fb777 Privacy Policy for the Philippines
This fb777 privacy policy explains the information covered by the notice, why it may be used, how cookies and sharing are addressed, and how to raise a privacy request. Use the contents below to find information about access, correction, deletion and retention.
On this page
Draft for operator review: This English version is not yet an approved operational notice. The legal controller, privacy contact, actual processing practices and retention schedule must be confirmed before publication. Descriptions carried over from the source policy are not independently verified statements about live systems.
1 Scope and responsibility
This notice concerns personal information associated with the fb777-branded website at fb777fb.ph and the account, transaction and support activities described below. Reading an information page, opening an account and using a separate payment provider are different activities; they do not necessarily involve the same data or the same organisation.
The name fb777 identifies the brand in this draft, not a verified legal entity. The operator must supply the legal name and contact details of the personal information controller, together with the appropriate privacy representative, before this notice is finalised. The site’s listed support email is provided in Contact and complaints; it is not presented here as a confirmed data protection officer address.
For Philippine readers, the relevant general framework is the Data Privacy Act of 2012 and its implementing rules, where applicable. Referring to that framework does not certify fb777’s compliance or establish that a particular service is authorised to operate.
2 What personal data is covered?
The source policy identifies six categories of information. The examples below explain their scope; they are not a request to provide every item. The live collection notice should identify what is required, why it is needed and what happens if you choose not to provide it.
| Data category | Examples | When it may be needed |
|---|---|---|
| Identity information | Name, date of birth and identity-document details | Account eligibility or an explained identity-verification requirement; do not send documents merely to read this page. |
| Contact details | Registered mobile number, email address and contact preferences | Registration, account recovery or a support request, depending on the service used. |
| Payment records | Payment-account reference, PHP transaction amount, date and status | Processing or investigating a transaction. Never send a wallet PIN or OTP to a support contact. |
| Technical information | IP address, browser type, device details and access logs | Website delivery, diagnostics or security, depending on the actual hosting and logging configuration. |
| Account and game activity | Account actions, game history, stakes and recorded results | Providing account features, handling disputes or meeting a documented record-keeping requirement. |
| Location information | Country or approximate area inferred from an IP address | Location-related service checks. This description does not confirm collection of precise GPS location. |
3 How is information collected?
Information can come from a user, a device or a service involved in a specific request. The following collection routes are retained from the source policy and must be matched to the actual service before approval:
- Information you provide: details entered into registration or profile fields, and messages sent to support.
- Automatic records: server logs, device information and browser storage generated when the relevant technology is in use.
- Payment processing: transaction confirmations, reference numbers or status updates supplied by a payment provider.
- Identity checks: documents and verification results requested for a clearly explained eligibility, security or legal purpose.
- Other service providers: information from identity or fraud-screening services, where used and appropriately disclosed.
Share only what is necessary: A privacy or support enquiry should not include your password, OTP, wallet PIN or a complete payment-card record. If an identity check is needed, confirm the recipient and secure submission method first.
4 Why is information used?
The stated service purposes are listed below. A purpose alone is not permission to process data: the controller must identify an applicable lawful basis and meet any additional rules for sensitive information. Consent, where relied on, must be specific and informed rather than inferred merely from visiting this page. The Philippine implementing rules explain these requirements.
- Account administration: create, verify, maintain and recover an account.
- Transactions: process deposits or withdrawals and reconcile payment records.
- Requested services: provide available account features and administer offers a user chooses to join.
- Fraud and misuse prevention: investigate suspicious activity and apply relevant legal requirements.
- Support: respond to enquiries, technical problems and disputes.
- Service reliability: diagnose errors and improve performance or security.
- Legal obligations: meet identified reporting, record-keeping or lawful disclosure duties.
- Personalisation and marketing: deliver optional communications or tailored content only on an appropriate basis, with the relevant choices explained.
Marketing choices: Use an unsubscribe option or contact the listed support address to request that marketing stop. A working account preference must be confirmed before it is described as available. Withdrawing marketing consent does not necessarily stop essential account notices or processing required on another lawful basis.
