1. Overview
taya08 ("taya08," "we," "us," or "our") operates the online gaming platform accessible at taya08.app. As a data controller, taya08 is responsible for the personal information you provide when you register, play, or otherwise interact with our platform.
This Privacy Policy is issued in compliance with the Data Privacy Act of 2012 (Republic Act No. 10173) of the Philippines and its Implementing Rules and Regulations, as enforced by the National Privacy Commission (NPC). It applies to all personal data collected through the taya08 website, mobile application, customer support channels, and any other touchpoints operated by taya08.
By registering an account or using the taya08 platform, you acknowledge that you have read and understood this Privacy Policy and consent to the collection and processing of your personal data as described herein. If you do not agree, please discontinue use of the platform and contact support to close your account.
Plain language summary: We collect your data to run your account, process payments, comply with Philippine law, and keep the platform safe. We do not sell your data. You have rights over your information and can contact us at any time.
2. Personal Data We Collect
2.1 Identity & Contact Data
- Full legal name as it appears on your government-issued ID
- Date of birth (to verify the 21+ age requirement)
- Nationality and country of residence
- Residential address (barangay, city/municipality, province, ZIP code)
- Mobile number (Philippine format preferred)
- Email address
2.2 Identity Verification (KYC) Data
- Copies of government-issued identification documents (e.g., Philippine Passport, Driver's License, UMID, SSS ID, PhilHealth ID, Voter's ID)
- Selfie or liveness-check image for biometric matching where required
- Source-of-funds documentation for large transactions as required by AMLC regulations
2.3 Financial Data
- GCash or PayMaya mobile number linked to your account
- Bank account details (account name, account number, bank name) for bank transfer transactions
- Debit card details (card number masked, expiry date) where applicable
- Transaction history including deposits, withdrawals, wagers, and bonus credits
2.4 Technical & Usage Data
- IP address and approximate geolocation at the time of login and each session
- Device type, operating system, browser type and version
- Session duration, pages visited, games played, and betting patterns
- Login timestamps and authentication logs
- Cookies and similar tracking technologies (see Section 10)
2.5 Communications Data
- Records of live chat conversations with taya08 support agents
- Email correspondence with taya08
- Feedback, complaints, and survey responses
3. How We Collect Your Data
taya08 collects personal data through the following means:
- Direct collection: Information you provide when registering an account, completing KYC verification, making a deposit or withdrawal, contacting support, or participating in a promotion.
- Automated collection: Technical data collected automatically when you access the platform, including through cookies, web beacons, server logs, and analytics tools.
- Third-party sources: Identity verification data from KYC service providers; fraud and AML screening data from compliance databases; payment confirmation data from GCash, PayMaya, and banking partners.
4. Purpose of Processing
taya08 processes your personal data for the following purposes:
- Account management: Creating, maintaining, and securing your taya08 account; authenticating your identity at login; processing password resets.
- Age and identity verification: Confirming that you meet the 21+ minimum age requirement and verifying your identity as required by PAGCOR and AMLC regulations.
- Payment processing: Processing deposits and withdrawals through GCash, PayMaya, bank transfer, and debit card; reconciling transactions; investigating payment disputes.
- Regulatory compliance: Fulfilling obligations under the Anti-Money Laundering Act (RA 9160), PAGCOR licensing conditions, and the Data Privacy Act (RA 10173); reporting to AMLC and other authorities as required by law.
- Fraud prevention and security: Detecting and preventing fraudulent activity, bonus abuse, multi-accounting, and unauthorized access; maintaining platform integrity.
- Customer support: Responding to your enquiries, complaints, and requests; resolving disputes; improving support quality.
- Responsible gaming: Monitoring gaming patterns to identify potential problem gambling behavior; administering self-exclusion, deposit limits, and cooling-off periods.
- Marketing and promotions: Sending you promotional offers, bonus notifications, and platform updates where you have provided consent. You may withdraw consent at any time.
- Platform improvement: Analyzing usage data to improve game offerings, website performance, and user experience.
5. Legal Basis for Processing
Under the Data Privacy Act of 2012, taya08 processes your personal data on the following legal bases:
- Contractual necessity: Processing required to perform the contract between you and taya08 (i.e., operating your account, processing transactions, and providing gaming services).
- Legal obligation: Processing required to comply with applicable Philippine laws, including PAGCOR licensing requirements, AMLC reporting obligations, and NPC data protection requirements.
- Legitimate interests: Processing for fraud prevention, platform security, and responsible gaming monitoring, where these interests are not overridden by your privacy rights.
- Consent: Processing for direct marketing communications, where you have given explicit consent. You may withdraw this consent at any time without affecting the lawfulness of prior processing.
6. Data Sharing & Disclosure
taya08 does not sell, rent, or trade your personal data to third parties for their own marketing purposes. We may share your data with the following categories of recipients, strictly on a need-to-know basis:
- Payment processors: GCash (Mynt), PayMaya (Voyager Innovations), and banking partners, for the purpose of processing your financial transactions.
- KYC and identity verification providers: Third-party services that assist with document verification and biometric matching as part of our regulatory compliance obligations.
- Regulatory authorities: PAGCOR, the Anti-Money Laundering Council (AMLC), the National Privacy Commission (NPC), and other Philippine government agencies, where disclosure is required by law or court order.
- IT and cloud service providers: Hosting, database, and security service providers who process data on our behalf under strict data processing agreements.
- Fraud prevention services: Industry-shared databases used to detect and prevent fraud, bonus abuse, and problem gambling.
- Professional advisers: Legal counsel, auditors, and compliance consultants, subject to professional confidentiality obligations.
All third-party processors engaged by taya08 are contractually required to implement appropriate technical and organizational security measures and to process personal data only in accordance with taya08's instructions.
