aha33 Privacy Policy
At aha33, your personal data is handled with care and in full compliance with the Data Privacy Act of 2012 (Republic Act No. 10173). This Privacy Policy explains what information we collect, why we collect it, how we use it, and your rights as a data subject. We encourage you to read this document in full before using the aha33 platform.
Who We Are
aha33 ("we," "our," or "us") is the operator of the online gaming platform accessible at aha33.app. aha33 operates under the regulatory oversight of the Philippine Amusement and Gaming Corporation (PAGCOR) and is committed to upholding the privacy rights of all users in accordance with the Data Privacy Act of 2012 (Republic Act No. 10173) and its implementing rules and regulations issued by the National Privacy Commission (NPC).
For the purposes of this Privacy Policy, aha33 acts as the Personal Information Controller (PIC) in respect of the personal data you provide when registering for or using the aha33 platform. This means aha33 determines the purposes for which, and the manner in which, your personal data is processed.
This Privacy Policy applies to all personal data collected through the aha33 website, mobile applications, customer support channels, and any other touchpoints operated by aha33. It does not apply to third-party websites or services that may be linked to or from aha33 — those platforms maintain their own independent privacy policies.
Data We Collect
aha33 collects only the personal data that is necessary to provide you with a safe, compliant, and enjoyable gaming experience. The categories of personal data we collect include, but are not limited to, the following:
| Category | Examples | Required? |
|---|---|---|
| Identity Data | Full legal name, date of birth, nationality, government-issued ID number (e.g., PhilSys, passport, driver's license) | Yes — KYC / AML compliance |
| Contact Data | Email address, mobile number, residential address (barangay, city/municipality, province) | Yes — account communication |
| Account Data | Username, hashed password, account creation date, login history, device identifiers | Yes — platform access |
| Financial Data | Deposit and withdrawal records, payment method identifiers (e.g., GCash mobile number, bank account name), transaction amounts in PHP | Yes — payment processing & AML |
| Gaming Activity Data | Game history, wager amounts, win/loss records, session duration, bonus usage, sports betting selections | Yes — regulatory reporting |
| Technical Data | IP address, browser type and version, operating system, screen resolution, referring URL, cookie identifiers | Yes — fraud prevention & security |
| Communications Data | Live chat transcripts, support email correspondence, any documents submitted for KYC verification | Yes — customer support & dispute resolution |
| Marketing Preferences | Promotional opt-in/opt-out choices, preferred communication channel, language preference | Optional |
aha33 does not collect sensitive personal information as defined under the Data Privacy Act — such as racial or ethnic origin, political or religious beliefs, health data, or biometric data — unless specifically required by applicable law or regulatory mandate and only with your explicit consent where consent is the applicable legal basis.
How We Collect Your Data
aha33 collects your personal data through the following channels and methods:
- Direct registration: When you create an aha33 account, you provide your name, date of birth, contact details, and payment information directly through the registration form.
- KYC verification submissions: When you submit identity documents, selfies, or proof of payment method in response to a verification request from aha33 support or automated compliance systems.
- Platform activity: Your gaming behavior, transaction history, and session data are recorded automatically as you use the aha33 platform.
- Payment providers: When you transact via GCash, Maya, BPI, BDO, Metrobank, 7-Eleven, Coins.ph, or USDT TRC20, relevant transaction data is shared between the payment provider and aha33 to complete and record the transaction.
- Customer support interactions: Any communications you initiate with our support team via live chat or email are recorded and stored for quality assurance and dispute resolution purposes.
- Cookies and tracking technologies: Automated technical data is collected via cookies, web beacons, and similar technologies as described in Section 7 of this Privacy Policy.
- Third-party game providers: JILI and other integrated game studios may share aggregated or session-level gameplay data with aha33 for compliance, fraud prevention, and platform integrity purposes.
You are responsible for ensuring that all personal data you provide to aha33 is accurate, complete, and current. Providing false or misleading information during registration or verification is a breach of aha33's Terms & Conditions and may result in account closure and forfeiture of funds.
