About This Privacy Policy
This Privacy Policy ("Policy") is issued by sb777 ("sb777," "we," "us," or "our") and describes how we collect, use, disclose, retain, and protect personal data in connection with your use of the sb777 online casino and sports betting platform accessible at https://sb777.bio (the "Platform"), including all services, games, and features offered through the Platform.
This Policy applies to all registered users of sb777, visitors to the Platform, and individuals whose personal data we process in connection with the operation of our services. It should be read alongside the sb777 Terms & Conditions and Responsible Gaming Policy.
sb777 is committed to protecting your personal data in accordance with the Data Privacy Act of 2012 (Republic Act No. 10173) of the Republic of the Philippines ("DPA") and its Implementing Rules and Regulations, as administered by the National Privacy Commission (NPC). The Platform also processes data in compliance with the requirements of the Philippine Amusement and Gaming Corporation (PAGCOR) as a condition of our operating licence.
This Policy was last updated on 1 January 2026. Please review it periodically. Continued use of the sb777 Platform after changes are published constitutes your acceptance of the updated Policy.
Data Controller Identity
For the purposes of the Data Privacy Act of 2012, the data controller responsible for the personal data collected through the sb777 Platform is:
sb777
https://sb777.bio
PAGCOR (Philippine Amusement and Gaming Corporation)
As data controller, sb777 determines the purposes and means of processing your personal data and is responsible for ensuring that processing activities comply with the DPA and applicable PAGCOR data governance requirements. Where sb777 engages third-party service providers to process personal data on its behalf, those providers act as data processors under written data processing agreements that impose obligations equivalent to those required under Philippine law.
Personal Data We Collect
sb777 collects personal data through three primary channels: information you provide directly, data generated by your use of the Platform, and data received from third-party sources. The following describes the categories of personal data we collect:
3.1 Registration and Account DataWhen you create an sb777 account, we collect:
- Full legal name as it appears on a government-issued ID
- Date of birth (for age verification — 21+ requirement under PAGCOR regulations)
- Philippine mobile number (used as primary account identifier and for OTP verification)
- Email address
- Username and password (password stored in encrypted, hashed form only)
- Residential address (required for full KYC verification prior to first withdrawal)
Before processing your first withdrawal, sb777 collects copies of government-issued identification documents to satisfy PAGCOR KYC (Know Your Customer) requirements. Acceptable documents include UMID, PhilSys National ID, Philippine Passport, Driver's License (LTO), PRC ID, and Postal ID. A selfie photograph may be requested alongside the document for liveness verification purposes.
3.3 Financial and Transaction Data- GCash number or PayMaya account details used for deposit and withdrawal
- Bank account details (BDO, BPI, Metrobank) where used for transactions
- Deposit history, withdrawal history, and transaction amounts in Philippine Peso (PHP)
- Cryptocurrency wallet addresses where USDT transactions are processed
- Game session records, including game titles played, session duration, and timestamps
- Wager amounts, game results, and win/loss data
- Bonus claims, wagering progress, and promotion redemptions
- Sports betting selections, odds accepted, and bet settlement records
- IP address and approximate geolocation data derived from IP
- Device type, operating system, and browser type
- Cookie identifiers and session tokens (see Section 7)
- Platform access logs, including login timestamps and session durations
Where you contact sb777 via live chat, email, or any other support channel, we retain records of those communications, including the content of your messages, the date and time of contact, and the resolution provided. This applies to support queries, complaints, and responsible gaming requests.
3.7 Data We Do Not Collectsb777 does not collect sensitive personal information beyond what is strictly necessary for age and identity verification. We do not collect information relating to race, religion, health conditions, or political opinions. We do not store full card numbers — card payments are processed through PCI-DSS compliant payment gateways that tokenize card data.
