Privacy Policy
At tayagm, we treat your personal data with the same level of care and precision we bring to every aspect of our platform. This Privacy Policy explains exactly what data we collect, why we collect it, how we protect it, and what rights you hold as a tayagm player under Philippine law.
How tayagm Protects Your Data
These cards highlight the core principles of the tayagm Privacy Policy. The full legal text follows in the sections below — please read the complete policy before using the platform.
Minimal Data Collection
tayagm only collects personal data that is strictly necessary for account registration, identity verification, payment processing, and PAGCOR regulatory compliance. We do not collect data for purposes beyond those disclosed in this policy, and we do not sell your personal information to third parties for any purpose — commercial or otherwise.
End-to-End Encryption
All data transmitted between your device and the tayagm platform is encrypted using industry-standard TLS protocols. Sensitive data at rest — including payment details and identity documents — is stored in encrypted form using AES-256 encryption. Your KYC documents are stored in isolated, access-controlled storage environments with audit logging enabled.
Your Rights Under RA 10173
As a tayagm player, you have enforceable rights under the Philippine Data Privacy Act of 2012 (Republic Act No. 10173) — including the right to access your data, request corrections, withdraw consent, and request deletion where permitted by law. tayagm provides a straightforward process for exercising each of these rights through your account dashboard or via live chat support.
Controlled Third-Party Sharing
tayagm shares your data only with regulated third-party processors — such as KYC verification providers, payment gateways, and fraud detection services — under strict data processing agreements. Every third-party partner is vetted for compliance with RA 10173. We do not share your data with advertisers, data brokers, or any party outside the scope of platform operations.
Defined Retention Periods
tayagm retains personal data only for as long as is required by law or necessary for the purposes for which it was collected. Account and transaction records are retained for a minimum of five years to meet PAGCOR and anti-money laundering regulatory requirements. Where retention is no longer required, data is securely deleted or anonymised.
Marketing Opt-Out Anytime
tayagm sends promotional communications only to players who have opted in at registration or through account preferences. You can withdraw your consent for marketing communications at any time through your account settings or by contacting tayagm support. Opt-out requests are processed within two Philippine business days. Transactional and regulatory communications are not affected by marketing opt-out.
Introduction
This Privacy Policy ("Policy") describes how tayagm ("we", "us", "our", "the Platform") collects, uses, processes, stores, and protects the personal data of individuals ("you", "the User", "the Player") who access or use the services available at tayagm.ws and all associated subdomains and mobile applications.
tayagm is committed to protecting your privacy and handling your personal data in full compliance with the Republic Act No. 10173, otherwise known as the Data Privacy Act of 2012 (DPA), its Implementing Rules and Regulations, and any issuances by the National Privacy Commission (NPC) of the Philippines. Where applicable, we also comply with PAGCOR's data governance requirements for licensed online gaming operators.
This Policy applies to all personal data collected through your use of the tayagm platform, including during account registration, identity verification, gameplay, financial transactions, customer support interactions, and any marketing communications you have consented to receive.
By registering a tayagm account or using any part of our platform, you confirm that you have read and understood this Privacy Policy and consent to the collection and processing of your personal data as described herein. If you do not agree with this Policy, you must not register an account or use the tayagm platform.
This Policy was last updated and effective as of 1 January 2026. The current version is always available at tayagm.ws/privacy-policy.
Who We Are
tayagm is a PAGCOR-regulated online gaming platform operating under Philippine law. The platform offers Filipino players access to a curated selection of online slots, live casino games, sports betting, sabong, bingo, and promotional gaming events — all denominated in Philippine Peso (PHP) and accessible via local payment methods including GCash, PayMaya, BPI, BDO, Metrobank, and 7-Eleven.
For the purposes of the Data Privacy Act of 2012, tayagm is the Personal Information Controller (PIC) with respect to the personal data of registered players and website visitors. This means tayagm determines the purposes and means of processing your personal data and bears primary responsibility for ensuring that such processing is lawful, fair, and transparent.
Where tayagm engages third-party service providers to process personal data on its behalf — such as KYC verification platforms, payment processors, and fraud detection services — those third parties act as Personal Information Processors (PIPs) under data processing agreements that impose equivalent obligations as required by the DPA.
