At toto21, your privacy matters. This Privacy Policy explains exactly what personal data we collect, why we collect it, how we use and protect it, and what rights you have as a toto21 player in the Philippines.
Six core commitments toto21 makes to every Filipino player regarding their personal information.
Every piece of data transmitted between your device and toto21 is protected by bank-grade 256-bit SSL encryption. Your personal details, payment information, and account credentials are never sent in plain text.
toto21 does not sell, rent, or trade your personal data to third parties for marketing purposes. Your information is used solely to operate your account, process transactions, and improve your toto21 experience.
toto21 processes personal data in compliance with the Philippine Data Privacy Act of 2012 (Republic Act No. 10173) and its implementing rules. Your rights as a data subject under Philippine law are fully respected.
toto21 collects only the personal data that is strictly necessary to provide our services, comply with regulatory requirements, and keep your account secure. We do not collect data beyond what is needed for these purposes.
You have the right to access the personal data toto21 holds about you and to request corrections where information is inaccurate or incomplete. Submit a request to our support team and we will respond within a reasonable timeframe.
Subject to our legal and regulatory obligations, you may request the deletion of your personal data from toto21's systems. Requests are reviewed on a case-by-case basis and processed in accordance with applicable Philippine law.
toto21 ("toto21," "we," "us," or "our") operates the online gaming platform accessible at toto21.club (the "Platform"). We are committed to protecting the privacy and personal data of every player who registers and uses our services.
This Privacy Policy describes how toto21 collects, uses, stores, shares, and protects personal information in connection with your use of the Platform. It applies to all players, visitors, and individuals who interact with toto21 through our website, customer support channels, or any other means.
Scope: This Privacy Policy applies to all personal data processed by toto21 in connection with the Platform. By registering an account or using the Platform, you acknowledge that you have read and understood this Privacy Policy and consent to the processing of your personal data as described herein.
toto21 processes personal data in accordance with the Philippine Data Privacy Act of 2012 (Republic Act No. 10173), its Implementing Rules and Regulations, and the guidelines issued by the National Privacy Commission (NPC) of the Philippines. Where applicable, toto21 also observes the data protection requirements of PAGCOR, the Philippine Amusement and Gaming Corporation.
This Privacy Policy should be read together with toto21's Terms & Conditions and Responsible Gaming Policy, both of which are incorporated by reference.
toto21 collects personal data that is necessary to provide our services, verify your identity, process transactions, and comply with our legal and regulatory obligations. The categories of personal data we collect include:
Note: toto21 does not collect or store full payment card numbers, CVV codes, or online banking passwords. Payment transactions are processed through secure third-party payment gateways, and toto21 only receives transaction reference data.
toto21 collects personal data through the following means:
toto21 uses the personal data we collect for the following purposes:
| Purpose | Data Used |
|---|---|
| Account creation and management | Identity, contact, and login credential data |
| Age and identity verification (KYC) | Identity documents, date of birth, selfie images |
| Processing deposits and withdrawals | Financial data, payment method details, transaction history |
| Providing gaming services | Gaming activity data, account preferences |
| Fraud prevention and security | Technical data, IP address, device information, transaction patterns |
| Anti-money laundering compliance | Financial data, identity data, transaction history |
| Responsible gaming monitoring | Gaming activity data, responsible gaming settings |
| Customer support | Communications data, account information |
| Marketing communications (with consent) | Contact information, gaming preferences |
| Platform improvement and analytics | Technical data, usage logs (aggregated and anonymized) |
| Legal and regulatory compliance | All categories as required by applicable law |
toto21 will not use your personal data for any purpose that is incompatible with the purposes listed above without first obtaining your consent or establishing another lawful basis for processing.
toto21 processes your personal data on one or more of the following legal bases as recognized under the Philippine Data Privacy Act of 2012:
toto21 does not sell, rent, or trade your personal data to third parties for their own marketing purposes. We may share your personal data with the following categories of recipients only to the extent necessary for the purposes described in this Privacy Policy:
toto21 engages trusted third-party service providers to assist in operating the Platform, including payment processors (GCash, PayMaya, BPI, BDO, Metrobank), identity verification providers, cloud hosting services, customer support platforms, and fraud detection services. These providers are contractually bound to process your data only on toto21's instructions and in accordance with applicable data protection law.
toto21 may disclose personal data to PAGCOR, the National Privacy Commission, the Anti-Money Laundering Council (AMLC), or other competent Philippine authorities where required by law, court order, or regulatory directive. toto21 will notify you of such disclosures where legally permitted to do so.
