1. Introduction
This Privacy Policy (hereinafter "Policy") describes how nurtstar (hereinafter "nurtstar", "the Platform", "we", "us", "our"), the operator of the online gambling and sports betting platform accessible at nurtstar.org, collects, uses, processes, stores, shares, and protects the personal information of registered players, visitors, and other individuals (hereinafter "you", "your", "Data Subject") who interact with the nurtstar Platform.
This Policy is issued in compliance with Republic Act No. 10173, otherwise known as the Data Privacy Act of 2012 (hereinafter "DPA"), its Implementing Rules and Regulations (IRR), and the applicable issuances of the National Privacy Commission (NPC) of the Philippines. nurtstar additionally operates under the regulatory oversight of the Philippine Amusement and Gaming Corporation (PAGCOR), which imposes its own data governance and reporting obligations on licensed operators.
By registering an account on nurtstar, accessing the Platform, or submitting any personal information to us, you acknowledge that you have read and understood this Policy and consent to the collection and processing of your personal data as described herein. If you do not agree with this Policy, you must not register an account or continue to use the nurtstar Platform.
This Policy should be read together with the nurtstar Terms & Conditions and Responsible Gaming Policy, which are incorporated by reference.
2. Data Controller
For the purposes of the Data Privacy Act of 2012 and its implementing regulations, nurtstar is the Personal Information Controller (PIC) in respect of the personal data collected through the Platform. As PIC, nurtstar determines the purposes for which and the means by which personal data is processed, and bears the corresponding legal obligations and accountability under the DPA.
nurtstar has designated a Data Protection Officer (DPO) who is responsible for overseeing compliance with this Policy and applicable data privacy laws. Contact details for the DPO are provided in Section 15 of this Policy.
3. Categories of Personal Data We Collect
nurtstar collects the following categories of personal data from Data Subjects:
3.1 Identity and Registration Data
- Full legal name as it appears on a government-issued identification document;
- Date of birth and age verification information;
- Gender;
- Nationality and country of residence;
- Government-issued identification numbers (e.g., PhilSys National ID number, passport number, driver's licence number) for KYC purposes.
3.2 Contact and Communication Data
- Registered email address;
- Philippine mobile number;
- Residential address, including barangay, city or municipality, province, and postal code;
- Records of communications with nurtstar Support, including chat transcripts, email correspondence, and support ticket content.
3.3 Financial and Transaction Data
- Deposit and withdrawal transaction records, including amounts, timestamps, and payment method identifiers;
- GCash account reference identifiers (not full GCash credentials), PayMaya reference identifiers, and bank account details where required for withdrawal processing;
- Account balance history;
- Bonus and promotional transaction records;
- Source of funds documentation submitted for KYC or AML compliance purposes.
3.4 Gaming and Behavioural Data
- Game session logs, including games played, bet amounts, win/loss outcomes, and session durations;
- Sports betting activity, including markets wagered on and results;
- Login history, including timestamps and IP addresses;
- Device identifiers, browser type and version, and operating system;
- Responsible gaming tool usage (deposit limits set, cooling-off periods activated, self-exclusion records).
3.5 Verification Documentation
- Copies of government-issued photo identification documents submitted for KYC verification;
- Proof of address documentation (e.g., utility bill, bank statement);
- Supporting financial documentation submitted to satisfy AML obligations.