5 Cookies, tracking and browser choices
Cookies store small pieces of information in a browser. Similar tools, including local storage, may also remember settings or help identify a session. The four categories below explain the source policy’s cookie coverage; they are not a verified inventory of the cookies currently installed by this website.
- Essential cookies: may support a requested session or core function. Blocking them can prevent that function from working.
- Preference cookies: may remember selected settings, where that feature is provided.
- Analytics cookies: may measure visits and interactions. The provider, purpose, duration and applicable choice should be disclosed before activation.
- Security cookies: may support fraud prevention or detection of unusual access, depending on the implementation.
You can review, block or delete stored site data in your browser. Where a consent preference tool is offered, use it to manage optional categories. Deleting cookies may sign you out, but it does not delete server-side account records. Cookie names, providers, lifetimes and any advertising or referral tracking must be checked against the actual deployment before this notice is approved.
6 Who may receive information?
The source policy states that fb777 does not sell personal information. This draft retains that commitment for operator confirmation; it is not an independent audit of advertising, analytics or referral arrangements. Sharing needed to deliver a service is a separate matter and must have a stated purpose and appropriate basis.
- Payment providers: information needed to process or trace a transaction using the method selected by the user.
- Identity-verification providers: information proportionate to the verification being performed.
- Public authorities: information covered by a valid legal request or applicable obligation, rather than unrestricted access to all records.
- Fraud-prevention services: relevant information used for an explained security investigation.
- Technical service providers: hosting, maintenance or support data needed for their assigned work.
The operator must confirm the recipient categories, safeguards and any processing outside the Philippines. A payment provider or a separately operated website may issue its own privacy notice. Follow that notice for its independent activities; an external link is not proof that the destination follows identical practices. See the NPC’s explanation of the information a privacy notice should disclose.
7 How long is information retained?
Retention should be linked to a documented purpose and any applicable obligation, not continued simply because storage is available. The periods below are the schedule stated in the source policy. They remain unconfirmed and must not be presented as statutory Philippine retention periods:
- Account information: while the account is active and five years after closure, as stated in the source schedule.
- Financial transaction records: seven years; the applicable starting point and legal or operational basis require confirmation.
- Game history: three years after account closure, according to the source schedule.
- Support communications: two years; the starting event and scope of tickets or chat records require confirmation.
- Technical logs: one year; the log categories and starting point require confirmation.
Each period needs a necessity assessment. Where there is no continuing basis to retain identifiable data, secure deletion or effective anonymisation is the appropriate outcome. A legal hold or unresolved dispute may affect particular records; the reason should be documented. Closing an account, clearing cookies and deleting all personal data are different actions. Ask what can be erased and what, if anything, must remain.
8 Your privacy rights and choices
Where Philippine data privacy law applies, rights are subject to the conditions and exceptions in that law. These six cards preserve the original rights topics; they do not promise an unconditional right to immediate deletion or to stop every processing activity. The National Privacy Commission’s rights guide provides the official overview.
Access and information
Ask what personal data is processed, why, and who receives it, and request reasonable access to your information.
Correction
Request correction of inaccurate or incomplete personal information and explain which record needs changing.
Erasure
Request deletion where the applicable grounds are met. A lawful record-keeping duty may limit what can be erased.
Blocking or suspension
Request blocking or suspension of processing where the law permits, identifying the activity and your reason.
Data portability
Request an electronic copy in a commonly used format where the legal conditions for portability apply.
Objection and consent choices
Raise an objection to applicable processing, including direct marketing, or withdraw consent relied on for a particular purpose.
Send a clear request to [email protected] and ask for routing to the responsible privacy representative. Identify the requested action without sending unnecessary documents. Proportionate identity checks may be needed. The source notice’s 30-business-day response target requires confirmation and must not override an applicable legal deadline. You may also seek redress or raise a complaint through the appropriate process.
