Section 1
Who We Are
no1 is the operator of the online casino platform accessible at no1.today and
all associated subdomains and mobile browser interfaces (collectively, the
"Platform"). In this Privacy Policy, references to
"no1," "we," "us," or "our" refer to the
operator of the Platform.
no1 acts as the Personal Information Controller (PIC) in
respect of the personal data it collects from players and visitors, as defined
under the Philippine Data Privacy Act of 2012 (Republic Act No. 10173,
hereinafter "DPA") and its Implementing Rules and Regulations
("IRR").
Our designated Data Protection Officer (DPO) is responsible
for overseeing compliance with the DPA and this Privacy Policy. You may contact
our DPO by sending a written inquiry to the email address listed in the footer
of this page, with the subject line: "Attention: Data Protection Officer."
National Privacy Commission (NPC): no1's data processing activities
are conducted in accordance with NPC guidelines. If you believe your data privacy
rights have been violated and we have not adequately addressed your concern, you have
the right to file a complaint with the NPC at privacy.gov.ph.
Section 2
Personal Data We Collect
no1 collects personal data that is necessary, adequate, and not excessive in
relation to the purposes for which it is collected and processed. The categories
of personal data we collect include:
A. Registration & Identity Data
- Full legal name as it appears on your government-issued ID.
- Date of birth (used to verify that you are 21 years of age or older).
- Gender (optional, for personalization purposes).
- Nationality and country of residence.
- Email address and mobile number.
- Username and encrypted password.
B. Identity Verification (KYC) Data
- Scanned or photographed copies of government-issued photo ID (e.g., Philippine passport, SSS ID, UMID, driver's license, PhilSys National ID).
- Proof of address (e.g., utility bill, bank statement dated within 90 days).
- Selfie or liveness check image for biometric verification, where required.
- Proof of payment method (e.g., screenshot of GCash or PayMaya account showing your registered name).
C. Financial & Transaction Data
- Deposit and withdrawal amounts, dates, and payment method references.
- GCash or PayMaya account reference numbers (we do not store full wallet credentials).
- Bank account name and last four digits of account number for BPI, BDO, and Metrobank transfers.
- Transaction history and wallet balance records.
D. Gameplay & Behavioral Data
- Game session logs, including games played, wager amounts, win/loss outcomes, and session duration.
- Bonus and promotion usage history.
- Responsible gaming tool settings (deposit limits, self-exclusion status, cooling-off periods).
- Customer support interaction records, including chat transcripts and email correspondence.
E. Technical & Device Data
- IP address and approximate geolocation derived from IP.
- Device type, operating system, and browser type and version.
- Unique device identifiers.
- Session timestamps and page interaction logs.
- Cookie identifiers and similar tracking technology data (see Section 10).
Sensitive Personal Information: Government ID numbers, biometric data
(where collected for liveness verification), and financial account details are classified
as sensitive personal information under the DPA. no1 applies heightened security controls
to this category of data and processes it only to the extent strictly required for KYC
compliance and fraud prevention.
Section 3
How We Collect Your Data
no1 collects personal data through the following channels:
-
Directly from you: When you register for an Account, complete
KYC verification, make a deposit or withdrawal, contact customer support, respond
to a survey, or participate in a promotion.
-
Automatically: When you visit or interact with the Platform,
our servers and analytics tools automatically collect technical and behavioral
data, including IP address, device information, and session activity.
-
From third-party identity verification providers: When you
submit KYC documents, we may use a third-party verification service to
authenticate your identity. These providers return a verification result and
risk score to no1.
-
From payment processors: GCash, PayMaya, BPI, BDO, and
Metrobank may share transaction confirmation data with no1 to reconcile
deposits and withdrawals.
-
From fraud prevention and AML screening services: We may
receive data from third-party services that screen for politically exposed
persons (PEPs), sanctions lists, and adverse media in compliance with our
Anti-Money Laundering Act (AMLA) obligations.
Voluntary Provision: You are not legally required to provide your
personal data to no1. However, certain data — particularly registration details and
KYC documents — is necessary for us to provide our services. If you choose not to
provide this data, we may be unable to create or maintain your Account or process
your withdrawals.
Section 4
How We Use Your Personal Data
no1 uses the personal data it collects for the following purposes:
-
Account creation and management: To register your Account,
verify your identity, maintain your Wallet, and provide you with access to
the Platform's games and features.
-
Transaction processing: To process deposits and withdrawals
via GCash, PayMaya, BPI, BDO, and Metrobank, and to maintain accurate
financial records.
-
KYC and regulatory compliance: To verify that you meet the
21+ age requirement, confirm your identity, and comply with our obligations
under the Anti-Money Laundering Act (AMLA), PAGCOR regulations, and the DPA.
-
Fraud prevention and security: To detect, investigate, and
prevent fraudulent activity, money laundering, bonus abuse, and unauthorized
access to Accounts.
-
Customer support: To respond to your inquiries, resolve
disputes, and improve our support processes.
-
Responsible gaming: To monitor gameplay patterns for signs
of problem gambling, enforce deposit limits and self-exclusion orders, and
provide you with responsible gaming tools.