4. How We Collect Personal Data
nurtstar collects personal data through the following means:
| Collection Method | Description |
|---|---|
| Account Registration | Data provided directly by the Player when creating a nurtstar account, including name, date of birth, email, and mobile number. |
| KYC Submission | Identity and address verification documents submitted by Players as required by PAGCOR and AML regulations. |
| Gameplay Activity | Automatically generated records of game sessions, bets, outcomes, and account transactions during Platform use. |
| Payment Transactions | Transaction metadata generated when Players deposit or withdraw via GCash, PayMaya, BPI, BDO, Metrobank, or card payment. |
| Support Interactions | Information provided by Players when contacting nurtstar Support via live chat, email, or messaging channels. |
| Cookies & Technical Data | Automatically collected technical data via browser cookies, session tokens, and server logs when a Player accesses the Platform. |
| Third-Party Verification | Data received from identity verification service providers and payment processors engaged by nurtstar to facilitate KYC and transaction processing. |
5. Purpose and Legal Basis for Processing
nurtstar processes personal data for the following purposes and under the following legal bases as recognised under the Data Privacy Act of 2012:
5.1 Account Creation and Management
Purpose: To register and maintain Player accounts, authenticate logins, and manage account settings.
Legal Basis: Performance of a contract (the nurtstar Terms & Conditions) to which the Data Subject is a party.
5.2 Identity Verification and KYC Compliance
Purpose: To verify the age (21+ requirement), identity, and eligibility of Players as required by PAGCOR and applicable Philippine law.
Legal Basis: Compliance with a legal obligation under PAGCOR regulations and the Anti-Money Laundering Act.
5.3 Payment Processing
Purpose: To process deposits, withdrawals, and financial transactions via GCash, PayMaya, BPI, BDO, Metrobank, and other authorised Philippine payment methods.
Legal Basis: Performance of contract; compliance with financial reporting obligations.
5.4 Anti-Money Laundering and Fraud Prevention
Purpose: To monitor transactions and account activity for suspicious patterns, fulfil reporting obligations to the Anti-Money Laundering Council (AMLC), and prevent fraud and financial crime.
Legal Basis: Legal obligation under the Anti-Money Laundering Act (AMLA) as amended and PAGCOR licensing conditions.
5.5 Responsible Gaming Compliance
Purpose: To administer responsible gaming tools (deposit limits, self-exclusion), monitor for signs of problem gambling, and comply with PAGCOR's responsible gaming requirements.
Legal Basis: Legitimate interest; legal obligation under PAGCOR regulation.
5.6 Customer Support
Purpose: To respond to Player inquiries, process complaints, and provide account-related assistance.
Legal Basis: Performance of contract; legitimate interest.
5.7 Platform Improvement and Analytics
Purpose: To analyse Platform usage patterns, improve game selection, optimise user experience, and diagnose technical issues.
Legal Basis: Legitimate interest in improving the Platform for all Players.
5.8 Marketing Communications
Purpose: To send Players promotional offers, bonus notifications, and casino updates where the Player has opted in to receive such communications.
Legal Basis: Consent. Players may withdraw consent to marketing at any time as described in Section 13.
6. Disclosure and Sharing of Personal Data
nurtstar does not sell, rent, or trade personal data to unrelated third parties. Personal data is disclosed only in the circumstances described below:
6.1 Service Providers and Processors
nurtstar engages third-party service providers who process personal data on nurtstar's behalf as Personal Information Processors (PIPs) under data processing agreements. These include:
- Identity verification and KYC service providers;
- Payment processing partners (e.g., GCash, PayMaya, bank partners);
- Game technology providers whose games are integrated into the Platform;
- Cloud hosting and data centre service providers;
- Customer support platform providers;
- Fraud detection and cybersecurity service providers.
All such processors are contractually bound to process data only for the specified purpose and in accordance with nurtstar's instructions and the DPA.
6.2 Regulatory and Law Enforcement Authorities
nurtstar is required by law to disclose personal data to competent Philippine regulatory and law enforcement authorities where legally mandated, including:
- PAGCOR — for regulatory compliance, audit, and licensing purposes;
- The Anti-Money Laundering Council (AMLC) — where transactions meet mandatory reporting thresholds or trigger suspicious activity reporting obligations under AMLA;
- The National Privacy Commission (NPC) — in connection with personal data breach notifications or NPC investigations;
- Any other competent government authority, court, or tribunal where required by a valid legal process, court order, or applicable Philippine law.
