1. Introduction
hottaya ("we," "us," or "our") operates the online casino platform accessible at hottaya.net. In the course of providing our services to players in the Philippines and elsewhere, we collect and process certain personal data. This Privacy Policy describes our practices with respect to that data — what we collect, why we collect it, how we use it, who we share it with, and how long we keep it.
This Privacy Policy applies to all users of the hottaya platform, including registered players, visitors who browse the site without registering, and any other individuals whose personal data we process in connection with our services. By using the hottaya platform, you acknowledge that you have read and understood this Privacy Policy.
This Privacy Policy should be read alongside our Terms & Conditions, which govern your use of the platform generally. Defined terms used in this Privacy Policy have the same meaning as in the Terms & Conditions unless otherwise stated.
2. Personal Data We Collect
hottaya collects personal data through several channels: directly from you when you register or use the platform, automatically through your use of the site, and from third parties such as payment processors and identity verification providers. The categories of personal data we collect include:
2.1 Registration and Identity Data
- Full legal name, date of birth, and nationality
- Email address and mobile phone number
- Residential address (including city, province, and postal code)
- Government-issued identification documents (e.g., Philippine passport, UMID, PhilSys ID, driver's license) submitted for KYC verification
- Selfie or facial image submitted for identity verification purposes
2.2 Financial and Transaction Data
- GCash or PayMaya account details (mobile number associated with the account)
- Bank account details (account name, account number, bank name) for BPI, BDO, Metrobank, and other supported banks
- Credit or debit card details (card number is tokenized and not stored in full by hottaya)
- Transaction history, including deposit amounts, withdrawal amounts, dates, and payment method used
- Bonus and promotional activity records
2.3 Gaming Activity Data
- Game session records, including games played, bets placed, outcomes, and session duration
- Account balance history
- Responsible gaming tool usage (e.g., deposit limits set, self-exclusion requests)
2.4 Technical and Usage Data
- IP address and approximate geolocation derived from IP
- Device type, operating system, and browser information
- Pages visited, features used, and time spent on the platform
- Cookie identifiers and similar tracking data (see Section 6)
2.5 Communications Data
- Records of communications with hottaya customer support, including live chat transcripts and email correspondence
- Feedback, complaints, and survey responses
3. How We Use Your Personal Data
hottaya uses the personal data we collect for the following purposes:
| Purpose | Data Used |
|---|---|
| Account registration and management | Identity data, contact data |
| Identity verification (KYC) and age verification | Identity data, ID documents, facial image |
| Processing deposits and withdrawals | Financial data, transaction data |
| Providing and improving gaming services | Gaming activity data, technical data |
| Fraud prevention and security monitoring | All categories as relevant |
| Anti-money laundering (AML) compliance | Identity data, financial data, transaction data |
| Regulatory reporting to PAGCOR | Identity data, transaction data, gaming data |
| Responsible gaming monitoring and intervention | Gaming activity data, responsible gaming data |
| Customer support | Communications data, account data |
| Marketing and promotional communications (with consent) | Contact data, gaming preferences |
| Platform analytics and improvement | Technical data, usage data (aggregated/anonymized) |
hottaya does not use your personal data for automated decision-making that produces legal or similarly significant effects without human review, except where required by law or where you have given explicit consent.
4. Legal Basis for Processing
Under the Philippine Data Privacy Act of 2012, hottaya processes your personal data on the following legal bases:
- Contractual necessity: Processing required to perform our contract with you — including account management, payment processing, and game provision.
- Legal obligation: Processing required to comply with applicable laws and regulations, including PAGCOR licensing requirements, AML obligations, and tax reporting.
- Legitimate interests: Processing for fraud prevention, platform security, and improving our services, where these interests are not overridden by your rights.
- Consent: Processing for marketing communications and non-essential cookies, where we have obtained your prior consent. You may withdraw consent at any time.
5. Data Sharing and Disclosure
hottaya does not sell your personal data to third parties. We share personal data only in the following circumstances:
5.1 Service Providers
We share data with trusted third-party service providers who assist us in operating the platform, including payment processors (GCash, PayMaya, banks), identity verification providers, cloud hosting providers, customer support software providers, and analytics providers. All service providers are contractually required to process data only on our instructions and to maintain appropriate security standards.
5.2 Regulatory and Legal Disclosure
hottaya may disclose personal data to PAGCOR, the Anti-Money Laundering Council (AMLC), the National Privacy Commission (NPC), law enforcement agencies, or other government authorities where required by applicable Philippine law, court order, or regulatory requirement. We will notify you of such disclosures where legally permitted to do so.
5.3 Business Transfers
In the event of a merger, acquisition, or sale of all or substantially all of hottaya's assets, personal data held by hottaya may be transferred to the acquiring entity. We will notify affected users prior to any such transfer and ensure that the receiving entity is bound by privacy obligations no less protective than those in this policy.
