This Privacy Policy describes how sm77 ("we", "us", "the Platform") collects, uses, stores, discloses, and protects the personal information of players and visitors on sm77.one, in accordance with the Philippine Data Privacy Act of 2012 (Republic Act 10173) and its Implementing Rules and Regulations.
By registering an account on sm77 or continuing to use the Platform, you acknowledge that you have read this Privacy Policy and consent to the collection and processing of your personal data as described herein.
This Privacy Policy applies to all personal data processed by sm77 in connection with the sm77 Platform at sm77.one, including account registration, identity verification, game activity, financial transactions, customer support interactions, and marketing communications. It applies to all players registered in the Philippines and to any visitor who accesses the Platform regardless of location.
1.1 Data Controller. sm77, operating through sm77.one, is the data controller responsible for the personal information of its registered players and site visitors. As data controller, sm77 determines the purposes and means of processing personal data collected through the Platform.
1.2 Scope. This Privacy Policy covers all personal data processed in connection with your use of the sm77 Platform, including data collected during registration, identity verification (KYC), payment processing, gameplay, customer support, and marketing. It does not cover the data practices of third-party game providers or payment processors, each of which operates under its own privacy framework.
1.3 Legal Framework. sm77 processes personal data in compliance with:
sm77 collects the following categories of personal data from players and Platform visitors:
| Category | Examples | When Collected |
|---|---|---|
| Identity Data | Full legal name, date of birth, nationality, government ID type and number | Registration and KYC verification |
| Contact Data | Philippine mobile number, email address, residential address | Registration; account updates |
| Financial Data | GCash number, PayMaya number, bank account name and number (BPI, BDO, Metrobank), transaction history | Deposit and withdrawal processing |
| KYC Documents | Scanned or photographed government-issued ID (Philippine Passport, PhilSys ID, UMID, Driver's License, Voter's ID, SSS ID, PRC ID) | KYC verification prior to first withdrawal |
| Account Data | Username, encrypted password, account creation date, login history, session logs, device identifiers | Registration; ongoing platform use |
| Game & Betting Data | Game titles played, wager amounts, win/loss records, session duration, bet history, bonus usage | During active gameplay and account activity |
| Technical Data | IP address, browser type and version, operating system, device type, screen resolution, referral URL | Automatically upon site access |
| Support Data | Live chat transcripts, email correspondence, complaint records, support ticket history | Customer support interactions |
| Responsible Gaming Data | Self-exclusion requests, deposit limits set, session limits, cooling-off periods, problem gambling flags | Player tool usage; platform monitoring |
| Marketing Data | Promotional preferences, email open rates, offer redemption history, communication opt-out status | When marketing communications are sent or interacted with |
Sensitive Personal Information: KYC documents and responsible gaming data (including self-exclusion status and problem gambling flags) constitute sensitive personal information under the Data Privacy Act. sm77 applies heightened protection to these categories, including stricter access controls and longer encryption standards.
sm77 collects personal data through the following means:
sm77 processes personal data only for specified, legitimate purposes. The following table summarises our principal processing purposes and the legal basis for each under the Philippine Data Privacy Act:
| Purpose | Legal Basis |
|---|---|
| Account creation and management | Performance of a contract (Terms & Conditions) |
| Identity and age verification (KYC) | Legal obligation (AML regulations; gaming regulatory requirements) |
| Processing deposits and withdrawals | Performance of a contract; legal obligation |
| Providing access to games and services | Performance of a contract |
| Fraud prevention and AML monitoring | Legal obligation; legitimate interest |
| Customer support and complaint handling | Performance of a contract; legitimate interest |
| Responsible gaming monitoring and intervention | Legal obligation; legitimate interest; vital interest of the data subject |
| Platform security and session monitoring | Legitimate interest; legal obligation |
| Sending account-related notifications (OTP, withdrawal confirmation) | Performance of a contract |
| Sending promotional and marketing communications | Consent (you may withdraw consent at any time) |
| Improving Platform features and user experience | Legitimate interest |
| Compliance with regulatory reporting obligations | Legal obligation |
4.1 Marketing Consent. Where processing is based on consent — specifically for marketing communications — you have the right to withdraw your consent at any time by updating your communication preferences in your Account settings or by contacting sm77 support. Withdrawal of consent does not affect the lawfulness of processing carried out before the withdrawal.
sm77 does not sell, rent, or trade your personal data to third parties for their own marketing purposes. We share personal data only in the following circumstances and only to the extent necessary for the stated purpose:
No sale of data: sm77 does not sell, lease, or trade player personal data to advertising networks, data brokers, or third-party marketers. Your data is used solely to operate the sm77 Platform and fulfil our regulatory obligations.