6.3 Business Transfers
In the event of a merger, acquisition, restructuring, or sale of assets involving nurtstar, personal data held by nurtstar may be transferred to the acquiring entity, subject to the same protections afforded under this Policy. Players will be notified of any such transfer that materially affects their data rights.
7. Data Retention
nurtstar retains personal data only for as long as is necessary to fulfil the purposes for which it was collected, or as required by applicable Philippine law and PAGCOR regulations. The following general retention periods apply:
| Data Category | Retention Period | Basis |
|---|---|---|
| Account registration and KYC data | 5 years from account closure | PAGCOR regulatory requirement; AMLA |
| Financial transaction records | 5 years from transaction date | AMLA; PAGCOR; tax obligations |
| Game session logs | 3 years from session date | PAGCOR audit requirements |
| Support communications | 3 years from last interaction | Legitimate interest; dispute resolution |
| Self-exclusion records | Duration of exclusion + 5 years | PAGCOR responsible gaming obligations |
| Marketing consent records | Until consent is withdrawn + 1 year | DPA consent documentation requirement |
Upon expiry of the applicable retention period, personal data will be securely deleted, anonymised, or archived in a manner that prevents identification of the Data Subject, unless retention is required by a continuing legal obligation.
8. Data Security
nurtstar implements organisational and technical security measures to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or access. These measures include, but are not limited to:
- SSL/TLS Encryption: All data transmitted between Players' devices and nurtstar's servers is encrypted using SSL/TLS protocols;
- Access Controls: Access to personal data is restricted to authorised nurtstar personnel who require it to perform their job functions, on a need-to-know basis;
- Password Hashing: Account passwords are stored in hashed form using industry-standard cryptographic algorithms; nurtstar personnel cannot retrieve plaintext passwords;
- Secure Data Centres: Personal data is hosted on servers in facilities with physical security controls;
- Periodic Security Audits: nurtstar conducts periodic technical security reviews and vulnerability assessments of its Platform and data systems;
- Data Breach Response: nurtstar maintains a data breach response procedure in compliance with NPC Circular 16-03, including notification obligations to the NPC and affected Data Subjects within the prescribed periods.
Important: No internet-based platform can guarantee absolute security. Players are responsible for maintaining the security of their account credentials. If you believe your nurtstar account has been compromised, contact Support immediately at [email protected].
9. Cookies and Tracking Technologies
nurtstar uses cookies and similar tracking technologies (including session tokens, local storage, and analytics pixels) to operate and improve the Platform. The categories of cookies used are as follows:
- Strictly Necessary Cookies: Required for core Platform functionality, including maintaining login sessions, processing transactions, and enforcing security controls. These cannot be disabled without rendering the Platform non-functional.
- Performance and Analytics Cookies: Collect anonymised or aggregated data about how visitors use the Platform — pages visited, session durations, errors encountered — to help nurtstar improve user experience.
- Functional Cookies: Remember Player preferences such as language settings, responsible gaming limits, and display options across sessions.
- Marketing Cookies: Used to deliver relevant promotions and personalised content to Players who have consented to marketing. Players may withdraw marketing consent at any time.
Players may manage cookie preferences through their browser settings. Disabling cookies beyond the strictly necessary category may affect Platform functionality. nurtstar's cookie practices comply with the DPA and applicable NPC guidance on online tracking.
10. Your Data Subject Rights
Under the Data Privacy Act of 2012 and its implementing regulations, Data Subjects have the following rights in relation to their personal data held by nurtstar. Requests to exercise these rights should be submitted to the nurtstar Data Protection Officer at the contact details provided in Section 15.
Right to Be Informed
The right to be informed of how your personal data is being collected, used, and processed — as set out in this Policy.
Right of Access
The right to request a copy of the personal data nurtstar holds about you, and information about how it is used.
Right to Rectification
The right to request correction of inaccurate or incomplete personal data held in your nurtstar account.
Right to Erasure
The right to request deletion of personal data where it is no longer necessary, subject to overriding legal retention obligations under PAGCOR regulation and AMLA.