How We Use Your Personal Data
sb777 uses the personal data collected for the following purposes. Each purpose is matched to a lawful basis of processing under the Data Privacy Act of 2012 (see Section 5):
| Purpose | Description | Lawful Basis |
|---|---|---|
| Account Management | Creating and maintaining your sb777 account, authenticating logins, and enabling access to platform services. | Contract |
| Identity & Age Verification | Verifying that you are at least 21 years old and confirming your identity in compliance with PAGCOR regulations and the Anti-Money Laundering Act. | Legal Obligation |
| Transaction Processing | Processing deposits and withdrawals via GCash, PayMaya, BDO, BPI, Metrobank, Visa, Mastercard, and USDT in Philippine Peso. | Contract |
| Fraud & AML Prevention | Detecting, investigating, and preventing fraudulent transactions, bonus abuse, money laundering, and account takeover attempts as required under Philippine law. | Legal Obligation |
| Responsible Gaming | Monitoring gaming patterns to identify potentially problematic behavior, managing deposit limits, loss limits, and self-exclusion tools. | Legitimate Interest |
| PAGCOR Regulatory Reporting | Submitting required transaction and player reports to PAGCOR as mandated by our operating licence conditions. | Legal Obligation |
| Customer Support | Responding to queries, resolving disputes, processing complaints, and maintaining communication records. | Contract |
| Platform Improvement | Analyzing aggregated, anonymized usage data to improve game selection, site performance, and user experience. | Legitimate Interest |
| Promotions & Marketing | Sending promotional emails, in-platform notifications, and personalized offers where you have opted in or where permitted under applicable law. | Consent |
| Security & Access Logs | Maintaining audit logs of platform access and transactions for security, investigation, and regulatory compliance purposes. | Legal Obligation |
Legal Bases for Processing
Under the Data Privacy Act of 2012, sb777 processes personal data on the following lawful bases:
- Performance of a Contract: Processing necessary to provide the sb777 platform services you have registered for, including account management, game access, and financial transactions.
- Legal Obligation: Processing required to comply with Philippine law, including the Data Privacy Act, Anti-Money Laundering Act (AMLA), PAGCOR licence conditions, tax obligations, and court orders.
- Legitimate Interest: Processing for purposes that serve the legitimate business interests of sb777, including platform security, fraud prevention, and service improvement, provided those interests are not overridden by your fundamental rights and freedoms.
- Consent: Processing for purposes where we have obtained your prior, informed, specific, and freely-given consent, such as marketing communications. You may withdraw consent at any time without affecting the lawfulness of processing conducted prior to withdrawal.
Where processing is based on legitimate interest, sb777 has conducted a legitimate interest assessment to confirm that our interests are not overridden by your rights. You may request details of this assessment by contacting the sb777 Data Protection Officer at the address in Section 14.
Sharing Your Personal Data
sb777 shares personal data with trusted third-party service providers who process data on our behalf under written data processing agreements. These include: payment processing partners (GCash, PayMaya, banking institutions), KYC and identity verification providers, gaming software providers, cloud infrastructure providers, fraud detection services, and customer support platform providers. These processors are authorized to use your data only for the specific purposes sb777 has directed and are prohibited from using it for their own independent commercial purposes.
6.2 Regulatory and Law Enforcement Authoritiessb777 is required to disclose personal data to regulatory and law enforcement authorities in the following circumstances: PAGCOR reporting obligations, Anti-Money Laundering Council (AMLC) reports under the Anti-Money Laundering Act, compliance with lawful court orders or judicial processes, and responses to legally valid requests from Philippine government agencies.
6.3 Business TransfersIn the event that sb777 undergoes a merger, acquisition, restructuring, or sale of all or part of its assets, personal data held by sb777 may be transferred to the successor entity as part of that transaction. In such circumstances, sb777 will provide reasonable notice to affected users and ensure that the successor entity assumes equivalent data protection obligations.
6.4 No Sale of Personal Datasb777 does not sell, rent, or trade your personal data to third parties for their own commercial or marketing purposes. Any sharing of data is limited to what is necessary for the legitimate purposes described in this Policy and is subject to appropriate contractual safeguards.
Cookies & Tracking Technologies
Cookies are small text files placed on your device when you visit the sb777 Platform. They allow sb777 to recognize your device, maintain your session state, and improve your experience. sb777 also uses similar tracking technologies including web beacons, pixel tags, and local storage.
7.2 Categories of Cookies Used by sb777- Strictly Necessary Cookies: Essential for the operation of the sb777 Platform, including session management, authentication, and security. These cannot be disabled without impairing Platform functionality.