9 Security safeguards and incident concerns
Privacy protection requires suitable organisational, physical and technical measures. The source notice lists six safeguard areas. Their actual implementation must be confirmed; this draft does not certify a particular encryption strength, audit result or security product.
- Transport protection: use an appropriately secured connection when submitting personal information, and do not ignore certificate warnings.
- Account verification: use additional authentication where the service provides it, while protecting recovery details.
- Network protection: maintain controls intended to limit unauthorised access to systems.
- Security review: assess safeguards and resolve identified weaknesses; any claim of independent auditing needs supporting evidence.
- Data masking: avoid exposing complete payment or identity details in screens, messages or support records where unnecessary.
- Restricted access: limit staff and provider access to information needed for authorised work.
Report a concern safely: No online system can promise absolute security. If you suspect unauthorised disclosure, report what happened and when, using a redacted screenshot where helpful. Do not include credentials or repeat sensitive information unnecessarily. The controller must assess the incident and any applicable notification duties.
10 Children and users who are not eligible
The gaming service is not intended for children. This privacy notice does not set or lower the applicable gambling age or other eligibility restrictions. Any age statement elsewhere on the site must be checked against the actual service and applicable rules before publication.
- Eligibility checks: collect only information proportionate to an explained age or account-verification purpose.
- Suspected child data: request prompt review, restriction of inappropriate processing and lawful deletion where applicable; do not promise automatic erasure of every record regardless of obligations.
- Parent or guardian reports: explain the concern through the privacy contact route without emailing a child’s full identity documents at the first contact.
For parents and guardians: Keep account credentials and payment tools inaccessible to children, review shared-device settings and use appropriate parental controls. Refer to the responsible gaming page for the site’s stated guidance.
11 How are policy changes handled?
A privacy notice should remain consistent with the activities it describes. New purposes, recipients or collection tools need an appropriate explanation, not just a silent change to the page date. The operator must confirm the notification process used for material changes.
- Version information: the date above records this English draft revision, not legal approval or certification.
- Material updates: explain meaningful changes through a suitable notice; do not promise SMS or email delivery until those channels are confirmed.
- Consent where required: continued browsing alone is not blanket consent to new processing that requires specific consent.
- Your records: review the current notice when providing new information and keep a copy of the version relevant to your request.
12 Contact, privacy requests and complaints
For questions about the fb777 privacy policy, start with the email already listed on this website and ask for the legal controller and responsible privacy representative. Their confirmed details must be added before this draft becomes the final notice.
- Listed email: [email protected]. A useful subject is “Privacy request — access”, “correction” or “deletion”.
- Other channels: use account support only after confirming its authenticity. This notice does not verify that a live-chat service is available.
- Request details: state the data or activity concerned, the action requested and a safe way to contact you. Ask for a reference and the applicable response timeframe.
- Service availability: support hours and response targets need confirmation. Do not rely on an unverified five-minute, 24-hour or round-the-clock promise for a privacy matter.
If a concern remains unresolved, consult the NPC’s rights and complaint guidance and follow the applicable procedure. For general account information, see the fb777 FAQ and terms and conditions; those pages do not replace a privacy request.
Six areas of privacy protection
Protected connections
Check the address and connection before providing information. Encryption is one safeguard, not a guarantee that every data-handling practice is safe.
Proportionate identity checks
Understand why verification is needed, what document is requested and how to submit it securely. Do not send more information than the purpose requires.
Clear sharing commitments
The source policy’s no-sale commitment is retained for confirmation. Service-provider disclosures and any tracking arrangements must be explained separately.
Defined retention
Each data category needs a justified period and a clear starting point. Account closure does not, by itself, establish when every record is deleted.
Meaningful user choices
Ask for access, correction or other applicable rights using a clear request. Marketing preferences, cookies and server-side records involve different controls.
Evidence-based security review
Security claims should have supporting evidence. This notice does not claim an independent audit, certification or guaranteed protection from every incident.