Sub-Processor List

Cobalt Payments Inc. — gateway.cxbolt.com

Effective Date: July 31, 2026 Last Updated: July 31, 2026

This list is referenced by the Data Processing Addendum ("DPA") Section 7 and identifies the third parties Cobalt engages to process Merchant Personal Information. Merchants may subscribe to change notifications by emailing privacy@cxbolt.com with the subject line "Sub-Processor Notifications."


1. Confirmed Payment-Chain Participants

These are not Sub-Processors — they are independent controllers in the payment transaction chain, disclosed here for transparency per Privacy Policy Section 6 and DPA Section 7.4.

Entity Role Location
Wells Fargo Bank, N.A. Sponsor / member bank (Cobalt is a registered ISO) Concord, CA, USA
NMI (Network Merchants LLC) Payment gateway provider USA
Card networks — Visa, Mastercard, American Express, Discover Authorization, clearing, settlement, dispute processing USA / global
Debit and ACH networks, including NACHA participants Transaction routing and settlement USA
Issuing banks Cardholder relationship, authorization decisions Varies
Fiserv, Inc. (First Data) Acquirer / processor — merchant acquiring, settlement, and tax reporting USA

2. Sub-Processors

# Category Vendor Purpose Data processed Location
1 Cloud hosting & infrastructure DigitalOcean Application and database hosting All Portal data USA
2 Content delivery network / edge security Cloudflare Asset delivery, DNS, WAF, DDoS mitigation IP address, request metadata USA / global edge
3 Object / file storage DigitalOcean Spaces Product images, logos, signature images, attachments Images, files, signature evidence USA
4 Transactional email Mailgun (Sinch) Receipts, invoices, statements, estimates, reminders, digests, eGift delivery Recipient name, email address, document content USA
5 SMS / A2P messaging Twilio Reminders, alerts, one-time passcodes Mobile number, message content USA
6 Error & performance monitoring Sentry Diagnostics, error tracking, uptime IP, device, session and error metadata USA
7 Product analytics Google Analytics 4 Feature usage and aggregate performance Usage events, pseudonymous identifiers, IP USA
8 Business identity verification (KYB) Middesk Merchant onboarding, CIP, beneficial-ownership verification Business identity, principal identity, TIN/EIN USA
9 Sanctions & watch-list screening ComplyAdvantage OFAC/SDN, PEP, and adverse-media screening Name, address, date of birth, entity details USA / UK
10 Credit bureau — primary Equifax Underwriting — business credit and principal/guarantor personal credit Business credit data, principal PII, SSN, credit file USA
11 Credit bureau — secondary Dun & Bradstreet Trade-credit reference data Business credit and trade data USA
12 Terminal / device management PAX Technology — PAXSTORE Send-to-Device terminal fleet management (A800 / A35) Terminal ID, device telemetry, transaction amount USA
13 Tax reporting Fiserv (via its service provider) IRS Form 1099-K and related information reporting TIN, legal name, gross processing volume USA

Support platform. Support tickets are handled natively within the Portal; no third-party support vendor processes Merchant Personal Information. Gift cards. Gift-card issuance and the balance ledger are native to the Portal; no third-party stored-value platform is engaged. Fraud scoring. Risk and anomaly analytics are performed natively within the Portal and by the gateway and processor in the payment chain; no separate third-party fraud-scoring vendor is engaged.

Notes on specific vendors.

  • Equifax / Dun & Bradstreet. Because underwriting includes a personal credit pull on principals and guarantors, Cobalt must ensure it has a permissible purpose under the Fair Credit Reporting Act and obtains the principal’s written authorization at boarding. Adverse-action notice obligations may apply if an application is declined based in whole or in part on a consumer report.
  • Google Analytics 4. Configure IP anonymization, disable Google Signals and advertising features, and set data retention to the minimum needed. GA4 must not be loaded on authenticated Portal pages that display cardholder or account data, and must never receive personal or transaction identifiers.
  • Cloudflare. Acts as a reverse proxy and therefore terminates TLS; confirm the deployment is within Cobalt’s PCI DSS scope documentation.
  • Twilio / Mailgun. Message content is supplied by the merchant. Merchant remains the sender for TCPA, CAN-SPAM, and A2P 10DLC purposes (Terms §12).
  • Middesk / ComplyAdvantage. Used for Cobalt’s own regulatory compliance; in that capacity Cobalt acts as a controller, not the merchant’s processor (DPA §2.3).

3. Front-End Content Delivery Networks

The Portal currently loads certain front-end libraries from public CDNs. Those providers may receive the requesting IP address and basic request metadata as a technical necessity of serving the asset. They do not receive Merchant Personal Information.

Library Purpose
Tailwind CSS (runtime) Styling
jQuery DOM scripting
ApexCharts Charting
Google Fonts Typography

4. Onward Transfers

All Sub-Processors process data in the United States. Cobalt does not currently authorize processing of Merchant Personal Information outside the United States. Any change will be reflected here per DPA Section 7.3.

5. Contact

Questions or objections: privacy@cxbolt.com.


© 2026 Cobalt Payments Inc. All rights reserved. Cobalt Payments Inc. is a registered ISO of Wells Fargo Bank, N.A., Concord, CA. The Clover trademark logo is owned by Clover Network, Inc., a First Data company. All other trademarks, service marks and trade names referenced in this material are the property of their respective owners.

© 2026 Cobalt Payments Inc. All rights reserved. Registered ISO of Wells Fargo Bank, N.A., Concord, CA.

← Back to gateway.cxbolt.com