- Performance and Analytics Cookies: Used to collect aggregated, anonymized information about how users navigate the Platform, which pages are most visited, and where users encounter errors. This data helps sb777 improve Platform performance.
- Functional Cookies: Store your preferences such as language selection and responsible gaming settings to provide a more personalized experience.
- Fraud Prevention Cookies: Used to detect and prevent fraudulent activity, including identification of suspicious login attempts and bot activity.
With the exception of strictly necessary cookies, you may manage your cookie preferences through your browser settings. Most modern browsers allow you to refuse, delete, or be notified before cookies are set. Please note that disabling certain cookies may affect the functionality of the sb777 Platform, including session persistence and game loading performance.
Data Retention
sb777 retains personal data for as long as is necessary to fulfil the purpose for which it was collected or as required by applicable Philippine law. The following retention periods apply:
Retained for the duration of account activity, plus 5 years after account closure as required by PAGCOR and AMLA regulations.
Retained for a minimum of 5 years from the date of last transaction or account closure, per Anti-Money Laundering Act requirements.
Retained for 5 years from the date of the transaction, consistent with PAGCOR reporting obligations and AMLA provisions.
Retained for 2 years from the date of the session for operational purposes, and up to 5 years where required for regulatory audit purposes.
Retained for 2 years from the date of resolution, or longer where the communication relates to an unresolved dispute or investigation.
Retained for the period during which consent is active, plus 1 year after withdrawal to demonstrate consent history for compliance purposes.
Upon expiry of the applicable retention period, personal data will be securely deleted or anonymized such that it can no longer be associated with any individual. Where data cannot be immediately deleted due to technical constraints (e.g., backup systems), it will be isolated from active processing and deleted at the next scheduled purge cycle.
Data Security
sb777 implements appropriate technical and organizational measures to protect personal data against unauthorized access, accidental loss, destruction, or disclosure. Our security measures include:
- Encryption in Transit: All data transmitted between your device and sb777 servers is encrypted using 256-bit SSL/TLS protocols. Connections using outdated TLS versions are refused.
- Encryption at Rest: Sensitive personal data stored on sb777 infrastructure, including KYC documents and financial data, is encrypted at rest using industry-standard AES-256 encryption.
- Access Controls: Access to personal data is restricted to sb777 personnel and authorized processors who require it to perform their specific functions. Access is controlled by role-based permissions, multi-factor authentication, and audit logging.
- Password Security: Account passwords are stored in hashed, salted form only. sb777 does not store plain-text passwords and does not have access to your password after it is created.
- Two-Factor Authentication (2FA): sb777 offers 2FA via SMS OTP to all account holders as an additional layer of account access security. Players are encouraged to enable 2FA through account settings.
- Regular Security Audits: sb777 conducts regular security assessments and penetration testing of its Platform infrastructure to identify and remediate vulnerabilities.
- Data Breach Response: In the event of a personal data breach that is likely to result in significant harm to individuals, sb777 will notify the National Privacy Commission within 72 hours of becoming aware of the breach, and will notify affected individuals where required under the DPA.
While sb777 applies robust security measures, no online platform can guarantee absolute security. You are responsible for maintaining the security of your account credentials and for notifying sb777 immediately if you suspect unauthorized access to your account.
Your Rights as a Data Subject
Under the Data Privacy Act of 2012, you have the following rights with respect to your personal data held by sb777. To exercise any of these rights, contact the sb777 Data Protection Officer as described in Section 14.
Right to Be InformedYou have the right to be informed about how your personal data is collected, used, and disclosed. This Privacy Policy fulfils that obligation. You may request a summary of the personal data sb777 holds about you at any time.
Right to AccessYou have the right to request a copy of the personal data that sb777 holds about your account, including transaction history, gaming activity, and KYC records. sb777 will respond to access requests within fifteen (15) days of receipt.
Right to RectificationIf you believe that personal data sb777 holds about you is inaccurate, incomplete, or outdated, you have the right to request correction. You may update basic account information directly through your sb777 account settings. Changes to identity documents or other KYC data require verification through the support team.