-
Platform improvement: To analyze usage patterns, conduct
A/B testing, and improve the design, performance, and game selection of
the Platform.
-
Marketing communications (with consent): To send you
promotional emails, SMS notifications, and in-platform messages about
bonuses, new games, and special offers — but only if you have opted in
to receive such communications. You may opt out at any time.
-
Legal obligations: To comply with court orders, regulatory
directives, and lawful requests from PAGCOR, AMLC, the NPC, and other
competent Philippine authorities.
Section 5
Legal Basis for Processing
Under the Philippine Data Privacy Act, no1 processes your personal data on
the following legal bases:
-
Contractual necessity: Processing is necessary to perform
the contract between you and no1 — specifically, to create and manage your
Account, process transactions, and provide access to the Platform's services.
This is the primary legal basis for most of our data processing activities.
-
Legal obligation: Processing is required for no1 to comply
with applicable Philippine law, including the DPA, AMLA, and PAGCOR
regulatory requirements. This includes KYC verification, AML screening,
and the retention of financial records.
-
Legitimate interests: Processing is necessary for no1's
legitimate interests in fraud prevention, platform security, and business
analytics, provided these interests are not overridden by your rights and
freedoms.
-
Consent: For marketing communications and optional analytics
cookies, no1 relies on your freely given, specific, informed, and unambiguous
consent. You may withdraw this consent at any time without affecting the
lawfulness of processing carried out before withdrawal.
Section 6
Sharing Your Personal Data
no1 does not sell, rent, or trade your personal data to third parties for
their own marketing purposes. We share your data only in the following
circumstances and only to the extent necessary:
-
Payment processors: GCash, PayMaya, BPI, BDO, and Metrobank
receive transaction data necessary to process your deposits and withdrawals.
Each processor operates under its own privacy policy and applicable Philippine
financial regulations.
-
Identity verification providers: Third-party KYC service
providers receive your identity documents and biometric data solely for the
purpose of verifying your identity. These providers are contractually bound
to process your data only for this purpose.
-
Game providers: The game studios whose titles are available
on the Platform may receive anonymized session data (e.g., game ID, wager
amount, outcome) for game integrity and RTP auditing purposes. They do not
receive your name, contact details, or financial information.
-
Fraud prevention and AML screening services: We share
relevant data with third-party screening services to fulfill our AMLA
obligations, including PEP and sanctions list screening.
-
Regulatory and law enforcement authorities: no1 will
disclose personal data to PAGCOR, AMLC, the NPC, the National Bureau of
Investigation (NBI), or other competent authorities when required by law,
court order, or regulatory directive.
-
Professional advisors: Our lawyers, auditors, and
accountants may access personal data to the extent necessary to provide
their professional services, subject to strict confidentiality obligations.
Cross-Border Transfers: Some of our third-party service providers
may be located outside the Philippines. Where personal data is transferred internationally,
no1 ensures that appropriate safeguards are in place — such as contractual data protection
clauses — to protect your data to a standard equivalent to that required under the DPA.
Section 7
Data Retention
no1 retains your personal data only for as long as necessary to fulfill the
purposes for which it was collected, or as required by applicable law. The
following retention periods apply:
-
Account and KYC data: Retained for the duration of your
Account and for a minimum of 5 years after Account closure,
in compliance with AMLA record-keeping requirements.
-
Financial transaction records: Retained for a minimum of
5 years from the date of the transaction, as required by
AMLA and applicable tax regulations.
-
Customer support records: Retained for 3 years
from the date of the last interaction, or longer if the interaction relates
to an ongoing dispute or investigation.
-
Marketing consent records: Retained for the duration of
your consent and for 1 year after withdrawal of consent,
to demonstrate compliance.
-
Technical and device logs: Retained for 12 months
from the date of collection, unless required for an ongoing security
investigation.
When personal data is no longer required, no1 will securely delete or
anonymize it in accordance with our data disposal procedures. Anonymized
data (which can no longer identify you) may be retained indefinitely for
statistical and analytical purposes.
Section 8
Security Measures
no1 implements a comprehensive set of technical and organizational security
measures to protect your personal data against unauthorized access, disclosure,
alteration, and destruction. These measures include:
-
Encryption in transit: All data transmitted between your
device and the no1 Platform is encrypted using TLS 1.2 or higher.
-
Encryption at rest: Sensitive personal data stored on our
servers — including KYC documents and financial records — is encrypted using
AES-256 encryption.
-
Access controls: Access to personal data is restricted to
no1 staff and contractors who have a legitimate need to access it for their
job functions. All access is logged and audited.
-
Two-factor authentication (2FA): no1 offers 2FA for player
Accounts and requires it for all internal staff accessing production systems.
-
Regular security audits: no1 conducts periodic penetration
tests and vulnerability assessments of its Platform and infrastructure.
-
Incident response: no1 maintains a documented data breach
response plan. In the event of a personal data breach that poses a real risk
to your rights and freedoms, we will notify the NPC within 72 hours and
affected players without undue delay, as required by the DPA.
