MegaPari Privacy Policy

This Privacy Policy explains the collection, processing, protection, disclosure, and destruction of personal information across our online services. It sets out what data is collected, how it is used, and the safeguards applied to keep it secure. Processing is based on consent, contract, legal obligations, and legitimate interests. Users can withdraw consent at any time, subject to legal and regulatory limits. The document applies to all users accessing the website and related platforms.

Privacy and Data Protection

We collect personal information to provide and improve services, meet legal duties, and protect users and the platform.

Types of data include:

  • Identity and contact details: name, date of birth, address, email, phone.
  • Account and verification records: username, KYC files, ID documents, proof of address, age checks.
  • Payment and transaction information: deposits, withdrawals, card or e-wallet details processed by providers.
  • Technical and usage data: device identifiers, IP address, browser, operating system, app logs, gameplay and betting activity, preferences.
  • Responsible gaming data: limits, self-exclusion, affordability indicators when provided.
  • Communications: support tickets, chat transcripts, complaints, consent records.

Purposes for collection and processing:

  • Account registration, identity verification, age checks, and security.
  • Payments, withdrawals, transaction processing, and prevention of fraud and misuse.
  • Compliance with the Data Privacy Act of 2012, AML/CTF rules, and requests from regulators and law enforcement.
  • Service operation, analytics, product safety, and improvement of user experience.
  • Customer support and dispute resolution.

Technical and organizational security measures:

  • Transport Layer Security for data in transit and encryption for sensitive records at rest.
  • Role-based access controls, multi-factor authentication, and least-privilege access for staff.
  • Segregated environments, secure key management, audit logs, and change controls.
  • Regular vulnerability scanning, penetration testing, and incident response procedures.
  • Vendor due diligence and data processing agreements covering confidentiality and security.

User rights under Philippine law and applicable international standards:

  • Access: request a copy of personal data and information on processing.
  • Correction: update inaccurate or incomplete records.
  • Deletion: request erasure when no longer needed or when consent is withdrawn, subject to legal retention.
  • Portability: receive a copy in a commonly used format where technically feasible.
  • Restriction and objection: limit or object to certain processing.
  • Consent withdrawal: stop processing based on consent at any time.
  • Complaint: lodge a complaint with the National Privacy Commission.

Compliance statement:

  • Processing follows the Data Privacy Act of 2012, NPC issuances, anti-money laundering obligations, and, where relevant, GDPR principles for users in the EEA or for cross-border transfers.
  • Retention generally lasts for the life of the account and at least 5 years after account closure or last transaction to meet AML and regulatory requirements.

Use of Collected Information

We use information to deliver and secure online services and to meet legal and contractual duties:

  • Account management, identity verification, and user authentication.
  • Payment processing, refunds, chargeback handling, and transaction monitoring.
  • Compliance checks, KYC, AML/CTF screening, sanctions screening, and reporting to competent authorities when required.
  • Risk management, fraud prevention, security monitoring, and incident handling.
  • Service analytics, performance measurement, and product improvement.
  • Personalisation of content and settings, responsible gaming tools, and customer support.
  • Marketing messages and notifications based on consent or legitimate interest, with an option to opt out at any time.

Processing is lawful, necessary for the services, and carried out in a transparent manner aligned to stated purposes.

Access to Information

How users can access, update, or delete information:

  • Access and update: review and edit profile details through account settings or by contacting Support.
  • Correction: provide supporting documents if needed for identity or address changes.
  • Deletion: submit a request through the Contact page. Erasure will proceed unless retention is required by AML, tax, or dispute obligations.
  • Portability: request a machine-readable copy where feasible.

By using MegaPari, users consent to required security checks, identity verification, and the processing of payment information by payment providers and banks for transaction purposes.

Requests will be verified for identity and logged for compliance. Responses will be provided within timeframes set by the National Privacy Commission guidelines.

Protection of Children’s Privacy

The services are intended for adults 18 years old and above. Registration by minors is not permitted. The operator cannot verify age without appropriate documents during KYC or when reasonable doubts arise.

If a parent or guardian believes a minor has provided personal information, a request for deletion can be submitted through the Contact page. Once verified, the account will be closed and related data erased, unless retention is required for fraud prevention or legal purposes.

International Data Transfers

Personal information may be stored and processed in countries where service partners, payment providers, or support teams operate. Use of the site constitutes consent to these transfers, subject to safeguards.

To protect confidentiality and integrity during transfers:

  • Contractual safeguards such as data processing agreements and standard contractual clauses.
  • Vendor security reviews, ongoing monitoring, and documented instructions for processing.
  • Limited access, purpose restriction, and audit rights.

Partners are required to maintain equivalent confidentiality and security standards.

Use of Cookies

Cookies are small text files placed on a device to remember settings and preferences and to support secure and efficient operation of websites.

How cookies are used:

  • Essential cookies for login, security, and core features.
  • Functional cookies for preferences and experience personalisation.
  • Analytics cookies for statistics, performance measurement, and behaviour analysis.
  • Advertising cookies for measuring campaign reach and limiting repetitive ads, subject to consent.

Retention and control:

  • Cookie lifetime is up to 1 year unless removed earlier by the user.
  • Browser settings and the on-site cookie banner can be used to manage or refuse non-essential cookies.
  • Disabling certain cookies may affect access to some services or features.

Acceptance of Privacy Policy

Use of the services means full acceptance of this Privacy Policy and any related notices posted on the website. The current version published on this page prevails over previous versions.

Updates will be reflected by a revised effective date, and material changes will be communicated through the website or by direct notice when required by law. Continued use after updates constitutes acceptance of the updated document.

Third-Party Privacy Practices

Personal information may be shared with third parties when required by law, to resolve disputes, to enforce agreements, or to operate the services. Typical recipients include payment processors, banks, KYC and AML providers, analytics services, customer support tools, and auditors.

Lists of key processors and partners may be provided on the website or upon request. When sharing is not listed in advance, users will be informed of the purpose and scope where legally required. Providing information and continuing to use the services constitutes consent to such sharing, subject to contractual safeguards and purpose limitation.

Each third party maintains its own privacy practices and terms. Users are encouraged to review those policies.

Updated: