1. Introduction and Scope
Cobalt Payments Inc. (“Company,” “Cobalt Payments,” “we,” “us,” or “our”) is committed to protecting your privacy and safeguarding the personal information entrusted to us. This Privacy Policy (“Policy”) describes how we collect, use, disclose, store, protect, and otherwise process personal information in connection with the Cxbolt Payment Gateway mobile application (the “Application”), our website at www.cobaltpayments.com, and the payment processing services provided thereunder (collectively, the “Services”).
This Policy applies to all individuals who access, download, install, or use the Application, including merchants, business owners, employees, authorized agents, and end-user customers whose payment data may be processed through the Application (collectively, “you” or “your”). This Policy applies regardless of whether you access the Application through the Apple App Store, Google Play Store, or any other distribution platform.
By downloading, installing, accessing, or using the Application, you acknowledge that you have read, understood, and agree to the collection, use, and disclosure of your information as described in this Policy. If you do not agree with the practices described herein, please do not download, install, access, or use the Application.
2. Information We Collect
2.1 Information You Provide Directly
We collect information that you voluntarily provide to us when you register for an account, apply for merchant services, use the Services, or otherwise communicate with us. This includes:
- Account Registration Information: Full legal name, date of birth, email address, phone number, mailing address, username, and password;
- Business Information: Business name, legal entity type, tax identification number (EIN/SSN), business address, industry classification (MCC), years in business, estimated monthly processing volume, business website URL, and articles of incorporation or organization;
- Identity Verification Information: Government-issued identification documents (driver’s license, passport, state ID), Social Security Number or Individual Taxpayer Identification Number, and biometric authentication data (fingerprint, facial recognition) used to access the Application;
- Financial Information: Bank account numbers, routing numbers, bank statements, credit reports, and financial history as required for underwriting and settlement;
- Beneficial Ownership Information: Names, addresses, dates of birth, and identification numbers of individuals owning 25% or more of the business entity, as required by the Corporate Transparency Act and FinCEN regulations;
- Communications: Content of emails, chat messages, support tickets, phone calls, and other communications with our customer support team;
- Survey and Feedback Data: Responses to surveys, questionnaires, product reviews, and feedback forms;
2.2 Transaction and Payment Data
IMPORTANT DISCLOSURE REGARDING SENSITIVE CARDHOLDER DATA: Raw credit card numbers, full primary account numbers (PANs), card verification values (CVV/CVC/CVV2), magnetic stripe data, EMV chip data, PIN blocks, and other sensitive cardholder authentication data (collectively, “Sensitive Cardholder Data”) are never transmitted to, processed by, stored on, or accessible within any network, server, database, system, or infrastructure owned, operated, or controlled by Cobalt Payments.
All Sensitive Cardholder Data is captured, tokenized, and encrypted exclusively by PCI DSS-certified third-party payment processors, acquiring banks, PCI-validated point-to-point encryption (P2PE) solution providers, and card network-approved service providers (collectively, “Third-Party Payment Processors”) at the point of capture — before any data element enters the Company’s environment. The collection, processing, encryption, storage, and protection of Sensitive Cardholder Data is governed entirely by the privacy policies, terms of service, and security certifications of the applicable Third-Party Payment Processors, not by this Privacy Policy.
The Company receives and processes only the following non-sensitive, non-reversible transaction data elements:
- Non-reversible payment tokens issued by Third-Party Payment Processors (which cannot be used to reconstruct, derive, or reverse-engineer full cardholder account information);
- Truncated card references (e.g., the last four digits of a card number) and masked account identifiers;
- Card brand, card type (credit/debit), and issuing country;
- Transaction amounts, dates, times, currency, and descriptions;
- Authorization codes, response codes, and decline reasons;
- Settlement status and batch identifiers;
- ACH routing numbers and masked account numbers for electronic check transactions;
- Billing and shipping addresses associated with transactions;
- Refund, void, and chargeback data;
- Recurring billing schedules and subscription details;
None of the data elements listed above constitute Sensitive Cardholder Data, and none can be used individually or in combination to reconstruct full payment card account information.
2.3 Information Collected Automatically
When you access or use the Application, we automatically collect certain technical and usage information, including:
- Device Information: Device type, model, manufacturer, operating system and version, unique device identifiers (UDID, IDFA, GAID, Android ID), screen resolution, and language settings;
- Network Information: IP address, mobile carrier, Wi-Fi network name (SSID), connection type (Wi-Fi, cellular, VPN), and signal strength;
- Application Usage Data: Pages viewed, features accessed, buttons clicked, time spent on each screen, session duration and frequency, crash logs, and performance diagnostics;
- Location Data: Approximate geographic location derived from IP address. We do not collect precise GPS location data unless you expressly enable location services for the Application and provide affirmative consent;
- Log Data: Access timestamps, error logs, referring URLs, browser type (for web-based services), and API call records;
2.4 Information from Third Parties
We may receive information about you from third-party sources, which we may combine with the information we collect directly. These sources include: acquiring banks and payment processors (transaction status, settlement data); card networks (BIN data, network rules compliance); credit bureaus and identity verification providers (creditworthiness, identity confirmation); fraud prevention services (device reputation, risk scoring); government databases (sanctions screening, business registration verification); and App Stores (purchase records, subscription status).
2.5 Cookies and Similar Technologies
Our web-based services and the Application may use cookies, web beacons, pixel tags, SDKs, and similar tracking technologies to collect information about your interactions with our Services. These technologies help us remember your preferences, analyze usage patterns, deliver relevant content, and prevent fraud. You can manage cookie preferences through your device or browser settings; however, disabling certain cookies may limit functionality.
3. How We Use Your Information
We use the personal information we collect for the following purposes:
| Purpose | Categories of Data | Legal Basis (GDPR) |
|---|---|---|
| Account registration and verification | Registration, identity, business info | Contract performance; Legal obligation |
| Payment transaction processing | Transaction data, payment card data, financial info | Contract performance; Legal obligation |
| Fraud prevention and risk management | Device info, transaction patterns, location, identity data | Legitimate interest; Legal obligation |
| Regulatory compliance (AML/KYC/BSA) | Identity, business, beneficial ownership, financial info | Legal obligation |
| Customer support and communications | Communications, account info, usage data | Contract performance; Legitimate interest |
| Service improvement and analytics | Usage data, device info, performance data | Legitimate interest |
| Marketing and promotional communications | Contact info, usage patterns, preferences | Consent; Legitimate interest |
| Legal proceedings and dispute resolution | All relevant categories | Legitimate interest; Legal obligation |
4. How We Share Your Information
We do not sell your personal information. We may share your information with the following categories of recipients and for the following purposes:
4.1 Service Providers and Payment Partners
We share information with trusted third-party service providers who assist us in operating the Services, including: acquiring banks and payment processors (for transaction processing and settlement); card networks such as Visa, Mastercard, American Express, and Discover (for authorization and compliance); identity verification and fraud prevention providers; cloud hosting and infrastructure providers; analytics and performance monitoring services; customer support platforms; and email and communication service providers. All service providers are contractually obligated to use your information only for the purposes for which it was disclosed and to maintain appropriate security measures.
4.2 Legal and Regulatory Disclosures
We may disclose your information when required by law or when we believe in good faith that disclosure is necessary to: (a) comply with a legal obligation, subpoena, court order, or governmental request; (b) protect and defend the rights, property, or safety of the Company, our users, or the public; (c) prevent fraud, money laundering, or other illegal activities; (d) enforce our Terms of Use and Terms of Service; or (e) comply with Card Network Rules, PCI DSS requirements, or the rules of regulatory authorities, including FinCEN, OFAC, and state financial regulators.
4.3 Business Transfers
In the event of a merger, acquisition, reorganization, bankruptcy, dissolution, or other corporate transaction involving the Company, your personal information may be transferred to the successor entity. We will provide notice of any such transfer and any choices you may have regarding your information.
4.4 With Your Consent
We may share your information for any purpose disclosed to you at the time of collection or with your express consent.
4.5 Aggregated and De-Identified Data
We may share aggregated, anonymized, or de-identified data that cannot reasonably be used to identify you with third parties for research, analytics, industry benchmarking, and business purposes. Such data is not considered personal information under this Policy.
4.6 Mobile Information and SMS/Text Messaging Data
No mobile information — including your mobile telephone number and your consent to receive text messages — will be sold, rented, or shared with any third parties or affiliates for their own marketing or promotional purposes. Text messaging originator opt-in data and consent are excluded from all of the information-sharing categories described in this Section 4; such data will not be shared with any third party for marketing purposes under any circumstance.
We use a trusted messaging provider (our SMS delivery vendor) solely to transmit the transactional text messages you have consented to receive — for example, payment receipts and confirmations — on our behalf and on behalf of the merchants with whom you transact. That provider is contractually restricted to using your information only to deliver those messages and may not use it for its own purposes. For details about the text-messaging program, message frequency, applicable rates, and how to opt out, see our Terms of Use.
5. Data Retention
We retain your personal information for as long as necessary to fulfill the purposes for which it was collected, including to satisfy our legal, regulatory, accounting, and reporting obligations. Specific retention periods include:
- Account and registration data: Duration of the account relationship plus seven (7) years;
- Transaction records: Seven (7) years from the date of the transaction, as required by the IRS, Card Network Rules, and applicable state laws;
- KYC/AML compliance records: Five (5) years following account closure, as required by the Bank Secrecy Act;
- Communications and support records: Three (3) years from the date of the communication;
- Device and usage analytics: Twenty-four (24) months from the date of collection;
- Marketing preferences: Until you withdraw consent or unsubscribe;
When personal information is no longer required, we will securely delete or anonymize it in accordance with our data retention and disposal policies and applicable law.
6. Data Security
6.1 Sensitive Cardholder Data — Third-Party Security
As disclosed in Section 2.2, Sensitive Cardholder Data (including full credit card numbers, PANs, CVV/CVC codes, magnetic stripe data, EMV chip data, and PIN blocks) does not pass through, reside on, or touch any system owned or operated by Cobalt Payments. The tokenization, encryption, secure transmission, and storage of all Sensitive Cardholder Data is performed exclusively by PCI DSS-certified Third-Party Payment Processors. The security of Sensitive Cardholder Data within the environments of those Third-Party Payment Processors is governed by their own security programs, PCI DSS certifications, card network compliance obligations, and applicable regulatory requirements — not by this Privacy Policy. We encourage you to review the privacy and security policies of the Third-Party Payment Processors whose services are utilized through the Application.
6.2 Cobalt Payments’ Security Program
For the non-sensitive data elements within the Company’s environment (tokens, truncated references, transaction metadata, account information, and other data described in Section 2), we implement comprehensive administrative, technical, and physical security measures, including but not limited to:
- PCI DSS compliance scoped to the Company’s role as a service provider that does not store, process, or transmit Sensitive Cardholder Data;
- TLS 1.2 or higher encryption for all data transmitted between your device and our servers;
- AES-256 encryption for all data at rest within our environment;
- Multi-factor authentication (MFA) for all account access;
- Role-based access controls with the principle of least privilege;
- Regular penetration testing and vulnerability assessments conducted by independent third parties;
- SOC 2 Type II certification;
- Continuous monitoring, intrusion detection, and real-time alerting systems;
- Employee security training and background checks;
- Incident response plan with defined escalation procedures;
While we employ commercially reasonable measures to protect the information within our environment, no method of transmission over the internet or electronic storage is completely secure. We cannot guarantee absolute security. The Company is not responsible for breaches, unauthorized access, or unauthorized disclosure of Sensitive Cardholder Data that occurs within the systems, networks, or infrastructure of any Third-Party Payment Processor, as such data never enters the Company’s environment.
7. Your Rights and Choices
7.1 Rights Under the California Consumer Privacy Act (CCPA/CPRA)
If you are a California resident, you have the following rights under the CCPA as amended by the CPRA:
- Right to Know: You have the right to request disclosure of the categories and specific pieces of personal information we have collected about you, the sources from which it was collected, the business purposes for collection, and the categories of third parties with whom it was shared;
- Right to Delete: You have the right to request that we delete personal information we have collected from you, subject to certain exceptions (such as retention required by law or for transaction completion);
- Right to Correct: You have the right to request correction of inaccurate personal information;
- Right to Opt Out of Sale/Sharing: We do not sell personal information. If this practice changes, we will provide a “Do Not Sell or Share My Personal Information” link;
- Right to Limit Use of Sensitive Personal Information: You may request that we limit our use and disclosure of sensitive personal information to purposes necessary for performing the Services;
- Right to Non-Discrimination: We will not discriminate against you for exercising any of your CCPA rights;
7.2 Rights Under the General Data Protection Regulation (GDPR)
If you are located in the European Economic Area (EEA), United Kingdom, or Switzerland, you have the following rights under the GDPR:
- Right of Access (Article 15): The right to obtain confirmation as to whether your personal data is being processed and to receive a copy of such data;
- Right to Rectification (Article 16): The right to have inaccurate personal data corrected;
- Right to Erasure (Article 17): The right to have your personal data deleted under certain circumstances;
- Right to Restriction of Processing (Article 18): The right to restrict the processing of your personal data in certain circumstances;
- Right to Data Portability (Article 20): The right to receive your personal data in a structured, commonly used, machine-readable format;
- Right to Object (Article 21): The right to object to processing based on legitimate interests or for direct marketing purposes;
- Right to Withdraw Consent (Article 7): Where processing is based on consent, the right to withdraw consent at any time without affecting the lawfulness of prior processing;
- Right to Lodge a Complaint: The right to lodge a complaint with a supervisory authority in your country of residence;
7.3 Additional State Privacy Rights
Residents of Virginia (VCDPA), Colorado (CPA), Connecticut (CTDPA), Utah (UCPA), Texas (TDPSA), Oregon (OCPA), Montana (MCDPA), and other states with comprehensive privacy laws may have additional rights, including the right to access, correct, delete, and obtain a copy of personal data, and the right to opt out of targeted advertising, profiling, and the sale of personal data. We honor all applicable state privacy rights.
7.4 Exercising Your Rights
To exercise any of the rights described above, you may: (a) submit a request through the privacy settings within the Application; (b) email us at support@cxbolt.com; or (c) call us at our toll-free number provided on our website. We will verify your identity before processing any request and will respond within the timeframes required by applicable law (generally thirty (30) to forty-five (45) days, with extensions as permitted).
7.5 Marketing Communications
You may opt out of marketing communications at any time by: (a) clicking the “unsubscribe” link in any marketing email; (b) adjusting your notification preferences within the Application settings; or (c) contacting us at support@cxbolt.com. Please note that opting out of marketing communications does not affect transactional or service-related communications, which are necessary for the operation of your account.
7.6 Text Message (SMS) Communications
If you provide your mobile telephone number and opt in, we may send you transactional text messages, such as payment receipts and confirmations, on our behalf and on behalf of the merchants with whom you transact. You will receive a text message only when you request a receipt at the time of a transaction; we operate no subscription and send no recurring or marketing text messages. Message and data rates may apply. You may cancel the text-message service at any time by replying STOP to any message, after which we will send a one-time confirmation and stop sending texts; reply HELP for assistance or contact us at support@cxbolt.com. Consent to receive text messages is not a condition of any purchase. See our Terms of Use for the full SMS program terms.
8. International Data Transfers
Your personal information may be transferred to, stored in, and processed in the United States or other countries where the Company or its service providers maintain facilities. These countries may have data protection laws that differ from those in your country of residence. When we transfer personal data from the EEA, UK, or Switzerland, we implement appropriate safeguards, including: Standard Contractual Clauses (SCCs) approved by the European Commission; the UK International Data Transfer Addendum; adequacy decisions where available; and supplementary technical and organizational measures as appropriate. By using the Services, you consent to the transfer of your information to the United States and other jurisdictions as described herein.
9. Children’s Privacy
The Application and Services are not directed to individuals under the age of eighteen (18) and are intended solely for use by adults who are authorized to enter into binding agreements. We do not knowingly collect, use, or disclose personal information from children under eighteen (18). If we become aware that we have collected personal information from a child under eighteen (18), we will take prompt steps to delete such information. If you believe that we have inadvertently collected information from a child, please contact us immediately at support@cxbolt.com.
This Policy complies with the Children’s Online Privacy Protection Act (COPPA), the California Age-Appropriate Design Code Act (CAADCA) where applicable, and all other applicable laws regarding the protection of children’s personal information.
10. Third-Party Links and Services
The Application may contain links to third-party websites, applications, or services that are not operated or controlled by the Company. This Policy does not apply to the practices of third parties. We are not responsible for the privacy practices of any third-party websites, applications, or services linked from or integrated with the Application. We encourage you to review the privacy policies of any third-party services you access through the Application.