6.1 Cross-Border Transfers. Some of sm77's third-party service providers — including game studios and technical infrastructure providers — may process personal data outside the Philippines. Where such transfers occur, sm77 takes steps to ensure that an equivalent level of data protection applies, including through contractual data processing agreements that incorporate data protection obligations consistent with the Data Privacy Act.
6.2 Safeguards. Transfers of personal data to countries that do not have data protection laws equivalent to the Philippines are conducted only where appropriate safeguards are in place, such as standard contractual clauses, binding corporate rules, or other mechanisms approved under applicable Philippine data protection law.
6.3 Notification. By using the sm77 Platform, you acknowledge and consent to the transfer of your personal data to third parties and service providers that may operate outside the Philippines, subject to the safeguards described in this section.
7.1 General Retention. sm77 retains personal data only for as long as necessary to fulfil the purposes for which it was collected, comply with legal obligations, resolve disputes, and enforce our agreements. The following retention periods apply as general guidelines:
7.2 Responsible Gaming Records. Self-exclusion records, deposit limit settings, and responsible gaming intervention notes may be retained for longer periods where required by applicable regulatory obligations or where retention is necessary to protect the player's vital interests.
7.3 Deletion. Upon expiry of the applicable retention period, personal data will be securely deleted or anonymised so that it can no longer be associated with an identifiable individual.
8.1 Technical Measures. sm77 implements industry-standard technical security measures to protect personal data against unauthorised access, disclosure, alteration, and destruction. These measures include:
8.2 Organisational Measures. sm77 maintains internal data handling policies, staff training on data protection obligations, and incident response procedures. Access to personal data is restricted to personnel whose roles require it.
8.3 Data Breach Notification. In the event of a personal data breach that is likely to result in significant harm to affected individuals, sm77 will notify the Philippine National Privacy Commission (NPC) within seventy-two (72) hours of becoming aware of the breach, and will notify affected players within a reasonable timeframe, in accordance with the Data Privacy Act.
8.4 Your Responsibility. While sm77 takes extensive measures to protect your data, the security of your Account also depends on your own practices. You are responsible for keeping your login credentials, OTPs, and withdrawal PIN confidential and for notifying sm77 immediately if you suspect unauthorised access to your Account.
9.1 What We Use. sm77 uses cookies and similar tracking technologies (such as web beacons and local storage) to operate the Platform, maintain your login session, prevent fraud, and improve the user experience. The following types of cookies are used:
9.2 Managing Cookies. You can control non-essential cookies through your browser settings. Disabling certain cookies may affect the functionality of specific Platform features. Instructions for managing cookies are available in your browser's help documentation.
Session cookies used for authentication and security are strictly necessary and cannot be blocked without preventing login. They are automatically deleted when you close your browser session.
Under the Philippine Data Privacy Act of 2012, you have the following rights in respect of your personal data held by sm77:
10.1 How to Exercise Your Rights. To exercise any of the above rights, contact sm77 via the support email at [email protected] with the subject line "Data Subject Request" and specify the right you wish to exercise and the data concerned. sm77 will acknowledge receipt within forty-eight (48) hours and provide a substantive response within fifteen (15) working days, or within thirty (30) working days where the request is complex.
10.2 Identity Verification. For security purposes, sm77 may require you to verify your identity before processing a data subject request. This ensures that personal data is not disclosed to or modified at the direction of unauthorised parties.
10.3 Limitations. The right to erasure and the right to object do not apply where sm77 is required by law to retain data — for example, KYC records required under AML regulations. sm77 will inform you of any applicable limitation when responding to your request.
10.4 Complaints to the NPC. If you are not satisfied with sm77's response to your data subject request, or if you believe your data rights have been violated, you have the right to lodge a complaint with the Philippine National Privacy Commission (NPC).
11.1 Age Restriction. The sm77 Platform is strictly intended for persons aged twenty-one (21) years and older. sm77 does not knowingly collect personal data from individuals under the age of 21. Age is verified at registration and at the point of first withdrawal through KYC documentation.
11.2 Underage Data. If sm77 discovers that personal data has been collected from a person under 21 years of age, the associated Account will be immediately closed, all data will be securely deleted to the extent not required for regulatory reporting, and any balance held in the account will be handled in accordance with applicable regulatory requirements.
11.3 Parental Responsibility. sm77 strongly encourages parents and guardians to take active measures to prevent minors from accessing online gambling platforms, including using parental control software and keeping login credentials for sm77 accounts private and inaccessible to persons under 21.
