sensitive personal information as defined under the DPA — such as government ID numbers — such processing is conducted strictly within the bounds of the DPA's lawful processing criteria and PAGCOR's KYC requirements. bossph applies heightened security controls to sensitive personal information.
How We Collect Your Data
bossph collects personal data through the following channels:
- Directly from you — when you register an account, complete KYC verification, make deposits or withdrawals, contact customer support, or participate in promotions;
- Automatically through platform use — via cookies, server logs, and analytics tools that record technical and usage data as you navigate bossph.cam;
- From payment processors — when you transact through GCash, PayMaya, BPI, BDO, Metrobank, or 7-Eleven, relevant transaction confirmation data is passed to bossph by those processors;
- From identity verification services — third-party KYC and identity verification providers may pass verification outcomes to bossph as part of the account onboarding process;
- From regulatory and law enforcement bodies — where bossph is required by law to obtain or verify information in response to regulatory instructions or legal process.
Purpose & Legal Basis for Processing
bossph processes personal data only where a lawful basis under the DPA exists. The following table sets out the primary purposes for which bossph processes personal data and the corresponding legal basis under the DPA:
| Processing Purpose | Legal Basis |
|---|---|
| Account registration and management | Performance of contract; Consent |
| Age verification (21+ requirement) | Legal obligation (PAGCOR regulations) |
| KYC and anti-money laundering compliance | Legal obligation (AMLA, PAGCOR) |
| Processing deposits, bets, and withdrawals | Performance of contract |
| Fraud detection and platform security | Legitimate interests; Legal obligation |
| Customer support and dispute resolution | Performance of contract; Legitimate interests |
| Responsible gaming monitoring | Legal obligation (PAGCOR); Legitimate interests |
| Marketing and promotions (opted-in) | Consent |
| Platform analytics and improvement | Legitimate interests |
| Regulatory reporting to PAGCOR and NPC | Legal obligation |
Where bossph relies on consent as the legal basis for processing, you have the right to withdraw that consent at any time by contacting our Data Protection Officer. Withdrawal of consent does not affect the lawfulness of processing carried out before the withdrawal.
Data Sharing & Third Parties
bossph does not sell, rent, or trade your personal information to third-party advertisers or commercial data brokers. bossph shares personal data with third parties only in the following circumstances:
6.1 Service Providers (Personal Information Processors)
bossph engages third-party service providers who process personal data on our behalf and under our written instruction. These include payment processors (GCash, PayMaya, partner banks), identity verification services, cloud hosting providers, anti-fraud technology vendors, and customer support platform operators. These providers are contractually bound to process data only as directed by bossph and to maintain appropriate security measures.
6.2 Game Content Providers
Game providers on the bossph platform — such as JILI, Pragmatic Play, Evolution Gaming, and other licensed studios — may receive limited technical data (such as player session tokens) necessary to deliver game content. They do not receive personally identifiable information beyond what is necessary for gameplay and game integrity purposes.
6.3 Regulatory and Law Enforcement Authorities
bossph is required by law to disclose personal data to PAGCOR, the Anti-Money Laundering Council (AMLC), the National Privacy Commission, and relevant Philippine law enforcement agencies upon lawful request. bossph will comply with all such legally valid demands and will notify affected data subjects where permitted by law.
6.4 Corporate Transactions
In the event of a merger, acquisition, restructuring, or sale of all or a portion of bossph's business, personal data held by bossph may be transferred as part of that transaction. Affected players will be notified in advance where required by the DPA, and the acquiring entity will be bound by the terms of this Policy or required to issue a successor policy with equivalent protections.
No Sale of Personal Data
bossph does not and will not sell your personal information to third-party advertisers, marketing platforms, or data aggregators. Any future arrangement that could be characterised as a sale of personal data will require your explicit prior consent and will be subject to a specific update of this Policy.
International Data Transfers
bossph's primary data processing infrastructure is located within the Philippines. However, certain service providers — including cloud infrastructure partners and game content providers — may process or store data in server locations outside the Philippines.
Where personal data is transferred to a jurisdiction outside the Philippines, bossph ensures that appropriate safeguards are in place in accordance with the DPA, including contractual protections (such as data processing agreements with equivalent privacy standards) or transfers to jurisdictions that offer comparable levels of data protection. bossph will not transfer personal data to a foreign jurisdiction where adequate protection cannot be assured.
Data Retention
bossph retains personal data for as long as is necessary to fulfil the purposes for which it was collected, subject to any longer retention periods required by law or regulation. Key retention principles include:
- Account and KYC records are retained for a minimum of five (5) years from the date of account closure, as required under PAGCOR regulations and AMLA;
- Financial transaction records are retained for a minimum of five (5) years;
- Customer support communications are retained for three (3) years from the date of the interaction;
- Marketing consent records are retained for the duration of your marketing consent plus three (3) years;
- Technical and usage logs may be retained for up to twelve (12) months for security and fraud detection purposes.
Upon expiry of applicable retention periods, personal data is securely deleted, anonymised, or — where physical documents are involved — destroyed in a manner that prevents reconstruction. bossph does not archive personal data beyond what is proportionate to its legitimate retention purposes.
Security Measures
bossph implements a multi-layered approach to personal data security, combining technical, organizational, and procedural controls to protect your information against unauthorized access, accidental loss, alteration, or disclosure. Security measures in place at bossph include:
- 256-bit SSL/TLS encryption for all data in transit between your device and bossph servers;
- Encryption at rest for sensitive data categories, including KYC documents and payment information;
- Role-based access controls limiting data access to authorised personnel with a demonstrated need;
- Multi-factor authentication requirements for internal system access;
- Regular penetration testing and vulnerability assessments by independent security professionals;
- Fraud detection and anomaly monitoring systems operating continuously;
- Staff training on data privacy and security obligations under the DPA;
- Incident response procedures aligned with NPC notification requirements.
