Sub-Processor List
Cobalt Payments Inc. — gateway.cxbolt.com
Effective Date: July 31, 2026 Last Updated: July 31, 2026
This list is referenced by the Data Processing Addendum ("DPA") Section 7 and identifies the third parties Cobalt engages to process Merchant Personal Information. Merchants may subscribe to change notifications by emailing privacy@cxbolt.com with the subject line "Sub-Processor Notifications."
1. Confirmed Payment-Chain Participants
These are not Sub-Processors — they are independent controllers in the payment transaction chain, disclosed here for transparency per Privacy Policy Section 6 and DPA Section 7.4.
| Entity | Role | Location |
|---|---|---|
| Wells Fargo Bank, N.A. | Sponsor / member bank (Cobalt is a registered ISO) | Concord, CA, USA |
| NMI (Network Merchants LLC) | Payment gateway provider | USA |
| Card networks — Visa, Mastercard, American Express, Discover | Authorization, clearing, settlement, dispute processing | USA / global |
| Debit and ACH networks, including NACHA participants | Transaction routing and settlement | USA |
| Issuing banks | Cardholder relationship, authorization decisions | Varies |
| Fiserv, Inc. (First Data) | Acquirer / processor — merchant acquiring, settlement, and tax reporting | USA |
2. Sub-Processors
| # | Category | Vendor | Purpose | Data processed | Location |
|---|---|---|---|---|---|
| 1 | Cloud hosting & infrastructure | DigitalOcean | Application and database hosting | All Portal data | USA |
| 2 | Content delivery network / edge security | Cloudflare | Asset delivery, DNS, WAF, DDoS mitigation | IP address, request metadata | USA / global edge |
| 3 | Object / file storage | DigitalOcean Spaces | Product images, logos, signature images, attachments | Images, files, signature evidence | USA |
| 4 | Transactional email | Mailgun (Sinch) | Receipts, invoices, statements, estimates, reminders, digests, eGift delivery | Recipient name, email address, document content | USA |
| 5 | SMS / A2P messaging | Twilio | Reminders, alerts, one-time passcodes | Mobile number, message content | USA |
| 6 | Error & performance monitoring | Sentry | Diagnostics, error tracking, uptime | IP, device, session and error metadata | USA |
| 7 | Product analytics | Google Analytics 4 | Feature usage and aggregate performance | Usage events, pseudonymous identifiers, IP | USA |
| 8 | Business identity verification (KYB) | Middesk | Merchant onboarding, CIP, beneficial-ownership verification | Business identity, principal identity, TIN/EIN | USA |
| 9 | Sanctions & watch-list screening | ComplyAdvantage | OFAC/SDN, PEP, and adverse-media screening | Name, address, date of birth, entity details | USA / UK |
| 10 | Credit bureau — primary | Equifax | Underwriting — business credit and principal/guarantor personal credit | Business credit data, principal PII, SSN, credit file | USA |
| 11 | Credit bureau — secondary | Dun & Bradstreet | Trade-credit reference data | Business credit and trade data | USA |
| 12 | Terminal / device management | PAX Technology — PAXSTORE | Send-to-Device terminal fleet management (A800 / A35) | Terminal ID, device telemetry, transaction amount | USA |
| 13 | Tax reporting | Fiserv (via its service provider) | IRS Form 1099-K and related information reporting | TIN, legal name, gross processing volume | USA |
Support platform. Support tickets are handled natively within the Portal; no third-party support vendor processes Merchant Personal Information. Gift cards. Gift-card issuance and the balance ledger are native to the Portal; no third-party stored-value platform is engaged. Fraud scoring. Risk and anomaly analytics are performed natively within the Portal and by the gateway and processor in the payment chain; no separate third-party fraud-scoring vendor is engaged.
Notes on specific vendors.
- Equifax / Dun & Bradstreet. Because underwriting includes a personal credit pull on principals and guarantors, Cobalt must ensure it has a permissible purpose under the Fair Credit Reporting Act and obtains the principal’s written authorization at boarding. Adverse-action notice obligations may apply if an application is declined based in whole or in part on a consumer report.
- Google Analytics 4. Configure IP anonymization, disable Google Signals and advertising features, and set data retention to the minimum needed. GA4 must not be loaded on authenticated Portal pages that display cardholder or account data, and must never receive personal or transaction identifiers.
- Cloudflare. Acts as a reverse proxy and therefore terminates TLS; confirm the deployment is within Cobalt’s PCI DSS scope documentation.
- Twilio / Mailgun. Message content is supplied by the merchant. Merchant remains the sender for TCPA, CAN-SPAM, and A2P 10DLC purposes (Terms §12).
- Middesk / ComplyAdvantage. Used for Cobalt’s own regulatory compliance; in that capacity Cobalt acts as a controller, not the merchant’s processor (DPA §2.3).
3. Front-End Content Delivery Networks
The Portal currently loads certain front-end libraries from public CDNs. Those providers may receive the requesting IP address and basic request metadata as a technical necessity of serving the asset. They do not receive Merchant Personal Information.
| Library | Purpose |
|---|---|
| Tailwind CSS (runtime) | Styling |
| jQuery | DOM scripting |
| ApexCharts | Charting |
| Google Fonts | Typography |
4. Onward Transfers
All Sub-Processors process data in the United States. Cobalt does not currently authorize processing of Merchant Personal Information outside the United States. Any change will be reflected here per DPA Section 7.3.
5. Contact
Questions or objections: privacy@cxbolt.com.
© 2026 Cobalt Payments Inc. All rights reserved. Cobalt Payments Inc. is a registered ISO of Wells Fargo Bank, N.A., Concord, CA. The Clover trademark logo is owned by Clover Network, Inc., a First Data company. All other trademarks, service marks and trade names referenced in this material are the property of their respective owners.