Right to ErasureSubject to applicable retention requirements under Philippine law (including AMLA and PAGCOR regulations), you have the right to request the deletion of personal data that is no longer necessary for the purposes it was collected, or where you have withdrawn consent and there is no other lawful basis for processing.
Right to ObjectYou have the right to object to the processing of your personal data where that processing is based on legitimate interest. Where you object, sb777 will cease processing unless there are compelling legitimate grounds that override your interests, rights, and freedoms.
Right to Data PortabilityWhere processing is based on your consent or on a contract, you have the right to receive a copy of your personal data in a structured, commonly used, and machine-readable format. sb777 will respond to portability requests within fifteen (15) days.
Right to Withdraw ConsentWhere processing is based on your consent, you may withdraw that consent at any time by contacting the sb777 Data Protection Officer or by updating your marketing preferences in account settings. Withdrawal of consent does not affect the lawfulness of processing conducted before the withdrawal.
Right to Complain to the NPCIf you believe sb777 has processed your personal data in breach of the Data Privacy Act, you have the right to lodge a complaint with the National Privacy Commission (NPC) of the Philippines. sb777 encourages you to contact us first so we can attempt to resolve the matter directly before escalation.
Children's Privacy
The sb777 Platform is strictly not intended for use by persons under 21 years of age. sb777 does not knowingly collect personal data from individuals under 21. Under PAGCOR regulations governing online gaming in the Philippines, a minimum age of 21 is a mandatory eligibility requirement for participation in casino-style gaming.
Where sb777 becomes aware that personal data has been collected from an individual who is under 21 years of age, we will take immediate steps to delete that data from our systems and close the associated account. If you are a parent or guardian and believe your child has registered an account with sb777, please contact the Data Protection Officer immediately using the contact details in Section 14.
Cross-Border Data Transfers
Some of sb777's service providers and infrastructure partners may process personal data outside the Republic of the Philippines. Where personal data is transferred to a jurisdiction outside the Philippines, sb777 ensures that appropriate safeguards are in place in accordance with Section 21 of the Data Privacy Act and the NPC's guidelines on cross-border data transfers.
Safeguards used for cross-border transfers include contractual data processing agreements incorporating NPC-approved standard clauses, transfers to jurisdictions with adequate data protection frameworks as recognized by the NPC, and binding corporate rules where applicable within affiliated entity groups.
By using the sb777 Platform, you acknowledge that your data may be processed in countries outside the Philippines in connection with the services described in this Policy. Such transfers are conducted in compliance with applicable Philippine data protection law and are limited to what is necessary for the purposes described in Section 4.
Updates to This Privacy Policy
sb777 reserves the right to update or modify this Privacy Policy at any time to reflect changes in our processing activities, applicable law, regulatory requirements from PAGCOR or the NPC, or improvements to our privacy practices. The "Last Updated" date at the top of this Policy reflects the date of the most recent revision.
Where changes are material — meaning they significantly alter the way sb777 collects or uses personal data — sb777 will provide advance notice by posting a prominent notice on the Platform and, where practicable, by sending an email notification to registered account holders.
Your continued use of the sb777 Platform following the publication of an updated Privacy Policy constitutes your acceptance of the changes. If you do not accept any updated terms, please discontinue your use of the Platform and contact the Data Protection Officer to close your account and request deletion of your data subject to applicable retention requirements.
Contact Us & Data Protection Officer
For all matters relating to this Privacy Policy, the processing of your personal data by sb777, or to exercise your data subject rights under the Data Privacy Act of 2012, please contact the sb777 Data Protection Officer through the following channels:
Please include "Privacy Request" and your registered account identifier in the subject line for faster processing.
For urgent account-level privacy concerns, live chat provides the fastest initial response.
If your complaint is not resolved through our internal process, you may escalate to the NPC as the competent supervisory authority under the Data Privacy Act of 2012.
sb777 will acknowledge all formal data subject requests within three (3) business days and will provide a substantive response within fifteen (15) days of receipt, or within the extended period permitted under the DPA for complex requests. All requests are handled by Filipino-speaking staff who are familiar with the practical realities of our player base.