Right to Object
The right to object to processing of your personal data for direct marketing or profiling purposes at any time.
Right to Data Portability
The right to receive personal data you have provided to nurtstar in a structured, commonly used, and machine-readable format.
Right to Damages
The right to seek compensation for any damages suffered as a result of inaccurate, incomplete, outdated, false, or unlawfully obtained personal data held by nurtstar.
Right to Complain
The right to lodge a complaint with the National Privacy Commission (NPC) of the Philippines if you believe your data rights have been violated by nurtstar.
nurtstar will respond to verified Data Subject requests within fifteen (15) business days of receipt. Requests may be subject to identity verification before processing. Where a request cannot be fulfilled due to a legal obligation — such as mandatory AML retention requirements — nurtstar will explain the applicable legal basis in writing.
11. Minors and Age Restriction
The nurtstar Platform is strictly restricted to persons aged 21 years or older, as required by PAGCOR. nurtstar does not knowingly collect personal data from individuals under the age of 21. Age verification is conducted during the KYC process for all registered accounts.
If nurtstar discovers or is notified that personal data has been collected from a person under the age of 21, nurtstar will immediately close the associated account, delete or anonymise all personal data collected in respect of that individual, return any real-money balance (net of bonuses), and take the further steps required by PAGCOR regulation. Parents or guardians who believe their child has registered on the Platform should contact nurtstar Support immediately.
12. Cross-Border Data Transfers
nurtstar primarily stores and processes personal data within the Republic of the Philippines. Where personal data is transferred to service providers or processors operating outside the Philippines — for example, in connection with cloud infrastructure, game technology providers, or fraud detection services — such transfers are conducted only where:
- The recipient country's laws afford a level of protection at least comparable to the DPA; or
- nurtstar has entered into data transfer agreements with the recipient that incorporate equivalent data protection standards and obligations consistent with the DPA and applicable NPC guidance on cross-border data flows.
Players may request information about cross-border data transfers affecting their personal data by contacting the nurtstar DPO.
13. Marketing Communications and Opt-Out
nurtstar may send Players promotional communications, bonus notifications, and Platform updates by email or messaging where the Player has provided consent at registration or at any subsequent time. Marketing communications will always clearly identify nurtstar as the sender and will include a mechanism to unsubscribe or withdraw consent.
Players may withdraw consent to marketing communications at any time by:
- Using the unsubscribe link included in any nurtstar marketing email; or
- Contacting nurtstar Support and requesting removal from all marketing communications.
Withdrawal of consent to marketing does not affect the lawfulness of processing conducted prior to withdrawal, and does not affect nurtstar's ability to send transactional communications (e.g., deposit confirmations, withdrawal notifications, account security alerts) that are necessary for the administration of a Player's account.
14. Changes to This Policy
nurtstar reserves the right to update or amend this Privacy Policy at any time to reflect changes in applicable law, regulatory requirements, or nurtstar's data processing practices. Where changes are material, nurtstar will notify registered Players via email to their registered address or by a notice displayed on the Platform prior to the change taking effect.
The effective date at the top of this Policy will be updated to reflect the date of the most recent revision. Continued use of the nurtstar Platform after the revised Policy takes effect constitutes acceptance of the updated terms. Players who do not accept material changes to this Policy should cease using the Platform and contact nurtstar to arrange account closure.
15. Contact and Data Protection Officer
If you have any questions, concerns, or requests relating to this Privacy Policy, your personal data rights, or nurtstar's data processing practices, please contact the nurtstar Data Protection Officer:
Data Protection Officer
nurtstar Casino
Email:
[email protected]
Live Chat:
Available 24/7 on the Platform
Jurisdiction:
Republic of the Philippines
If you are not satisfied with nurtstar's response to a data privacy concern, you have the right to lodge a complaint directly with the National Privacy Commission (NPC) of the Philippines through the NPC's official complaints process.