11. App Store-Specific Privacy Disclosures
11.1 Apple App Store Privacy Nutrition Labels
In accordance with Apple’s App Privacy requirements, we disclose the following categories of data collected by the Application: contact information (name, email, phone number); financial information (tokenized payment references, truncated card identifiers, bank account information for settlement — note: full credit card numbers and Sensitive Cardholder Data are never collected, transmitted to, or stored by Cobalt Payments; such data is tokenized and encrypted by Third-Party Payment Processors before reaching our environment); identifiers (user ID, device ID); usage data (product interaction, advertising data); and diagnostics (crash data, performance data). Data linked to your identity includes contact information, tokenized financial references, and identifiers. Data used to track you across apps and websites owned by other companies includes identifiers and usage data, but only with your consent.
11.2 Google Play Data Safety Section
In accordance with Google Play’s Data Safety requirements, we disclose: the Application collects personal information including name, email, phone number, tokenized payment references, truncated card identifiers, bank account information for settlement, device IDs, and app usage data. Full credit card numbers, PANs, CVV/CVC codes, and other Sensitive Cardholder Data are never transmitted to, processed by, or stored on Cobalt Payments’ servers — such data is tokenized and encrypted exclusively by Third-Party Payment Processors at the point of capture. Data within our environment is encrypted in transit using TLS 1.2 or higher and at rest using AES-256. Data is collected for account management, payment facilitation, fraud prevention, analytics, and app functionality. Data is shared with payment processors, acquiring banks, card networks, and service providers as described in Section 4. Users can request data deletion by contacting support@cxbolt.com or through the in-app privacy settings.
12. Do Not Track Signals
The Application does not currently respond to “Do Not Track” (DNT) signals from web browsers. However, we honor opt-out preferences communicated through the Application’s privacy settings and through applicable state-specific opt-out mechanisms, including the Global Privacy Control (GPC) signal recognized under the CCPA/CPRA.
13. Biometric Information
If you choose to use biometric authentication features (such as fingerprint or facial recognition) to access the Application, we process biometric data solely for the purpose of verifying your identity. Biometric templates are stored locally on your device and are processed through the operating system’s native biometric framework (Apple Face ID/Touch ID or Android BiometricPrompt). We do not store, transmit, or have access to your raw biometric data. You may disable biometric authentication at any time through the Application settings or your device settings.
For residents of Illinois, Texas, Washington, and other states with biometric information privacy laws, we provide this notice: we collect biometric identifiers solely for authentication purposes; biometric data is not sold, leased, or traded; biometric templates are permanently destroyed when deleted from the device or when the account is terminated; and you may contact us for additional information regarding our biometric data practices.
14. Automated Decision-Making and Profiling
We may use automated decision-making processes, including machine learning algorithms, for the following purposes: fraud detection and prevention (analyzing transaction patterns, device fingerprints, and behavioral data to identify and block potentially fraudulent transactions); risk assessment (evaluating merchant applications based on business profile, credit history, and industry risk factors); and transaction monitoring (automated screening of transactions for compliance with AML regulations and sanctions lists).
Where automated decision-making produces legal effects or similarly significantly affects you, you have the right to: (a) obtain meaningful information about the logic involved; (b) request human review of the decision; and (c) contest the decision. To exercise these rights, contact us at support@cxbolt.com.
15. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or business operations. If we make material changes, we will notify you by: (a) posting the revised Policy within the Application with an updated effective date; (b) sending a push notification through the Application; (c) sending an email to the address associated with your account; and/or (d) displaying a prominent notice within the Application upon your next login. We encourage you to review this Policy periodically. Your continued use of the Application after the effective date of any changes constitutes acceptance of the revised Policy.
16. Data Protection Officer
The Company has designated a Data Protection Officer (DPO) who is responsible for overseeing our data protection strategy and ensuring compliance with applicable data protection laws. You may contact our DPO at:
Data Protection Officer
Cobalt Payments Inc.
Email: support@cxbolt.com
17. Contact Information
If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us at:
Cobalt Payments Inc.
Attn: Privacy Department
Email: support@cxbolt.com
Website: www.cobaltpayments.com
For California residents, you may also contact the California Attorney General at oag.ca.gov for information about your rights under the CCPA.
For EEA residents, you have the right to lodge a complaint with your local data protection authority. A list of EEA supervisory authorities is available at edpb.europa.eu.
© 2026 Cobalt Payments Inc.. All rights reserved.