Why We Use Your Data
aha33 uses the personal data it collects for specific, legitimate purposes only. We do not process your data in ways that are incompatible with the purpose for which it was originally collected. The primary purposes for which we use your personal data are as follows:
- Account creation and management: To register your aha33 account, authenticate your identity on login, and manage your account settings and preferences throughout your use of the platform.
- Payment processing: To facilitate deposits and withdrawals in Philippine Peso (₱ PHP) through your chosen payment method, and to maintain accurate financial records of all transactions associated with your account.
- Regulatory compliance and AML: To fulfill aha33's obligations under PAGCOR regulations and the Anti-Money Laundering Act of 2001 (Republic Act No. 9160, as amended), including customer due diligence, transaction monitoring, and mandatory reporting to the Anti-Money Laundering Council (AMLC) where required by law.
- Identity verification (KYC): To verify that you are who you claim to be, that you meet the minimum age requirement of 21 years for casino-style gambling in the Philippines, and that you are not a politically exposed person (PEP) or a subject of sanctions lists.
- Fraud prevention and platform security: To detect, investigate, and prevent fraudulent activity, bonus abuse, multi-accounting, unauthorized access, collusion, and other activities that threaten the integrity of the platform or the safety of other users.
- Customer support: To respond to your inquiries, investigate complaints, resolve disputes, and provide technical assistance related to your aha33 account or gaming activity.
- Responsible gaming: To monitor gaming patterns, enforce self-exclusion requests, apply deposit limits, and provide reality-check notifications in support of aha33's responsible gaming commitments and PAGCOR's player protection requirements.
- Marketing and promotions: Where you have opted in, to send you information about aha33 promotions, bonuses, tournaments, and platform updates via email or in-platform notifications. You may opt out of marketing communications at any time.
- Platform improvement: To analyze aggregated and anonymized usage data to improve the performance, design, and content of the aha33 platform, including game selection, user interface, and payment flow optimization.
- Legal proceedings: To exercise or defend aha33's legal rights in the event of disputes, regulatory investigations, or court proceedings involving your account or activity on the platform.
Legal Basis for Processing
Under the Data Privacy Act of 2012, aha33 must have a lawful basis for each processing activity involving your personal data. The legal bases aha33 relies upon are:
- Contractual necessity: Processing that is necessary to perform our contract with you — i.e., to operate your aha33 account, process your transactions, and deliver the gaming services you have registered to use.
- Legal obligation: Processing that is required to comply with aha33's obligations under PAGCOR regulations, the Anti-Money Laundering Act, the Data Privacy Act, and other applicable Philippine laws and regulations.
- Legitimate interests: Processing that is necessary for aha33's legitimate business interests, including fraud prevention, platform security, and service improvement, provided that such interests are not overridden by your rights and freedoms as a data subject.
- Consent: For optional processing activities — such as marketing communications and certain non-essential cookies — aha33 will seek your prior, informed, and freely given consent. You may withdraw your consent at any time without affecting the lawfulness of processing conducted prior to withdrawal.
Sharing Your Data
aha33 does not sell, rent, or trade your personal data to third parties for their own marketing purposes. We share your personal data only in the following limited circumstances:
- Payment processors: GCash, Maya, BPI, BDO, Metrobank, 7-Eleven bill payment networks, Coins.ph, and USDT TRC20 processors receive the transaction data necessary to complete your deposit or withdrawal. Each of these providers maintains its own privacy policy and operates under applicable Philippine financial regulations.
- Game providers: Third-party game studios integrated into the aha33 platform (including JILI) may receive your account session data to facilitate gameplay, ensure fairness, and comply with their own licensing obligations.
- Regulatory authorities: aha33 is legally required to share relevant data with PAGCOR, the Anti-Money Laundering Council (AMLC), the National Privacy Commission (NPC), and other Philippine government authorities upon lawful request or as mandated by regulation.
