CXbolt Payment Gateway

Privacy Policy

Effective Date: June 1, 2026  |  Last Updated: July 31, 2026

1. Introduction and Scope

Cobalt Payments Inc. (“Company,” “Cobalt Payments,” “we,” “us,” or “our”) is committed to protecting your privacy and safeguarding the personal information entrusted to us. This Privacy Policy (“Policy”) describes how we collect, use, disclose, store, protect, and otherwise process personal information in connection with the Cxbolt Payment Gateway mobile application (the “Application”), our website at www.cobaltpayments.com, and the payment processing services provided thereunder (collectively, the “Services”).

This Policy applies to all individuals who access, download, install, or use the Application, including merchants, business owners, employees, authorized agents, and end-user customers whose payment data may be processed through the Application (collectively, “you” or “your”). This Policy applies regardless of whether you access the Application through the Apple App Store, Google Play Store, or any other distribution platform.

By downloading, installing, accessing, or using the Application, you acknowledge that you have read, understood, and agree to the collection, use, and disclosure of your information as described in this Policy. If you do not agree with the practices described herein, please do not download, install, access, or use the Application.

2. Information We Collect

2.1 Information You Provide Directly

We collect information that you voluntarily provide to us when you register for an account, apply for merchant services, use the Services, or otherwise communicate with us. This includes:

2.2 Transaction and Payment Data

IMPORTANT DISCLOSURE REGARDING SENSITIVE CARDHOLDER DATA: Raw credit card numbers, full primary account numbers (PANs), card verification values (CVV/CVC/CVV2), magnetic stripe data, EMV chip data, PIN blocks, and other sensitive cardholder authentication data (collectively, “Sensitive Cardholder Data”) are never transmitted to, processed by, stored on, or accessible within any network, server, database, system, or infrastructure owned, operated, or controlled by Cobalt Payments.

All Sensitive Cardholder Data is captured, tokenized, and encrypted exclusively by PCI DSS-certified third-party payment processors, acquiring banks, PCI-validated point-to-point encryption (P2PE) solution providers, and card network-approved service providers (collectively, “Third-Party Payment Processors”) at the point of capture — before any data element enters the Company’s environment. The collection, processing, encryption, storage, and protection of Sensitive Cardholder Data is governed entirely by the privacy policies, terms of service, and security certifications of the applicable Third-Party Payment Processors, not by this Privacy Policy.

The Company receives and processes only the following non-sensitive, non-reversible transaction data elements:

None of the data elements listed above constitute Sensitive Cardholder Data, and none can be used individually or in combination to reconstruct full payment card account information.

2.3 Information Collected Automatically

When you access or use the Application, we automatically collect certain technical and usage information, including:

2.4 Information from Third Parties

We may receive information about you from third-party sources, which we may combine with the information we collect directly. These sources include: acquiring banks and payment processors (transaction status, settlement data); card networks (BIN data, network rules compliance); credit bureaus and identity verification providers (creditworthiness, identity confirmation); fraud prevention services (device reputation, risk scoring); government databases (sanctions screening, business registration verification); and App Stores (purchase records, subscription status).

2.5 Cookies and Similar Technologies

Our web-based services and the Application may use cookies, web beacons, pixel tags, SDKs, and similar tracking technologies to collect information about your interactions with our Services. These technologies help us remember your preferences, analyze usage patterns, deliver relevant content, and prevent fraud. You can manage cookie preferences through your device or browser settings; however, disabling certain cookies may limit functionality.

3. How We Use Your Information

We use the personal information we collect for the following purposes:

Purpose Categories of Data Legal Basis (GDPR)
Account registration and verification Registration, identity, business info Contract performance; Legal obligation
Payment transaction processing Transaction data, payment card data, financial info Contract performance; Legal obligation
Fraud prevention and risk management Device info, transaction patterns, location, identity data Legitimate interest; Legal obligation
Regulatory compliance (AML/KYC/BSA) Identity, business, beneficial ownership, financial info Legal obligation
Customer support and communications Communications, account info, usage data Contract performance; Legitimate interest
Service improvement and analytics Usage data, device info, performance data Legitimate interest
Marketing and promotional communications Contact info, usage patterns, preferences Consent; Legitimate interest
Legal proceedings and dispute resolution All relevant categories Legitimate interest; Legal obligation

4. How We Share Your Information

We do not sell your personal information. We may share your information with the following categories of recipients and for the following purposes:

4.1 Service Providers and Payment Partners

We share information with trusted third-party service providers who assist us in operating the Services, including: acquiring banks and payment processors (for transaction processing and settlement); card networks such as Visa, Mastercard, American Express, and Discover (for authorization and compliance); identity verification and fraud prevention providers; cloud hosting and infrastructure providers; analytics and performance monitoring services; customer support platforms; and email and communication service providers. All service providers are contractually obligated to use your information only for the purposes for which it was disclosed and to maintain appropriate security measures.

4.2 Legal and Regulatory Disclosures

We may disclose your information when required by law or when we believe in good faith that disclosure is necessary to: (a) comply with a legal obligation, subpoena, court order, or governmental request; (b) protect and defend the rights, property, or safety of the Company, our users, or the public; (c) prevent fraud, money laundering, or other illegal activities; (d) enforce our Terms of Use and Terms of Service; or (e) comply with Card Network Rules, PCI DSS requirements, or the rules of regulatory authorities, including FinCEN, OFAC, and state financial regulators.

4.3 Business Transfers

In the event of a merger, acquisition, reorganization, bankruptcy, dissolution, or other corporate transaction involving the Company, your personal information may be transferred to the successor entity. We will provide notice of any such transfer and any choices you may have regarding your information.

4.4 With Your Consent

We may share your information for any purpose disclosed to you at the time of collection or with your express consent.

4.5 Aggregated and De-Identified Data

We may share aggregated, anonymized, or de-identified data that cannot reasonably be used to identify you with third parties for research, analytics, industry benchmarking, and business purposes. Such data is not considered personal information under this Policy.

4.6 Mobile Information and SMS/Text Messaging Data

No mobile information — including your mobile telephone number and your consent to receive text messages — will be sold, rented, or shared with any third parties or affiliates for their own marketing or promotional purposes. Text messaging originator opt-in data and consent are excluded from all of the information-sharing categories described in this Section 4; such data will not be shared with any third party for marketing purposes under any circumstance.

We use a trusted messaging provider (our SMS delivery vendor) solely to transmit the transactional text messages you have consented to receive — for example, payment receipts and confirmations — on our behalf and on behalf of the merchants with whom you transact. That provider is contractually restricted to using your information only to deliver those messages and may not use it for its own purposes. For details about the text-messaging program, message frequency, applicable rates, and how to opt out, see our Terms of Use.

5. Data Retention

We retain your personal information for as long as necessary to fulfill the purposes for which it was collected, including to satisfy our legal, regulatory, accounting, and reporting obligations. Specific retention periods include:

When personal information is no longer required, we will securely delete or anonymize it in accordance with our data retention and disposal policies and applicable law.

6. Data Security

6.1 Sensitive Cardholder Data — Third-Party Security

As disclosed in Section 2.2, Sensitive Cardholder Data (including full credit card numbers, PANs, CVV/CVC codes, magnetic stripe data, EMV chip data, and PIN blocks) does not pass through, reside on, or touch any system owned or operated by Cobalt Payments. The tokenization, encryption, secure transmission, and storage of all Sensitive Cardholder Data is performed exclusively by PCI DSS-certified Third-Party Payment Processors. The security of Sensitive Cardholder Data within the environments of those Third-Party Payment Processors is governed by their own security programs, PCI DSS certifications, card network compliance obligations, and applicable regulatory requirements — not by this Privacy Policy. We encourage you to review the privacy and security policies of the Third-Party Payment Processors whose services are utilized through the Application.

6.2 Cobalt Payments’ Security Program

For the non-sensitive data elements within the Company’s environment (tokens, truncated references, transaction metadata, account information, and other data described in Section 2), we implement comprehensive administrative, technical, and physical security measures, including but not limited to:

While we employ commercially reasonable measures to protect the information within our environment, no method of transmission over the internet or electronic storage is completely secure. We cannot guarantee absolute security. The Company is not responsible for breaches, unauthorized access, or unauthorized disclosure of Sensitive Cardholder Data that occurs within the systems, networks, or infrastructure of any Third-Party Payment Processor, as such data never enters the Company’s environment.

7. Your Rights and Choices

7.1 Rights Under the California Consumer Privacy Act (CCPA/CPRA)

If you are a California resident, you have the following rights under the CCPA as amended by the CPRA:

7.2 Rights Under the General Data Protection Regulation (GDPR)

If you are located in the European Economic Area (EEA), United Kingdom, or Switzerland, you have the following rights under the GDPR:

7.3 Additional State Privacy Rights

Residents of Virginia (VCDPA), Colorado (CPA), Connecticut (CTDPA), Utah (UCPA), Texas (TDPSA), Oregon (OCPA), Montana (MCDPA), and other states with comprehensive privacy laws may have additional rights, including the right to access, correct, delete, and obtain a copy of personal data, and the right to opt out of targeted advertising, profiling, and the sale of personal data. We honor all applicable state privacy rights.

7.4 Exercising Your Rights

To exercise any of the rights described above, you may: (a) submit a request through the privacy settings within the Application; (b) email us at support@cxbolt.com; or (c) call us at our toll-free number provided on our website. We will verify your identity before processing any request and will respond within the timeframes required by applicable law (generally thirty (30) to forty-five (45) days, with extensions as permitted).

7.5 Marketing Communications

You may opt out of marketing communications at any time by: (a) clicking the “unsubscribe” link in any marketing email; (b) adjusting your notification preferences within the Application settings; or (c) contacting us at support@cxbolt.com. Please note that opting out of marketing communications does not affect transactional or service-related communications, which are necessary for the operation of your account.

7.6 Text Message (SMS) Communications

If you provide your mobile telephone number and opt in, we may send you transactional text messages, such as payment receipts and confirmations, on our behalf and on behalf of the merchants with whom you transact. You will receive a text message only when you request a receipt at the time of a transaction; we operate no subscription and send no recurring or marketing text messages. Message and data rates may apply. You may cancel the text-message service at any time by replying STOP to any message, after which we will send a one-time confirmation and stop sending texts; reply HELP for assistance or contact us at support@cxbolt.com. Consent to receive text messages is not a condition of any purchase. See our Terms of Use for the full SMS program terms.

8. International Data Transfers

Your personal information may be transferred to, stored in, and processed in the United States or other countries where the Company or its service providers maintain facilities. These countries may have data protection laws that differ from those in your country of residence. When we transfer personal data from the EEA, UK, or Switzerland, we implement appropriate safeguards, including: Standard Contractual Clauses (SCCs) approved by the European Commission; the UK International Data Transfer Addendum; adequacy decisions where available; and supplementary technical and organizational measures as appropriate. By using the Services, you consent to the transfer of your information to the United States and other jurisdictions as described herein.

9. Children’s Privacy

The Application and Services are not directed to individuals under the age of eighteen (18) and are intended solely for use by adults who are authorized to enter into binding agreements. We do not knowingly collect, use, or disclose personal information from children under eighteen (18). If we become aware that we have collected personal information from a child under eighteen (18), we will take prompt steps to delete such information. If you believe that we have inadvertently collected information from a child, please contact us immediately at support@cxbolt.com.

This Policy complies with the Children’s Online Privacy Protection Act (COPPA), the California Age-Appropriate Design Code Act (CAADCA) where applicable, and all other applicable laws regarding the protection of children’s personal information.

10. Third-Party Links and Services

The Application may contain links to third-party websites, applications, or services that are not operated or controlled by the Company. This Policy does not apply to the practices of third parties. We are not responsible for the privacy practices of any third-party websites, applications, or services linked from or integrated with the Application. We encourage you to review the privacy policies of any third-party services you access through the Application.