7. Data Retention
taya08 retains your personal data for as long as necessary to fulfill the purposes for which it was collected, subject to the following minimum retention periods:
- Account data and transaction records: Retained for a minimum of 5 years from the date of account closure, as required by PAGCOR licensing conditions and AMLC regulations.
- KYC documents: Retained for a minimum of 5 years from the date of verification, or longer if required by applicable law.
- Customer support records: Retained for 3 years from the date of the last interaction.
- Marketing consent records: Retained for the duration of your account and for 1 year following account closure or withdrawal of consent.
- Technical logs: Retained for 12 months from the date of generation, unless required for an ongoing investigation.
Upon expiry of the applicable retention period, personal data will be securely deleted or anonymized in accordance with NPC guidelines.
8. Data Security
taya08 implements industry-standard technical and organizational security measures to protect your personal data against unauthorized access, disclosure, alteration, or destruction. These measures include:
- Transport Layer Security (TLS 1.2 or higher) encryption for all data transmitted between your device and the taya08 platform
- AES-256 encryption for sensitive data stored at rest, including financial information and KYC documents
- Multi-factor authentication options for player accounts
- Role-based access controls limiting staff access to personal data on a strict need-to-know basis
- Regular penetration testing and vulnerability assessments conducted by independent security firms
- 24/7 security monitoring and intrusion detection systems
- Staff training on data protection and information security
In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, taya08 will notify the National Privacy Commission within 72 hours of becoming aware of the breach, and will notify affected individuals without undue delay, in accordance with NPC Circular 16-03.
9. Your Data Subject Rights
Under the Data Privacy Act of 2012, you have the following rights with respect to your personal data held by taya08:
- Right to be informed: The right to know what personal data taya08 collects about you and how it is processed — which is the purpose of this Privacy Policy.
- Right of access: The right to request a copy of the personal data taya08 holds about you.
- Right to rectification: The right to request correction of inaccurate or incomplete personal data.
- Right to erasure: The right to request deletion of your personal data where it is no longer necessary for the purposes for which it was collected, subject to our legal retention obligations.
- Right to object: The right to object to the processing of your personal data for direct marketing purposes at any time.
- Right to data portability: The right to receive your personal data in a structured, commonly used, machine-readable format.
- Right to lodge a complaint: The right to lodge a complaint with the National Privacy Commission (NPC) if you believe your data protection rights have been violated.
To exercise any of these rights, please contact our Data Protection Officer using the details in Section 14. taya08 will respond to all data subject requests within 15 business days of receipt. We may require identity verification before processing your request.
10. Cookies & Tracking Technologies
taya08 uses cookies and similar technologies to enhance your experience on the platform. A cookie is a small text file placed on your device when you visit a website. We use the following categories of cookies:
- Strictly necessary cookies: Essential for the platform to function. These include session authentication cookies and security tokens. These cannot be disabled.
- Functional cookies: Remember your preferences such as language settings, preferred payment method, and game lobby layout.
- Analytics cookies: Collect anonymized data about how players use the platform to help us improve performance and user experience. Data is aggregated and not linked to individual identities.
- Marketing cookies: Used to deliver relevant promotional content within the taya08 platform. These are only activated with your consent.
You can manage your cookie preferences through your browser settings. Note that disabling strictly necessary cookies may impair the functionality of the taya08 platform. For detailed cookie management instructions, refer to your browser's help documentation.
11. Minors & Age Restriction
The taya08 platform is strictly intended for persons aged 21 years and older. taya08 does not knowingly collect personal data from individuals under the age of 21. If we become aware that personal data has been collected from a person under 21, we will immediately close the associated account, return any deposits to the payment source, and delete the personal data in question.
If you are a parent or guardian and believe that a minor has registered on taya08, please contact us immediately at the details provided in Section 14 so that we can take prompt action.
12. Cross-Border Data Transfers
taya08 primarily stores and processes personal data within the Philippines. Where data is transferred to service providers located outside the Philippines (for example, cloud infrastructure providers), taya08 ensures that such transfers are subject to appropriate safeguards, including contractual clauses that provide a level of data protection equivalent to that required under the Data Privacy Act of 2012.
taya08 will not transfer your personal data to a country that does not provide an adequate level of data protection without first obtaining your explicit consent or implementing appropriate contractual safeguards as required by the NPC.
13. Changes to This Privacy Policy
taya08 reserves the right to update this Privacy Policy at any time to reflect changes in our data processing practices, applicable law, or regulatory requirements. Material changes will be communicated to registered players via email or in-platform notification at least 7 days before the changes take effect.
The "Last updated" date at the top of this page indicates when the most recent revision was made. Your continued use of the taya08 platform after the effective date of any revision constitutes your acceptance of the updated Privacy Policy.
Our Privacy Commitments
RA 10173 Compliant
taya08 fully complies with the Philippine Data Privacy Act of 2012 and NPC regulations. Your data rights are protected under Philippine law.
AES-256 Encryption
All sensitive data stored on taya08 servers is encrypted using AES-256. Data in transit is protected by TLS 1.2+ encryption at all times.
We Never Sell Your Data
taya08 does not sell, rent, or trade your personal information to third parties for marketing purposes. Your data is used only to operate your account.
Your Rights, Always
Access, correct, delete, or port your data at any time. Contact our DPO and we will respond within 15 business days as required by the NPC.
21+ Age Enforcement
We do not knowingly collect data from anyone under 21. Accounts found to belong to minors are closed immediately and all data is deleted.
Breach Notification
In the event of a data breach, taya08 notifies the NPC within 72 hours and affected players without undue delay, in line with NPC Circular 16-03.