vipr2 Privacy Policy
This Privacy Policy explains how vipr2 collects, uses, stores, and protects your personal information when you use our platform. It is written in compliance with Republic Act No. 10173, the Data Privacy Act of 2012, and all associated implementing rules issued by the National Privacy Commission of the Philippines.
How vipr2 Handles Your Data
This summary is for your convenience only. The full legal text below governs in all cases. Please read the complete Policy before using the vipr2 platform.
What We Collect
Registration details, identity verification documents, payment information, device and browser data, and gameplay activity. We collect only what is necessary for service delivery, legal compliance, and account security.
How We Use It
To operate your account, process deposits and GCash withdrawals, verify your identity under PAGCOR KYC requirements, prevent fraud, personalize your experience, and meet our legal obligations to PAGCOR and the AMLC.
Who We Share It With
We do not sell your data. Limited sharing occurs with PAGCOR, the AMLC, licensed payment processors (GCash, PayMaya, banks), identity verification partners, and cloud infrastructure providers — all under strict data processing agreements.
How We Protect It
SSL/TLS encryption on all connections, AES-256 encryption at rest for sensitive data, role-based internal access controls, regular security audits, and strict data minimization principles throughout our systems.
How Long We Keep It
Active account data is retained for the duration of your account plus a mandatory post-closure period required by Philippine gaming and anti-money laundering law. Marketing data is deleted upon opt-out. Retention schedules are detailed in Section 8.
Your Rights
Under the Philippine Data Privacy Act, you have the right to access, correct, delete, object to, and port your personal data. You may also withdraw consent for optional data processing at any time. Exercise your rights via our support channel.
Table of Contents
1 Scope and Data Controller
1.1 This Privacy Policy applies to all personal information collected by vipr2 through the vipr2 website (vipr2.cam), its mobile-optimized interface, all games, features, support channels, and any other services offered under the vipr2 brand (collectively, the "Platform").
1.2 vipr2 acts as the Personal Information Controller (PIC) as defined under Republic Act No. 10173, the Data Privacy Act of 2012 of the Philippines ("DPA"). As PIC, vipr2 determines the purposes and means of processing your personal information and is responsible for ensuring that processing is conducted lawfully, fairly, and transparently.
1.3 This Policy is issued in compliance with:
- Republic Act No. 10173 — Data Privacy Act of 2012;
- Implementing Rules and Regulations of the DPA issued by the National Privacy Commission (NPC);
- PAGCOR Online Gaming Regulations applicable to licensed operators;
- Republic Act No. 9160 as amended — Anti-Money Laundering Act (AMLA).
2 Personal Information We Collect
2.1 Registration and Identity Data
When you create a vipr2 account, we collect your full legal name, date of birth, Philippine mobile number, email address (if provided), home address, and username. This information is required to establish your account and is necessary for age verification (21+ requirement under PAGCOR regulations) and KYC compliance.
2.2 Identity Verification (KYC) Documents
As required by PAGCOR, vipr2 must verify the identity of all registered players. For this purpose, we collect copies of government-issued identification documents, which may include:
- Philippine National ID (PhilSys)
- Philippine passport
- SSS, GSIS, or Unified Multi-Purpose ID
- Driver's license issued by the LTO
- Voter's ID or COMELEC registration
- PRC Professional ID
KYC documents are processed and stored in accordance with PAGCOR guidelines and are not used for any purpose beyond identity verification and regulatory compliance.
2.3 Financial and Transaction Data
We collect information about deposits, withdrawals, and in-game transactions, including amounts, timestamps, payment method identifiers (such as your GCash-linked mobile number, PayMaya account reference, or bank account details), and transaction reference numbers. Full payment card or bank account numbers are not stored by vipr2 — such data is handled exclusively by our licensed payment processors.
2.4 Technical and Device Data
When you access the Platform, we automatically collect certain technical information including your IP address, device type and operating system, browser type and version, session duration, pages visited, and referring URL. This data is used for security monitoring, fraud prevention, and service optimization.
2.5 Gameplay and Behavioral Data
We collect records of your gaming activity — games played, bet amounts, outcomes, session times, and bonus usage. This data is used to operate the Platform, detect unusual patterns that may indicate fraud or problem gambling, and comply with PAGCOR reporting requirements.
2.6 Communications Data
Records of your interactions with vipr2 support — including live chat transcripts and support emails — are retained for quality assurance, dispute resolution, and regulatory audit purposes.
3 Legal Basis for Processing
vipr2 processes your personal information on the following legal bases as recognized under the Philippine Data Privacy Act:
- Contractual Necessity: Processing required to perform the contract between you and vipr2 — specifically, operating your account, processing deposits and withdrawals, and delivering gaming services;
- Legal Obligation: Processing required to comply with PAGCOR regulations, AMLA reporting obligations, NPC requirements, and other applicable Philippine law;
- Legitimate Interests: Processing necessary for fraud detection, platform security, responsible gaming monitoring, and service improvement — where these interests are not overridden by your privacy rights;
- Consent: Processing for optional purposes such as marketing communications, where your prior explicit consent has been obtained. You may withdraw consent at any time.