For all privacy-related enquiries, you may contact our Data Protection Officer (DPO) via the contact details provided in Section 14 of this Policy.
Personal Data We Collect
tayagm collects personal data through several channels: directly from you when you register and use the platform; automatically through your use of the platform; and from regulated third-party verification and fraud-prevention services. The categories of personal data collected are described below.
3.1 Registration and Account Data
- Full legal name (as it appears on your government-issued ID)
- Date of birth (used to verify you are 21 years of age or older)
- Email address and Philippine mobile number
- Current residential address within the Philippines
- Username and encrypted account credentials
3.2 Identity Verification (KYC) Data
- Copies of government-issued identification documents (PhilSys, Passport, LTO Driver's Licence, SSS ID, PRC ID, or UMID)
- Proof of address documents (utility bills or bank statements)
- Selfie or liveness check images used for biometric ID matching
- Source of funds documentation where applicable for high-value accounts
3.3 Financial and Transaction Data
- Deposit and withdrawal amounts, dates, and methods (GCash, PayMaya, BPI, BDO, Metrobank, 7-Eleven)
- GCash and PayMaya account reference numbers (partial, for reconciliation only)
- Bank account details used for withdrawal processing (account name and partial account number only)
- Transaction history and account balance records
3.4 Gameplay and Betting Data
- Game session logs, bet amounts, game outcomes, and win/loss records
- Responsible gaming tool settings (deposit limits, loss limits, self-exclusion status)
- Bonus and promotional credit usage history
3.5 Technical and Usage Data
- IP address and approximate geolocation (country and region level)
- Device type, operating system, and browser information
- Platform access timestamps and session duration
- Cookie and similar tracking technology data (see Section 7)
3.6 Communications Data
- Customer support chat transcripts and email correspondence
- Feedback and complaint records
- Marketing communication preferences and opt-in/opt-out records
We do not collect: full payment card numbers, CVV codes, or full bank account numbers. Payment processing is handled by regulated payment gateways that are independently PCI-DSS compliant. tayagm receives only the transaction reference and status confirmation necessary for account crediting purposes.
How We Use Your Personal Data
tayagm uses your personal data for the following purposes. Each processing activity is linked to a specific legal basis as described in Section 5.
| Purpose | Data Categories Used | Legal Basis |
|---|---|---|
| Account registration and management | Registration data, account credentials | Contractual necessity |
| Identity verification and KYC compliance | KYC documents, biometric check data | Legal obligation (PAGCOR, AML) |
| Processing deposits and withdrawals | Financial and transaction data | Contractual necessity |
| Fraud detection and AML monitoring | Transaction data, technical data, KYC data | Legal obligation, legitimate interest |
| Responsible gaming monitoring | Gameplay data, responsible gaming settings | Legal obligation (PAGCOR), legitimate interest |
| Customer support and dispute resolution | Communications data, account data | Contractual necessity |
| Regulatory reporting to PAGCOR | All categories as required by PAGCOR | Legal obligation |
| Platform security and abuse prevention | Technical data, account data | Legitimate interest |
| Marketing communications (opt-in only) | Registration data, communication preferences | Consent |
| Platform analytics and improvement | Anonymised/aggregated usage data | Legitimate interest |
tayagm does not use automated decision-making that produces legal or similarly significant effects on individual players, except where explicitly required by PAGCOR compliance procedures (such as automated flagging of accounts that trigger AML thresholds for human review). In all such cases, human review follows the automated flag before any account action is taken.
Legal Basis for Processing
Under the Data Privacy Act of 2012, tayagm is required to identify a lawful basis for each processing activity involving your personal data. tayagm relies on the following legal bases:
- Contractual Necessity: Processing that is necessary for the performance of the agreement between you and tayagm — including maintaining your account, processing transactions, and providing gaming services. Without this processing, tayagm cannot provide you with the platform's services.
- Legal Obligation: Processing required by Philippine law, PAGCOR regulations, anti-money laundering legislation (Republic Act No. 9160 as amended), and the Data Privacy Act itself. This includes KYC verification, transaction monitoring, and regulatory reporting. tayagm cannot opt out of this processing and neither can you as a platform user.