Your Role in Security: While no1 takes extensive measures to protect
your data, you also play an important role. Keep your password strong and unique, enable
2FA on your Account, and never share your login credentials with anyone. If you suspect
unauthorized access to your Account, contact no1 support immediately.
Section 9
Your Data Privacy Rights
Under the Philippine Data Privacy Act of 2012, you have the following rights
in relation to your personal data held by no1:
-
Right to be Informed: You have the right to know what
personal data no1 collects about you, why it is collected, and how it is
used. This Privacy Policy fulfills that obligation.
-
Right of Access: You may request a copy of the personal
data no1 holds about you, including information on how it has been processed.
-
Right to Rectification: If any personal data we hold about
you is inaccurate or incomplete, you have the right to request that it be
corrected. You can update most Account details directly through your Account
settings.
-
Right to Erasure: You may request the deletion of your
personal data where it is no longer necessary for the purposes for which it
was collected, subject to our legal obligations to retain certain records
(see Section 7).
-
Right to Data Portability: You may request that no1 provide
your personal data in a structured, commonly used, and machine-readable format
so that you can transfer it to another service provider.
-
Right to Object: You may object to the processing of your
personal data for direct marketing purposes at any time. You may also object
to processing based on legitimate interests, subject to no1's overriding
legitimate grounds.
-
Right to Withdraw Consent: Where processing is based on
your consent (e.g., marketing communications), you may withdraw that consent
at any time without affecting the lawfulness of prior processing.
-
Right to Lodge a Complaint: If you believe no1 has violated
your data privacy rights, you may file a complaint with the National Privacy
Commission (NPC) at privacy.gov.ph.
To exercise any of the above rights, please contact our Data Protection Officer
at the email address listed in the footer of this page. We will respond to all
verified data subject requests within 15 business days of
receipt, as required by the DPA IRR.
Identity Verification for Requests: To protect your privacy, no1 will
verify your identity before processing any data subject request. You may be asked to
provide a copy of a government-issued ID and confirm your registered email address.
This step ensures that we do not disclose or delete data in response to fraudulent requests.
Section 10
Cookies & Tracking Technologies
no1 uses cookies and similar tracking technologies (such as web beacons and
local storage) on the Platform. A cookie is a small text file placed on your
device when you visit a website. Cookies help us recognize you, remember your
preferences, and analyze how the Platform is used.
We use the following categories of cookies:
-
Strictly Necessary Cookies: These cookies are essential for
the Platform to function. They maintain your login session, protect against
cross-site request forgery (CSRF), and ensure the security of your Account.
These cookies cannot be disabled without breaking core Platform functionality.
-
Functional Cookies: These cookies remember your preferences,
such as your preferred language, display settings, and responsible gaming
tool configurations. They improve your experience but are not strictly
required for the Platform to operate.
-
Analytics Cookies: With your consent, we use analytics
cookies to understand how players interact with the Platform — which pages
are visited most, where players drop off, and how features are used. This
data is aggregated and anonymized where possible.
-
Marketing Cookies: With your consent, we may use cookies
to deliver personalized promotional content within the Platform based on
your gameplay history and preferences.
You can manage your cookie preferences through the cookie settings panel
available on the Platform. You can also control cookies through your browser
settings, though disabling strictly necessary cookies may impair your ability
to use the Platform.
Section 11
Minors
The no1 Platform is strictly intended for individuals who are 21 years
of age or older, in accordance with the minimum legal age for
casino-style gambling in the Philippines. no1 does not knowingly collect,
process, or store personal data from individuals under the age of 21.
All players are required to confirm their age during registration and to
provide valid proof of age during KYC verification. If no1 discovers or
has reasonable grounds to believe that a registered player is under 21 years
of age, no1 will:
- Immediately suspend the Account and block access to the Platform.
- Delete all personal data associated with the Account as soon as practicable, subject to any legal obligations to retain records of the incident.
- Return any real-money deposits to the originating payment method after investigation.
- Forfeit all Bonus Funds and any winnings derived from Bonus Funds.
Parents and Guardians: If you believe that a minor in your care has
registered on the no1 Platform, please contact our support team immediately at the
email address listed in the footer of this page. We will investigate and take
appropriate action as quickly as possible.
Section 12
Changes to This Privacy Policy
no1 reserves the right to update or amend this Privacy Policy at any time to
reflect changes in our data processing practices, applicable law, or regulatory
requirements. When material changes are made, we will notify registered players
via email or a prominent notice on the Platform at least 7 days
before the changes take effect.
The "Last Updated" date at the top of this page will always
reflect the date of the most recent revision. We encourage you to review this
Privacy Policy periodically to stay informed about how no1 protects your data.
Your continued use of the Platform after the effective date of any amendment
constitutes your acknowledgment of the updated Privacy Policy. If you do not
agree with the revised policy, you must stop using the Platform and may request
Account closure in accordance with our Terms & Conditions.
Questions About This Policy: If you have any questions, concerns,
or requests relating to this Privacy Policy or no1's data processing practices,
please contact our Data Protection Officer. Our email address is listed in the footer
of this page. We aim to respond to all privacy-related inquiries within 5 business days.