In the event of a merger, acquisition, or sale of all or substantially all of toto21's assets, your personal data may be transferred to the acquiring entity. You will be notified of any such transfer and the privacy practices of the successor entity prior to the transfer taking effect.
No Cross-Border Transfers Without Safeguards: toto21 does not transfer your personal data outside the Philippines unless adequate data protection safeguards are in place and the transfer is permitted under the Philippine Data Privacy Act and NPC guidelines.
toto21 uses cookies and similar tracking technologies to operate the Platform, remember your preferences, analyze usage patterns, and support security functions. The types of cookies we use include:
You can manage cookie preferences through your browser settings. Note that disabling strictly necessary cookies may affect the functionality of the Platform. toto21 does not use third-party advertising cookies or behavioral tracking cookies for ad targeting purposes.
toto21 retains personal data for as long as necessary to fulfill the purposes for which it was collected, comply with legal and regulatory obligations, resolve disputes, and enforce our agreements. The following general retention periods apply:
| Data Category | Retention Period |
|---|---|
| Account and identity data | Duration of account plus 5 years after closure |
| KYC verification documents | Duration of account plus 5 years after closure |
| Financial transaction records | Minimum 5 years (AML regulatory requirement) |
| Gaming activity logs | Duration of account plus 3 years after closure |
| Customer support communications | 3 years from date of communication |
| Technical and device logs | 12 months on a rolling basis |
| Marketing consent records | Until consent is withdrawn, plus 1 year |
Upon expiry of the applicable retention period, toto21 will securely delete or anonymize your personal data in accordance with our data disposal procedures. Where data is anonymized, it may be retained indefinitely for statistical and analytical purposes.
toto21 implements a comprehensive set of technical and organizational security measures to protect your personal data against unauthorized access, disclosure, alteration, or destruction. These measures include:
Your Role in Security: While toto21 takes extensive measures to protect your data, you also play an important role. Keep your toto21 login credentials confidential, use a strong and unique password, enable two-factor authentication where available, and notify toto21 immediately if you suspect unauthorized access to your account.
In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, toto21 will notify the National Privacy Commission within 72 hours of becoming aware of the breach and will inform affected players without undue delay.
Under the Philippine Data Privacy Act of 2012, you have the following rights with respect to your personal data held by toto21:
To exercise any of the above rights, please contact toto21's Data Protection Officer using the contact details provided in Section 13 of this Privacy Policy. toto21 will respond to all verified data subject requests within thirty (30) days of receipt, or within such extended period as permitted by applicable law.
The toto21 Platform is strictly intended for individuals who are at least 21 years of age. toto21 does not knowingly collect personal data from persons under 21 years of age. The minimum age requirement is enforced through our KYC verification process, which requires all players to submit valid government-issued identification confirming their date of birth.
If toto21 becomes aware that personal data has been collected from a person under 21 years of age, we will immediately suspend the associated account, delete the personal data in question, and take appropriate action in accordance with our Terms & Conditions and applicable law.
Parents and Guardians: If you believe that a minor under your care has registered on the toto21 Platform or provided personal data to toto21, please contact our support team immediately at support@toto21.club so that we can take prompt action.
toto21 may update this Privacy Policy from time to time to reflect changes in our data processing practices, applicable law, or regulatory requirements. The date of the most recent revision is displayed at the top of this page.
Where changes are material — meaning they significantly affect your rights or how toto21 processes your personal data — toto21 will provide advance notice via email to your registered address or through a prominent notice on the Platform. Non-material changes, such as typographical corrections or clarifications, may take effect immediately upon publication.
Your continued use of the toto21 Platform following the effective date of any updated Privacy Policy constitutes your acknowledgment of the changes. If you do not agree with the updated Privacy Policy, you should cease using the Platform and may request account closure by contacting our support team.
If you have any questions, concerns, or requests regarding this Privacy Policy or toto21's data processing practices, please contact us through the following channels:
Effective Date: This Privacy Policy is effective as of January 2026 and supersedes all previous versions. By continuing to use the toto21 Platform after this date, you confirm your acknowledgment of this Privacy Policy.
Join thousands of Filipino players who trust toto21 for a secure, fair, and exciting online casino experience. GCash deposits, live dealers, and 500+ games await. 21+ only.
⚠ 21+ ONLY • PLAY RESPONSIBLY • PAGCOR REGULATED