- Legitimate Interest: Processing that serves a legitimate interest of tayagm or its users where that interest is not overridden by your privacy rights — for example, fraud prevention, platform security, and aggregated analytics used to improve the platform. tayagm has assessed these interests against your privacy rights and is satisfied that the processing is proportionate.
- Consent: Processing that is based on your freely given, specific, and informed consent — primarily marketing communications. You may withdraw consent at any time through your account settings without affecting the lawfulness of processing that occurred prior to withdrawal.
Note: Where processing is based on legal obligation — particularly PAGCOR compliance and AML requirements — tayagm cannot honour requests to restrict or delete that data while the legal obligation remains in effect. Your rights under Section 10 are subject to these legal retention requirements.
Sharing Your Data with Third Parties
tayagm shares personal data with third parties only to the extent necessary for the purposes described in this Policy. tayagm does not sell, rent, or trade your personal data to any third party for commercial gain. The categories of third parties with whom tayagm may share your data, and the basis for doing so, are described below.
- KYC and Identity Verification Providers: Regulated third-party platforms engaged by tayagm to perform identity document verification, liveness checks, and AML screening as required by PAGCOR. These providers act as Personal Information Processors under binding data processing agreements.
- Payment Processors and Gateways: Regulated financial institutions and payment service providers (including GCash, PayMaya, and banking partners) engaged to process deposits and withdrawals. tayagm shares only the data necessary to facilitate each specific transaction.
- Fraud Detection and AML Services: Specialist third-party platforms used to screen transactions and player activity for fraud indicators and potential money laundering patterns, as required by Philippine AML law and PAGCOR regulations.
- Responsible Gaming Service Providers: Third-party operators of responsible gaming tools (including national exclusion register checking services) engaged by tayagm in connection with its PAGCOR-mandated responsible gaming obligations.
- PAGCOR and Philippine Government Authorities: As the licensing and regulatory authority for tayagm, PAGCOR may require disclosure of player data for regulatory examination, audit, or investigation purposes. tayagm is legally obligated to comply with such requirements. Similarly, law enforcement and other government authorities may lawfully require disclosure under valid legal process, which tayagm will honour.
- Legal and Professional Advisors: Lawyers, auditors, and compliance consultants engaged by tayagm under appropriate confidentiality obligations, where access to personal data is necessary for the provision of their services.
All third-party processors engaged by tayagm are required to process your personal data only for the specified purpose, to implement appropriate security measures, to comply with the Data Privacy Act of 2012, and to notify tayagm promptly of any data breach affecting your personal data.
Cookies & Tracking Technologies
tayagm uses cookies and similar tracking technologies on its web platform to ensure the proper functioning of the site, enhance your experience, and support security and compliance operations. The types of cookies used by tayagm are described in the table below.
| Cookie Type | Purpose | Retention | Can Be Disabled? |
|---|---|---|---|
| Strictly Necessary | Session authentication, security tokens, CSRF protection, load balancing | Session / up to 24 hours | No — platform will not function correctly without these |
| Functional | Language preferences, game display settings, responsible gaming tool states | Up to 12 months | Yes — but some platform features may be limited |
| Analytical | Anonymised aggregated usage statistics used to improve the platform | Up to 13 months | Yes — via cookie preference settings |
| Security & Fraud Prevention | Device fingerprinting for multi-account and bot detection in compliance with PAGCOR obligations | Up to 12 months | No — required for regulatory compliance |
tayagm does not use advertising or cross-site tracking cookies. Analytical cookies use anonymised and aggregated data only — individual players are not identifiable from analytical cookie data.
You can manage your cookie preferences through the cookie settings panel available on the tayagm platform. Please note that disabling strictly necessary and security cookies will prevent you from logging in and using the platform.
Data Retention
tayagm retains your personal data for the minimum period necessary to fulfil the purpose for which it was collected, and in any event for no longer than required by applicable Philippine law and PAGCOR regulations. The following retention periods apply:
- Account and registration data: Retained for the duration of your account and for a minimum of five (5) years following account closure, in compliance with PAGCOR record-keeping requirements and the Anti-Money Laundering Act.