- KYC and compliance service providers: aha33 may engage accredited third-party identity verification and AML screening services to assist with KYC procedures. These providers act as Personal Information Processors (PIPs) under binding data processing agreements that require them to handle your data solely on aha33's instructions and in compliance with the Data Privacy Act.
- IT and hosting providers: aha33's platform infrastructure is supported by technology service providers who may process technical data (including IP addresses and log data) in the course of providing hosting, security, and monitoring services. All such providers are bound by confidentiality and data protection obligations.
- Legal advisers and law enforcement: In cases involving suspected fraud, criminal activity, or legal proceedings, aha33 may disclose relevant data to its legal counsel, law enforcement agencies, or courts as required or permitted by law.
All third-party service providers who process personal data on behalf of aha33 are required to enter into written data processing agreements that impose data protection obligations consistent with the Data Privacy Act of 2012 and the NPC's implementing rules. aha33 remains responsible for ensuring that its processors handle your data appropriately.
Cookies & Tracking Technologies
aha33 uses cookies and similar tracking technologies on its website and platform to improve your experience, maintain session security, and analyze platform usage. A cookie is a small text file placed on your device by a website. Cookies cannot execute programs or deliver viruses to your device.
The types of cookies used by aha33 are as follows:
- Essential / Strictly Necessary Cookies: These are required for the platform to function correctly. They enable core features such as account login sessions, security tokens, and shopping cart / cashier functionality. These cookies cannot be disabled without disrupting your use of aha33.
- Functional Cookies: These remember your preferences and settings (such as your preferred language or notification settings) so that you do not have to re-enter them on each visit.
- Analytics Cookies: These help aha33 understand how users interact with the platform — for example, which games are most popular, where users spend the most time, and at which points in the registration flow users drop off. This data is collected in aggregate and is used solely to improve the aha33 platform.
- Security Cookies: These cookies support fraud prevention and bot detection systems by recording behavioral signals that distinguish legitimate users from automated tools.
You may control your cookie preferences through your browser settings. Most browsers allow you to block or delete cookies; however, disabling essential cookies may prevent you from accessing certain features of the aha33 platform. aha33 does not use third-party advertising cookies or cross-site behavioral tracking cookies.
Data Retention
aha33 retains your personal data only for as long as necessary to fulfill the purposes for which it was collected, and in accordance with applicable legal, regulatory, and contractual retention obligations. The key retention periods that apply to aha33 are:
- Account and identity data: Retained for a minimum of five (5) years following account closure, as required by PAGCOR regulations and anti-money laundering laws applicable to gaming operators in the Philippines.
- Financial transaction records: Retained for a minimum of five (5) years from the date of each transaction in compliance with AML record-keeping obligations under Republic Act No. 9160, as amended.
- KYC documentation: Retained for the duration of your account and for a minimum of five (5) years after account closure, in accordance with PAGCOR licensing conditions and AML requirements.
- Customer support records: Retained for three (3) years following the resolution of the relevant inquiry or dispute, unless a longer period is required for ongoing legal proceedings.
- Marketing preferences and opt-in records: Retained for the duration of your account and for a period of three (3) years following account closure or opt-out, to demonstrate compliance with consent requirements.
- Technical and log data: Typically retained for twelve (12) months, unless longer retention is required for an active security investigation or legal matter.
When your personal data is no longer required for any of the above purposes, aha33 will securely delete or anonymize it in accordance with industry-standard data disposal procedures. Anonymized data that no longer identifies you may be retained indefinitely for statistical and analytical purposes.
Data Security
aha33 takes the security of your personal data seriously and has implemented a range of technical and organizational measures designed to protect your information against unauthorized access, disclosure, alteration, and destruction. These measures include:
- Transport Layer Security (TLS / HTTPS) encryption for all data transmitted between your device and aha33's servers.
- Encryption of stored passwords using industry-standard one-way hashing algorithms — aha33 staff cannot view your password in plain text.
- Encryption of sensitive financial and identity data at rest using AES-256 or equivalent standards.
- Role-based access controls that restrict access to personal data to only those aha33 personnel and processors who require it to perform their job functions.