5.4 With Your Consent
We may share your data with third parties for purposes not described above where we have obtained your explicit prior consent.
6. Cookies and Tracking Technologies
hottaya uses cookies and similar tracking technologies to operate and improve the platform. Cookies are small text files stored on your device when you visit the site. We use the following categories of cookies:
- Strictly necessary cookies: Required for the platform to function. These cannot be disabled. They include session authentication cookies, security tokens, and load-balancing cookies.
- Functional cookies: Remember your preferences (e.g., language, display settings) to improve your experience. These are enabled by default but can be disabled.
- Analytics cookies: Collect aggregated, anonymized data about how users interact with the platform to help us improve it. These require your consent.
- Marketing cookies: Used to deliver relevant promotional content. These require your explicit consent and can be withdrawn at any time.
You can manage your cookie preferences through your browser settings. Note that disabling strictly necessary cookies will affect the functionality of the platform.
7. Data Retention
hottaya retains personal data for as long as necessary to fulfill the purposes for which it was collected, subject to the following minimum retention periods required by law:
- Account and identity data: retained for a minimum of five (5) years following account closure, as required by PAGCOR regulations and AML obligations.
- Transaction and financial records: retained for a minimum of five (5) years from the date of the transaction, in compliance with Philippine AML and tax laws.
- Customer support communications: retained for three (3) years from the date of the communication.
- Marketing consent records: retained for the duration of the consent plus three (3) years.
When personal data is no longer required and the applicable retention period has expired, hottaya will securely delete or anonymize the data in accordance with our data disposal procedures.
8. Data Security
hottaya implements appropriate technical and organizational measures to protect your personal data against unauthorized access, disclosure, alteration, or destruction. Our security measures include:
- 256-bit SSL/TLS encryption for all data transmitted between your device and the hottaya platform
- Encryption of sensitive data at rest, including financial data and identity documents
- Access controls limiting employee access to personal data on a need-to-know basis
- Regular security assessments and penetration testing
- Two-factor authentication available for player accounts
- Real-time fraud monitoring and anomaly detection systems
9. Your Rights Under the Data Privacy Act
As a data subject under the Philippine Data Privacy Act of 2012, you have the following rights with respect to your personal data held by hottaya:
- Right to be informed: You have the right to know what personal data we collect about you and how it is used.
- Right of access: You may request a copy of the personal data we hold about you.
- Right to rectification: You may request correction of inaccurate or incomplete personal data.
- Right to erasure: You may request deletion of your personal data where it is no longer necessary for the purposes for which it was collected, subject to our legal retention obligations.
- Right to object: You may object to the processing of your personal data for direct marketing purposes at any time.
- Right to data portability: You may request a copy of your personal data in a structured, commonly used, machine-readable format.
- Right to lodge a complaint: You have the right to lodge a complaint with the National Privacy Commission (NPC) if you believe your data privacy rights have been violated.
To exercise any of these rights, please contact hottaya's Data Protection Officer using the contact details in Section 13. We will respond to all valid requests within thirty (30) days. We may need to verify your identity before processing your request.
10. Children's Privacy
The hottaya platform is strictly intended for adults aged 21 years and above. hottaya does not knowingly collect personal data from individuals under the age of 21. If we become aware that we have inadvertently collected personal data from a person under 21, we will take immediate steps to delete that data and close the associated account.
If you are a parent or guardian and believe that a minor has registered on the hottaya platform, please contact our support team immediately so that we can investigate and take appropriate action.
11. Cross-Border Data Transfers
hottaya's primary operations and data storage are based in the Philippines. However, some of our service providers — including cloud hosting and analytics providers — may process data in other jurisdictions. Where personal data is transferred outside the Philippines, hottaya ensures that appropriate safeguards are in place to protect your data to a standard equivalent to that required under Philippine law, including through contractual data processing agreements with receiving parties.
12. Changes to This Privacy Policy
hottaya may update this Privacy Policy from time to time to reflect changes in our data practices, applicable law, or regulatory requirements. When material changes are made, we will notify registered players via email and/or through a prominent notice on the platform prior to the changes taking effect. The updated Privacy Policy will be effective from the date of publication on the site. We encourage you to review this policy periodically.
13. Contact Us & Data Protection Officer
If you have any questions, concerns, or requests relating to this Privacy Policy or the processing of your personal data by hottaya, please contact our Data Protection Officer (DPO):
Email: [email protected]
General Support: [email protected]
(Email addresses are displayed as plain text and are not clickable links.)
You may also raise data privacy concerns directly with the Philippine National Privacy Commission (NPC). Information about the NPC and how to file a complaint is available through official Philippine government channels.