- KYC and identity verification documents: Retained for a minimum of five (5) years from the date of verification, or from the date of account closure, whichever is later — as required by PAGCOR and Republic Act No. 9160.
- Financial transaction records: Retained for a minimum of five (5) years from the date of each transaction, as required by Philippine AML law and PAGCOR regulations.
- Gameplay and betting records: Retained for a minimum of five (5) years following account closure, for dispute resolution and regulatory audit purposes.
- Customer support communications: Retained for three (3) years from the date of each communication, for dispute resolution and quality assurance purposes.
- Marketing consent records: Retained for the duration of your account and for three (3) years following withdrawal of consent or account closure, to demonstrate compliance with consent obligations.
- Technical and usage data (non-anonymised): Retained for a maximum of thirteen (13) months before anonymisation or deletion, unless required for an active security or fraud investigation.
Upon expiry of the applicable retention period, personal data is securely deleted or irreversibly anonymised. tayagm maintains a formal data retention schedule that is reviewed annually to ensure alignment with current legal requirements.
Data Security
tayagm implements a comprehensive set of technical and organisational security measures designed to protect your personal data against unauthorised access, disclosure, alteration, and destruction. These measures include but are not limited to:
- Encryption in transit: All data transmitted between your device and tayagm's servers is encrypted using TLS 1.2 or higher. Connections using outdated protocols are rejected.
- Encryption at rest: Sensitive personal data and identity documents stored in tayagm's systems are encrypted using AES-256 encryption.
- Access controls: Access to personal data is restricted on a strict need-to-know basis. tayagm staff are granted the minimum level of access required for their specific role. All access to production data environments is logged and audited.
- Multi-factor authentication: Administrative access to systems containing personal data requires multi-factor authentication. tayagm also offers and encourages players to enable MFA on their player accounts.
- Penetration testing and vulnerability management: tayagm conducts regular security assessments and penetration tests on its platform infrastructure.
- Data breach response: tayagm maintains a formal data breach response plan. In the event of a personal data breach that is likely to prejudice your rights, tayagm will notify the National Privacy Commission within 72 hours of discovering the breach and will notify affected players without undue delay, in compliance with NPC Circular 16-03.
Your responsibility: The security of your tayagm account also depends on your own actions. Please use a strong, unique password for your tayagm account, enable two-factor authentication, and never share your login credentials with any other person. tayagm will never ask you for your password or PIN through any communication channel.
Your Data Rights
As a data subject under the Philippine Data Privacy Act of 2012, you have the following rights with respect to your personal data held by tayagm. You may exercise any of these rights by contacting tayagm's Data Protection Officer using the contact details in Section 14, or through the account settings panel where indicated.
Right to Access
You have the right to request a copy of the personal data tayagm holds about you, together with information about how it is being processed. Requests are fulfilled within 15 Philippine business days.
Right to Rectification
You have the right to request correction of inaccurate or incomplete personal data. For account data such as your address or contact number, you can update these directly through account settings.
Right to Erasure
You may request deletion of your personal data where it is no longer necessary for its original purpose and no legal retention requirement applies. Note that PAGCOR and AML obligations require us to retain certain records for a minimum of five years.
Right to Object / Restrict Processing
You may object to or request restriction of processing based on legitimate interest. This right does not apply to processing based on legal obligation or contractual necessity.
Right to Data Portability
You have the right to receive a copy of your personal data in a structured, commonly used, and machine-readable format, and to transmit that data to another controller where technically feasible and where the processing is based on consent or contract.
Right to Withdraw Consent
Where processing is based on your consent (e.g., marketing communications), you may withdraw that consent at any time through account settings or by contacting support. Withdrawal does not affect the lawfulness of prior processing.
Right to Lodge a Complaint
If you believe tayagm has not handled your personal data in compliance with the Data Privacy Act of 2012, you have the right to file a complaint with the National Privacy Commission (NPC) of the Philippines at privacy.gov.ph.
Right to File Damages
Under RA 10173, you have the right to be indemnified for damages sustained due to inaccurate, incomplete, outdated, false, unlawfully obtained, or unauthorised use of your personal data, subject to applicable law and NPC procedures.