- Regular penetration testing, vulnerability scanning, and security audits conducted by qualified information security professionals.
- Multi-factor authentication (MFA) options for player accounts to protect against unauthorized login attempts.
- Real-time fraud monitoring and anomaly detection systems that flag suspicious account activity for immediate review.
While aha33 employs robust security measures, no online platform can guarantee absolute security. In the event of a personal data breach that is likely to result in harm to you, aha33 will notify you and the National Privacy Commission (NPC) within the timeframes required under the Data Privacy Act and NPC Circular No. 16-03. You are encouraged to protect your own account by using a strong, unique password and enabling MFA where available.
aha33 will never ask for your password via email, live chat, SMS, or any other communication channel. If you receive any communication purporting to be from aha33 that requests your password or full payment card details, treat it as a phishing attempt and report it immediately to [email protected].
International Data Transfers
aha33's primary operations are based in the Philippines. However, some of the third-party service providers we use — including cloud hosting providers, game studios, and KYC verification services — may process your personal data in data centers located outside the Philippines.
Where personal data is transferred to a country or territory outside the Philippines, aha33 ensures that appropriate safeguards are in place to protect your data to a standard equivalent to that required under the Data Privacy Act of 2012. These safeguards may include:
- Standard contractual clauses approved by the National Privacy Commission or equivalent data protection authority in the recipient country.
- Binding corporate rules where the transfer is to a member of aha33's corporate group.
- Adequacy decisions recognizing the recipient country as providing an adequate level of data protection.
If you would like further information about the specific safeguards applicable to a particular transfer, please contact us at the details provided in Section 14.
Your Rights as a Data Subject
Under the Data Privacy Act of 2012, you have the following rights with respect to your personal data held by aha33. To exercise any of these rights, please contact us as described in Section 14. aha33 will respond to your request within a reasonable period, typically within thirty (30) calendar days, unless a longer period is justified and communicated to you.
- Right to be informed: You have the right to be told how your personal data is being processed, including the identity of the controller, the purposes and legal basis of processing, and the recipients of your data. This Privacy Policy fulfills that obligation.
- Right of access: You may request a copy of the personal data aha33 holds about you, along with information about how it is being used. aha33 will provide this information in a structured, commonly used format.
- Right to rectification: If any personal data aha33 holds about you is inaccurate or incomplete, you have the right to request that it be corrected. Certain data fields (such as your registered legal name) may require documentary evidence before a correction can be processed.
- Right to erasure: In certain circumstances, you may request that aha33 delete your personal data. This right is subject to aha33's legal and regulatory data retention obligations; data that must be retained under PAGCOR regulations or AML laws cannot be erased on request before the applicable retention period has elapsed.
- Right to object: You have the right to object to the processing of your personal data for direct marketing purposes at any time. You may also object to processing based on aha33's legitimate interests, though aha33 may continue processing if it can demonstrate compelling legitimate grounds that override your interests.
- Right to data portability: Where technically feasible and legally applicable, you may request a copy of your personal data in a structured, machine-readable format so that it can be transferred to another service provider.
- Right to lodge a complaint: If you believe aha33 has violated your data privacy rights, you have the right to file a complaint with the National Privacy Commission (NPC) through its official channels at privacy.gov.ph. aha33 encourages you to contact us first so that we may attempt to resolve your concern directly.
To exercise any of the rights described above, please submit a written request to aha33 via [email protected]. Please include your registered username and a description of the right you wish to exercise. aha33 may ask you to verify your identity before processing your request. There is no fee for submitting a rights request; however, aha33 reserves the right to charge a reasonable fee for manifestly unfounded or excessive requests.
Children's Privacy
The aha33 platform is strictly intended for individuals aged 21 years and above, in accordance with PAGCOR regulations governing casino-style online gambling in the Philippines. aha33 does not knowingly collect, process, or retain personal data of individuals below the age of 21.