11. App Store-Specific Privacy Disclosures

11.1 Apple App Store Privacy Nutrition Labels

In accordance with Apple’s App Privacy requirements, we disclose the following categories of data collected by the Application: contact information (name, email, phone number); financial information (tokenized payment references, truncated card identifiers, bank account information for settlement — note: full credit card numbers and Sensitive Cardholder Data are never collected, transmitted to, or stored by Cobalt Payments; such data is tokenized and encrypted by Third-Party Payment Processors before reaching our environment); identifiers (user ID, device ID); usage data (product interaction, advertising data); and diagnostics (crash data, performance data). Data linked to your identity includes contact information, tokenized financial references, and identifiers. Data used to track you across apps and websites owned by other companies includes identifiers and usage data, but only with your consent.

11.2 Google Play Data Safety Section

In accordance with Google Play’s Data Safety requirements, we disclose: the Application collects personal information including name, email, phone number, tokenized payment references, truncated card identifiers, bank account information for settlement, device IDs, and app usage data. Full credit card numbers, PANs, CVV/CVC codes, and other Sensitive Cardholder Data are never transmitted to, processed by, or stored on Cobalt Payments’ servers — such data is tokenized and encrypted exclusively by Third-Party Payment Processors at the point of capture. Data within our environment is encrypted in transit using TLS 1.2 or higher and at rest using AES-256. Data is collected for account management, payment facilitation, fraud prevention, analytics, and app functionality. Data is shared with payment processors, acquiring banks, card networks, and service providers as described in Section 4. Users can request data deletion by contacting support@cxbolt.com or through the in-app privacy settings.

12. Do Not Track Signals

The Application does not currently respond to “Do Not Track” (DNT) signals from web browsers. However, we honor opt-out preferences communicated through the Application’s privacy settings and through applicable state-specific opt-out mechanisms, including the Global Privacy Control (GPC) signal recognized under the CCPA/CPRA.

13. Biometric Information

If you choose to use biometric authentication features (such as fingerprint or facial recognition) to access the Application, we process biometric data solely for the purpose of verifying your identity. Biometric templates are stored locally on your device and are processed through the operating system’s native biometric framework (Apple Face ID/Touch ID or Android BiometricPrompt). We do not store, transmit, or have access to your raw biometric data. You may disable biometric authentication at any time through the Application settings or your device settings.

For residents of Illinois, Texas, Washington, and other states with biometric information privacy laws, we provide this notice: we collect biometric identifiers solely for authentication purposes; biometric data is not sold, leased, or traded; biometric templates are permanently destroyed when deleted from the device or when the account is terminated; and you may contact us for additional information regarding our biometric data practices.

14. Automated Decision-Making and Profiling

We may use automated decision-making processes, including machine learning algorithms, for the following purposes: fraud detection and prevention (analyzing transaction patterns, device fingerprints, and behavioral data to identify and block potentially fraudulent transactions); risk assessment (evaluating merchant applications based on business profile, credit history, and industry risk factors); and transaction monitoring (automated screening of transactions for compliance with AML regulations and sanctions lists).

Where automated decision-making produces legal effects or similarly significantly affects you, you have the right to: (a) obtain meaningful information about the logic involved; (b) request human review of the decision; and (c) contest the decision. To exercise these rights, contact us at support@cxbolt.com.

15. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or business operations. If we make material changes, we will notify you by: (a) posting the revised Policy within the Application with an updated effective date; (b) sending a push notification through the Application; (c) sending an email to the address associated with your account; and/or (d) displaying a prominent notice within the Application upon your next login. We encourage you to review this Policy periodically. Your continued use of the Application after the effective date of any changes constitutes acceptance of the revised Policy.

16. Data Protection Officer

The Company has designated a Data Protection Officer (DPO) who is responsible for overseeing our data protection strategy and ensuring compliance with applicable data protection laws. You may contact our DPO at:

Data Protection Officer
Cobalt Payments Inc.
Email: support@cxbolt.com

17. Contact Information

If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us at:

Cobalt Payments Inc.
Attn: Privacy Department
Email: support@cxbolt.com
Website: www.cobaltpayments.com

For California residents, you may also contact the California Attorney General at oag.ca.gov for information about your rights under the CCPA.

For EEA residents, you have the right to lodge a complaint with your local data protection authority. A list of EEA supervisory authorities is available at edpb.europa.eu.


© 2026 Cobalt Payments Inc.. All rights reserved.