Your Responsibilities
While bossph implements robust security controls, the security of your bossph account also depends on you maintaining the confidentiality of your login credentials. bossph strongly recommends enabling two-factor authentication (2FA) on your account and using a unique, strong password not shared with other platforms.
Your Data Rights
Under the Philippine Data Privacy Act of 2012, you hold the following rights in relation to the personal data bossph holds about you. bossph will respond to all rights requests within thirty (30) calendar days of receipt, or within such extended timeframe as permitted by the DPA where the request is complex or numerous.
Right to Be Informed
You have the right to be informed about how your personal data is collected, used, and processed by bossph — which is the primary purpose of this Privacy Policy.
Right to Access
You may request a copy of the personal data bossph holds about you, along with information about how it has been processed and with whom it has been shared.
Right to Correction
If any personal data bossph holds about you is inaccurate, incomplete, or outdated, you have the right to request that it be corrected. Some corrections can be made directly through your account settings.
Right to Erasure
You may request the deletion of your personal data where it is no longer necessary for the purposes collected, subject to bossph's legal obligations to retain certain records under PAGCOR and AMLA requirements.
Right to Object
You may object to the processing of your personal data for direct marketing purposes at any time. You may also object to processing based on legitimate interests where your specific situation warrants consideration.
Right to Data Portability
Where technically feasible and where processing is based on consent or contract, you may request that bossph provide your personal data in a structured, commonly used, and machine-readable format.
To exercise any of the rights above, please contact bossph's Data Protection Officer using the details in Section 14. bossph may need to verify your identity before processing a rights request to prevent unauthorized disclosure of personal data.
Cookies & Tracking Technologies
bossph uses cookies and similar tracking technologies on bossph.cam to ensure the platform functions correctly, to maintain your session state after login, to remember your preferences, and to gather aggregate analytics data that helps us improve the platform.
11.1 Types of Cookies Used
| Cookie Type | Purpose | Duration |
|---|---|---|
| Strictly Necessary | Session management, login state, security tokens | Session |
| Functional | Language preferences, game settings, display customisation | Up to 12 months |
| Analytics | Aggregate platform usage, page performance metrics | Up to 24 months |
| Security | Fraud detection, anomaly monitoring, bot prevention | Up to 12 months |
11.2 Managing Cookies
You may control cookie behaviour through your browser settings. Most browsers allow you to block or delete cookies. Note that blocking strictly necessary cookies will impair your ability to use the bossph platform, as they are required for session management and authentication. Analytics and functional cookies can be declined without affecting core platform access.
Minors
bossph's platform is strictly intended for individuals who are twenty-one (21) years of age or older, as mandated by PAGCOR. bossph does not knowingly collect personal data from individuals under 21 years of age. Age verification is a mandatory component of the bossph registration process.
If bossph becomes aware that personal data has been collected from an individual under the age of 21, that data will be deleted immediately, the associated account will be permanently suspended, and the matter will be escalated in accordance with applicable regulatory obligations.
21+ Age Requirement
The collection of personal data from minors for gambling purposes is strictly prohibited under both the DPA and PAGCOR regulations. If you have reason to believe that a minor has accessed bossph using false information, please report this to bossph support immediately at [email protected].
Updates to This Privacy Policy
bossph reviews and updates this Privacy Policy periodically to reflect changes in our data processing practices, platform operations, regulatory requirements, or applicable law. Material changes to this Policy will be communicated to registered players via the email address on file and/or through a notice displayed on the bossph platform prior to the change taking effect.
The "Last Updated" date displayed at the top of this Policy reflects the most recent revision. Your continued use of the bossph platform after the effective date of any amendment constitutes your acceptance of the updated Policy. If you do not agree with a material change, you should close your account before the amendment takes effect.
bossph recommends that you review this Privacy Policy periodically to stay informed about how your personal data is being handled. Previous versions of this Policy are available on request from the Data Protection Officer.
Contact & Complaints
For any questions, concerns, or requests relating to this Privacy Policy or to the exercise of your data rights under the DPA, please contact the bossph Data Protection Officer using the contact details below. All privacy-related requests will be acknowledged within five (5) business days and resolved within thirty (30) calendar days where possible.
Data Protection Officer — bossph
Email: [email protected]
Subject Line: "Privacy Request – [Your Name / Account Reference]"
Live Chat: Available 24/7 via the bossph platform
Response Time: Within 5 business days (acknowledgement); 30 days (resolution)
14.1 Complaints to the National Privacy Commission
If you believe that bossph has not adequately addressed a concern relating to the handling of your personal data, you have the right to lodge a complaint directly with the National Privacy Commission (NPC) of the Philippines. The NPC is the independent regulatory body responsible for the enforcement of the Data Privacy Act of 2012. Contact information for the NPC is publicly available through the Philippine government's official channels.
bossph encourages data subjects to contact the bossph DPO in the first instance before escalating to the NPC, as many concerns can be resolved directly and more efficiently through bossph's internal process.
Explore bossph with Confidence
Now that you know how bossph handles your data, head back to the platform — 500+ games, PHP wallet, GCash deposits, and a PAGCOR-licensed experience built for Filipino players. 21+ only.