If aha33 discovers or has reasonable grounds to believe that an account has been registered by or on behalf of a person under the age of 21, aha33 will immediately suspend the account, initiate verification procedures, and if confirmed, permanently close the account and return any deposited funds (net of any winnings, which will be forfeited). Any personal data collected in connection with such an account will be deleted as soon as legally permissible following account closure.
If you are a parent or guardian and you believe your child has registered an aha33 account without your knowledge or consent, please contact us immediately at [email protected].
Changes to This Privacy Policy
aha33 reserves the right to update or amend this Privacy Policy at any time to reflect changes in our data processing practices, applicable law, or regulatory requirements. When material changes are made, aha33 will notify registered players via the platform or by email to the address associated with your account, and the "Last Updated" date at the top of this page will be revised accordingly.
Your continued use of the aha33 platform following notification of changes to this Privacy Policy constitutes your acknowledgment of and agreement to the updated policy. If you do not agree to the revised Privacy Policy, you should stop using the platform and may request account closure by contacting aha33 support. We encourage you to review this Privacy Policy periodically to stay informed about how we protect your personal data.
Contact Us
If you have any questions, concerns, or requests relating to this Privacy Policy or to the way aha33 processes your personal data, please reach out to our Data Privacy team through the following channels:
- Live Chat: Available 24/7 directly within the aha33 platform — the fastest way to reach our support team for urgent privacy concerns.
- Email: [email protected] — for formal written privacy inquiries, data subject rights requests, and complaints. Please allow up to two (2) business days for a response, and up to thirty (30) calendar days for rights requests to be fully processed.
When contacting us regarding a data privacy matter, please include your registered aha33 username, a clear description of your inquiry or request, and any relevant details that will help us locate and review the data concerned. aha33 may request proof of identity before processing a data subject rights request to ensure that we do not disclose or modify personal data in response to unauthorized requests.
By registering for or continuing to use the aha33 platform, you confirm that you have read and understood this Privacy Policy and consent to the collection, use, and processing of your personal data as described herein. This Privacy Policy was last reviewed and updated on January 1, 2026, and is effective from that date.
How aha33 Keeps Your Information Safe
A quick look at the key privacy safeguards built into every layer of the aha33 platform.
TLS Encryption on All Connections
Every byte of data exchanged between your device and aha33's servers is protected by TLS (HTTPS) encryption. Your login credentials, payment details, and personal information are never transmitted in plain text — making interception by third parties extremely difficult.
PAGCOR-Compliant KYC Process
aha33 follows a rigorous Know Your Customer process aligned with PAGCOR licensing requirements. Your identity documents are collected only when required, stored securely, and accessed only by authorized compliance personnel — never by third-party marketers.
No Data Sold to Advertisers
aha33 does not sell, rent, or trade your personal data to third-party advertisers. Your data is used exclusively for operating your account, processing payments, complying with regulations, and improving the aha33 platform. Period. That's the commitment we make to every Filipino player.
Data Privacy Act 2012 Compliance
aha33 operates in full compliance with Republic Act No. 10173, the Data Privacy Act of 2012, and the implementing rules issued by the National Privacy Commission. As your Personal Information Controller, aha33 upholds all data subject rights recognized under Philippine law.
Password Hashing & MFA Support
Your aha33 password is never stored in plain text. We use industry-standard one-way hashing so that even aha33 staff cannot read your password. Multi-factor authentication (MFA) is available to add an extra layer of protection to your account against unauthorized access attempts.
Responsible Retention & Secure Deletion
aha33 retains your personal data only as long as legally required — typically five years for financial and identity records under PAGCOR and AML rules. Once the retention period ends, your data is securely deleted or anonymized using industry-standard disposal procedures.
Experience aha33 — Safely & Responsibly
Now that you know exactly how aha33 protects your personal data, you can play JILI slots, live dealer tables, bingo, and PBA sports betting with full confidence. Join thousands of Filipino players already enjoying the platform — your privacy is always our priority.
For players 21 years and older only. Please gamble responsibly. aha33 is regulated by PAGCOR.