12.1 Special Handling. Personal data relating to a player's responsible gaming status — including self-exclusion records, deposit and loss limits, session timer settings, cooling-off periods, and any problem gambling flags applied by the sm77 risk team — is treated as sensitive personal information and is subject to heightened access controls and retention policies.
12.2 Purpose of Processing. Responsible gaming data is processed for the sole purpose of protecting the player's welfare and fulfilling sm77's obligations under PAGCOR-aligned responsible gaming standards. This data is not used for marketing profiling or shared with third parties for commercial purposes.
12.3 Self-Exclusion Records. Where a player has submitted a self-exclusion request, sm77 retains a record of that exclusion and its terms for the full duration of the exclusion period and for a reasonable period thereafter, to prevent circumvention through account re-registration.
For more information on responsible gaming tools available to sm77 players, please visit the Responsible Gaming page.
13.1 Game Providers. Games delivered through the sm77 Platform are operated by independent third-party studios including PG Soft, Pragmatic Play, Evolution Gaming, JDB, Jili, and others. While sm77 integrates these games into its platform, each provider operates its own infrastructure and may process player identifiers and game activity data under its own terms. sm77 is not responsible for the data practices of independent game providers beyond the data processing agreements that govern their access to sm77 player data.
13.2 Payment Providers. GCash, PayMaya, BPI, BDO, and Metrobank are independent entities with their own privacy policies. Your use of these payment services is subject to their respective terms and data practices. sm77 receives only the transaction data necessary to credit or debit your sm77 Wallet.
13.3 No Responsibility for Third Parties. sm77 is not responsible for the privacy practices of any third-party service provider or platform. We encourage you to review the privacy policies of any third-party services you use in connection with your sm77 Account.
14.1 Right to Amend. sm77 reserves the right to update or modify this Privacy Policy at any time to reflect changes in our data practices, applicable law, or Platform services. The updated policy will be published on this page with a revised "Last Updated" date.
14.2 Notification of Material Changes. Where an amendment materially affects your rights or how sm77 processes your personal data, sm77 will notify registered players by email or in-platform notification prior to the change taking effect. Where the change requires your consent (for example, a new processing purpose), sm77 will request that consent before processing begins.
14.3 Continued Use. Your continued use of the sm77 Platform following the effective date of any amended Privacy Policy constitutes your acknowledgement of the changes. If you do not agree with an amendment, you should discontinue using the Platform and may request Account closure by contacting sm77 support.
15.1 Privacy Enquiries. For any questions, requests, or complaints related to this Privacy Policy or sm77's data practices, please contact our data protection contact at:
sm77 will acknowledge all privacy-related enquiries within forty-eight (48) hours and provide a substantive response within fifteen (15) working days. Complex requests involving data access, erasure, or portability may take up to thirty (30) working days.
15.2 NPC Complaints. If you are not satisfied with sm77's handling of a privacy complaint or data subject request, you have the right to lodge a formal complaint with the Philippine National Privacy Commission (NPC). Information about how to contact the NPC is available on the NPC's official website.
This Privacy Policy was last reviewed and updated in January 2026. sm77 recommends that all players review this policy periodically to remain informed of how their personal data is handled. The most current version of this policy is always available at sm77.one/privacy-policy.
These aren't just policy statements — they're structural commitments backed by real platform architecture and operational procedure.
All data exchanged between your device and sm77 is encrypted with 256-bit SSL — the same standard used by Philippine banking apps. Your login credentials, financial details, and personal data are never transmitted in plain text.
sm77's data practices are designed in compliance with Republic Act 10173 — the Philippine Data Privacy Act of 2012. Your rights as a data subject, including access, rectification, and erasure, are fully recognised and supported.
sm77 does not sell, rent, or share your personal data with advertisers or data brokers. Your information is used only to operate your Account, process payments, comply with legal obligations, and improve the Platform.
Access to personal data within sm77's systems is restricted to staff whose roles require it. KYC documents and responsible gaming records are subject to additional access controls beyond standard account data.
sm77 retains personal data only for as long as required by law or necessary for platform operations. KYC and financial records are retained for five years post-account closure as required under Philippine AML regulations.
Data subject requests — access, rectification, erasure, objection — are handled by sm77's support team available around the clock. We acknowledge all privacy requests within 48 hours and respond substantively within 15 working days.
Your personal data is protected, your winnings are in segregated accounts, and your privacy rights are respected. sm77 is built for Filipino players who deserve transparency at every level.
Must be 21 years or older to register and play. Gambling involves financial risk — play responsibly.