4 How We Use Your Personal Information
vipr2 uses the personal information we collect for the following purposes:
- Creating, verifying, and managing your vipr2 account;
- Processing deposits and withdrawals through GCash, PayMaya, BPI, BDO, Metrobank, and other supported channels;
- Conducting KYC and age verification as required by PAGCOR;
- Detecting, investigating, and preventing fraud, money laundering, and unauthorized account access;
- Monitoring for problem gambling behavior and applying responsible gaming interventions where appropriate;
- Responding to your customer support inquiries and resolving disputes;
- Sending transactional communications — account confirmations, withdrawal notifications, security alerts, and material policy updates;
- Sending promotional and marketing communications, where you have consented;
- Complying with PAGCOR reporting, AMLC reporting, and NPC obligations;
- Improving Platform performance, game offerings, and user experience through aggregated analytics.
5 Cookies and Tracking Technologies
5.1 The vipr2 Platform uses cookies and similar tracking technologies to operate essential platform functions, maintain your session state, and analyze usage patterns. The categories of cookies we use are:
- Strictly Necessary Cookies: Required for the Platform to function. These cannot be disabled. They include session authentication tokens and security cookies.
- Functional Cookies: Remember your preferences such as language settings and last-played games. These improve your experience but are not essential.
- Analytics Cookies: Collect aggregated, anonymized data about how players use the Platform to help us improve performance and navigation.
- Marketing Cookies: Used only where you have explicitly consented to receive personalized promotional content.
5.2 You may manage non-essential cookies through your browser settings. Disabling strictly necessary cookies will impair or prevent Platform functionality.
5.3 vipr2 does not deploy third-party advertising networks or social media tracking pixels that transmit your personal data to unrelated platforms.
6 Disclosure to Third Parties
6.1 vipr2 shares your personal information only in the following limited circumstances:
- Regulatory Authorities: PAGCOR, the Anti-Money Laundering Council (AMLC), the National Privacy Commission (NPC), and other Philippine government agencies, as required by law or regulatory order;
- Payment Processors: GCash (G-Xchange Inc.), PayMaya, BPI, BDO, Metrobank, and other payment service providers, solely for the purpose of processing your financial transactions. These providers are bound by their own regulatory obligations and data processing agreements with vipr2;
- Identity Verification Providers: Licensed KYC and document verification service providers used to fulfill PAGCOR's verification requirements;
- Cloud Infrastructure Providers: Hosting, storage, and computing infrastructure providers operating under strict data processing agreements and security certifications;
- Legal Advisers and Auditors: External professional advisers bound by confidentiality obligations, engaged for legal, audit, or compliance purposes;
- Law Enforcement: Philippine law enforcement agencies where disclosure is required by a valid court order, warrant, or statutory obligation.
6.2 All third-party service providers who process personal data on vipr2's behalf are required to enter into data processing agreements that impose data protection obligations at least equivalent to those described in this Policy.
7 International Data Transfers
7.1 vipr2 primarily stores and processes personal data within the Republic of the Philippines or in data centers located in jurisdictions with data protection standards deemed adequate under NPC guidelines.
7.2 Where personal data is transferred to service providers operating outside the Philippines — such as cloud infrastructure providers with global data centers — vipr2 ensures that such transfers are governed by contractual protections consistent with the requirements of the Philippine Data Privacy Act, including standard data protection clauses or equivalent safeguards.
7.3 vipr2 does not transfer personal data to jurisdictions that lack adequate legal protections for personal information without implementing appropriate safeguards and, where required, notifying the NPC.
8 Data Retention
vipr2 retains personal information for no longer than is necessary for the purposes for which it was collected, subject to mandatory retention periods imposed by Philippine law. Our standard retention schedule is as follows:
- Account and identity data: For the duration of your active account plus five (5) years following account closure, as required by PAGCOR and AMLA regulations;
- Transaction records: Five (5) years from the date of each transaction, consistent with AMLA record-keeping requirements;
- KYC documents: Five (5) years from account closure or last transaction, whichever is later;
- Support communications: Two (2) years from the date of the interaction, or until the resolution of any related dispute;
- Analytics and behavioral data: Up to two (2) years in identifiable form, thereafter retained only in aggregated and anonymized form;
- Marketing preferences and consent records: Until withdrawn, plus one (1) year thereafter as proof of prior consent;
- Security and access logs: Twelve (12) months from collection.
Upon expiry of the applicable retention period, personal data is securely deleted or irreversibly anonymized using industry-standard methods.