Children's Privacy and Age Restriction
The tayagm platform is strictly restricted to individuals who are 21 years of age or older, in accordance with Philippine law governing online casino-style gaming and PAGCOR's licensing conditions. The platform is not directed at, and does not knowingly collect personal data from, any person under the age of 21.
All registration applicants are required to provide their date of birth and to submit government-issued identity documents confirming their age as part of the mandatory KYC process. Accounts where the player is found to be under 21 years of age will be immediately suspended, all funds returned to the verified payment source, and the account permanently closed.
If tayagm discovers or is notified that personal data has been collected from a person under 21 years of age, we will take immediate steps to verify the matter, delete the data concerned, and close the account. If you are a parent or guardian and believe that a minor has registered an account with tayagm, please contact our Data Protection Officer immediately using the contact details in Section 14.
Age Restriction Notice: Only players aged 21 years and above are permitted to register and participate on the tayagm platform. Gambling can be addictive — please play responsibly. If you or someone you know is affected by problem gambling, contact the PAGCOR responsible gaming helpline.
Cross-Border Data Transfers
tayagm primarily processes and stores your personal data within the Philippines. However, in certain circumstances, personal data may be transferred to and processed by third-party service providers operating outside the Philippines — for example, KYC verification platforms or fraud detection services that operate regional or global infrastructure.
Where such cross-border transfers occur, tayagm ensures that:
- The recipient country, organisation, or system has been evaluated and determined to provide an adequate level of protection equivalent to that afforded by the Data Privacy Act of 2012;
- Appropriate contractual safeguards are in place with the receiving party, including data processing agreements that impose obligations consistent with RA 10173; and
- The transfer is limited to the minimum data necessary for the specific processing purpose, and the receiving party is prohibited from using the data for any purpose other than that specified.
tayagm does not transfer personal data to countries or organisations that have been assessed as providing inadequate data protection, unless an alternative lawful basis under the DPA applies and the transfer is subject to enhanced contractual protections.
Amendments to This Policy
tayagm reserves the right to update, amend, or replace this Privacy Policy at any time to reflect changes in Philippine law, NPC regulations, PAGCOR requirements, or our data processing practices. The effective date of the current version is always displayed at the top of this page.
Where amendments are material — meaning they significantly affect how your data is used or your rights in relation to it — tayagm will notify registered players via email to the address associated with their account and/or via a prominent notice on the platform, at least fourteen (14) calendar days before the amended Policy takes effect.
Minor amendments — such as clarifications of existing practices, corrections of typographical errors, or updates to contact details — may be made without advance notice. Your continued use of the tayagm platform after the effective date of any amendment constitutes your acceptance of the updated Policy. If you do not accept the amended Policy, you must cease using the platform and may request account closure.
All previous versions of this Privacy Policy are archived and available upon request from our Data Protection Officer.
Contact & Data Protection Officer
tayagm has designated a Data Protection Officer (DPO) in compliance with Section 21 of the Data Privacy Act of 2012 and its Implementing Rules and Regulations. The DPO is responsible for overseeing tayagm's compliance with RA 10173, serving as the point of contact for data subjects exercising their rights, and liaising with the National Privacy Commission.
To exercise your data rights, submit a privacy enquiry, report a suspected data breach affecting your account, or for any other privacy-related matter, please contact the tayagm Data Protection Officer through the following channel:
Email: [email protected]
Subject line: Please use "Data Privacy Request – [Your Account Username]" to ensure your request is routed to the DPO promptly.
Response time: tayagm will acknowledge your request within two (2) Philippine business days and will fulfil substantive requests within fifteen (15) Philippine business days from the date of acknowledgement. Complex requests may require an extension, which we will communicate to you in advance.
If you are not satisfied with tayagm's response to your privacy request or complaint, you have the right to escalate your complaint to the National Privacy Commission of the Philippines at privacy.gov.ph.
Experience tayagm — Secure, Fair & PAGCOR-Regulated
Now that you've reviewed the tayagm Privacy Policy, you can play with full confidence that your personal data is protected under Philippine law. Slots, live casino, bingo, sabong, and sports betting — all in PHP with local payment options. Players must be 21 years of age or older to participate.