9 Data Security
9.1 vipr2 implements a comprehensive set of technical and organizational security measures to protect your personal information from unauthorized access, disclosure, alteration, and destruction. These measures include:
- SSL/TLS 1.3 encryption on all data transmitted between your browser and our servers;
- AES-256 encryption for sensitive data stored at rest, including KYC documents and payment identifiers;
- Role-based access controls ensuring that personal data is accessible only to vipr2 personnel with a specific operational need;
- Multi-factor authentication requirements for all administrative access to systems containing personal data;
- Continuous security monitoring and automated anomaly detection;
- Regular independent security audits and penetration testing;
- Employee data privacy training and mandatory compliance acknowledgments.
9.2 While vipr2 implements these safeguards, no online system can guarantee absolute security. You are responsible for maintaining the security of your own account credentials. vipr2 will never ask for your password through any channel.
10 Your Data Subject Rights
Under the Philippine Data Privacy Act of 2012, you have the following rights in respect of your personal information held by vipr2:
To exercise any of these rights, contact the vipr2 Data Privacy Officer via the support channels listed in Section 15. We will respond to all verified requests within thirty (30) calendar days. Some requests may be subject to identity verification before processing. Certain rights may be limited where legal retention obligations require us to retain data.
If you are dissatisfied with our handling of a privacy request, you have the right to lodge a complaint with the National Privacy Commission of the Philippines.
11 Children and Minors
11.1 vipr2 does not direct any part of the Platform, its marketing, or its communications toward minors. Our registration process includes mandatory date-of-birth collection and age verification checks precisely to enforce this requirement.
11.2 Parents or guardians who believe a minor may have registered on vipr2 should contact our support team immediately. We will prioritize the investigation and take corrective action within 24 hours of a verified report.
12 Marketing Communications
12.1 vipr2 may send you promotional emails, SMS messages, and in-platform notifications about bonuses, new games, and platform updates. We will only send marketing communications if you have explicitly opted in during registration or subsequently through your account settings.
12.2 You may opt out of marketing communications at any time by:
- Updating your notification preferences in your vipr2 account settings;
- Contacting our support team via live chat and requesting removal from marketing lists.
12.3 Opting out of marketing communications does not affect transactional notifications — such as deposit confirmations, withdrawal status updates, and security alerts — which are required for the operation of your account.
12.4 vipr2 does not engage in unsolicited cold marketing. We do not purchase marketing lists or send communications to individuals who have not registered on the Platform.
13 Personal Data Breach Procedures
13.1 vipr2 maintains a documented Data Breach Response Plan. In the event of a personal data breach that is likely to result in risk to the rights and freedoms of affected players, vipr2 will:
- Notify the National Privacy Commission (NPC) within seventy-two (72) hours of becoming aware of the breach, as required under NPC Circular No. 16-03;
- Notify affected players without undue delay where the breach is likely to result in a high risk to their rights, providing clear information about the nature of the breach, the data involved, and protective actions they should take;
- Conduct a root cause analysis and implement remedial measures to prevent recurrence;
- Maintain a breach register as required by the DPA Implementing Rules.
13.2 If you suspect that your vipr2-related personal data has been compromised, contact our Data Privacy Officer immediately through the contact details in Section 15.
14 Amendments to This Policy
14.1 vipr2 may update this Privacy Policy from time to time to reflect changes in our data processing practices, regulatory requirements, or platform features. Material changes will be communicated to registered players via in-platform notification or email at least seven (7) days before the amendment takes effect.
14.2 The current version of this Policy, with its effective date, is always available on this page. Continued use of the vipr2 Platform after any amendment becomes effective constitutes acceptance of the revised Policy.
14.3 Where changes to this Policy require your renewed consent under the DPA, we will seek that consent before the new processing begins. If you do not consent to material changes, you may close your account in accordance with the process described in our Terms & Conditions.
15 Contact Us and Data Privacy Officer
vipr2 has designated a Data Privacy Officer (DPO) responsible for overseeing compliance with the Philippine Data Privacy Act and this Privacy Policy. For any privacy-related inquiries, data subject rights requests, or to report a suspected data breach, please contact us through the following channels:
- Live Chat: 24/7 via the vipr2 Platform — this is the fastest channel for urgent privacy matters
- Email: [email protected] — please include "Privacy Request" in the subject line
We aim to acknowledge all privacy inquiries within two (2) business days and to fully respond within thirty (30) calendar days. Complex requests may require additional time, in which case we will notify you of the extended timeline.
If you are not satisfied with our response to your privacy inquiry, you may escalate the matter to the National Privacy Commission of the Philippines, the government body responsible for enforcing the Data Privacy Act.
Your Data Is Safe at vipr2
We handle your personal information with the same care and speed we apply to your GCash withdrawals — seriously and without delay. A PAGCOR-regulated platform, Filipino support team, and NPC-compliant data practices, all working for you.
Must be 21 years or older. PAGCOR regulated. Gambling involves risk. Play responsibly.