Privacy Policy
Cobalt Payments Inc. — gateway.cxbolt.com Merchant Portal
Effective Date: July 31, 2026 Last Updated: July 31, 2026
Table of Contents
- Who We Are and What This Policy Covers
- Our Two Roles: Controller vs. Service Provider
- Information We Collect
- How We Use Information
- How We Disclose Information
- The Payment Transaction Chain
- Automated Processing, Analytics, and AI Features
- Aggregated and De-Identified Data
- We Do Not Sell Personal Information
- GLBA and the Financial-Institution Exemption
- Your Privacy Rights by State
- Data Retention
- Data Security
- Cardholder Data and PCI DSS
- Electronic Communications
- Cookies and Tracking
- Children's Privacy
- Third-Party Sites and Integrations
- Geographic Scope
- Changes to This Policy
- Contact Us
1. Who We Are and What This Policy Covers
Cobalt Payments Inc. ("Cobalt," "we," "us," or "our") is a Connecticut corporation with its principal place of business at 2264 Silas Deane Hwy, Suite 105, Rocky Hill, CT 06067. Cobalt is a registered Independent Sales Organization (ISO) of Wells Fargo Bank, N.A., Concord, California, and provides payment gateway and merchant-management technology.
This Privacy Policy describes how Cobalt collects, uses, discloses, and safeguards information in connection with:
- the gateway.cxbolt.com Merchant Portal (the "Portal"), including its Virtual Terminal, Point of Sale / Register, Products & Inventory, Gift Cards, Transactions, Disputes, Invoicing, Recurring Billing, Installments, Pay Links, Estimates, Statements, Accounts Receivable, Customers, Tasks, Alerts & Notifications, Reporting, and Settings modules;
- hosted payment pages, pay links, estimate acceptance pages, and electronic receipts we serve on behalf of merchants; and
- our websites, support channels, and related services (collectively with the Portal, the "Services").
This Policy does not cover the independent privacy practices of the merchants who use our Services. Each merchant is a separate business that determines its own privacy practices, and we are not responsible for the privacy practices of our merchants. If you are a consumer who transacted with a business that uses Cobalt, please review that business's privacy policy, and contact that business directly regarding your data.
Assumption flagged for review: This Policy assumes Cobalt does not itself take possession of merchant settlement funds in its gateway-only capacity, and that in its ISO capacity funds settle from the sponsor bank/acquirer to the merchant. Confirm before publication.
2. Our Two Roles: Controller vs. Service Provider
Our obligations differ depending on whose information is involved. This distinction is central to this Policy.
| Category of individual | Our role | Who is accountable |
|---|---|---|
| Merchant personnel — owners, officers, authorized users, team members who log into the Portal | Controller / Business. We determine how this data is used. | Cobalt |
| Merchant applicants — during underwriting, onboarding, and risk review | Controller / Business (jointly with the sponsor bank and acquirer) | Cobalt, sponsor bank, acquirer |
| Website visitors and prospects | Controller / Business | Cobalt |
| Consumers and cardholders — the merchant's own customers, whose data flows through the Portal (customer records, transactions, cards on file, gift cards, invoices, estimates) | Service Provider / Processor. We process this data only on the merchant's instructions and only to deliver the Services, plus as legally required. | The merchant is the Controller / Business. |
Merchant obligation. Each merchant is solely responsible for (a) maintaining its own privacy policy that accurately discloses how personal and financial information is collected and used, (b) providing all notices and obtaining all consents required to permit Cobalt to process consumer data as contemplated, and (c) responding to consumer rights requests concerning data the merchant controls. See the Data Processing Addendum.
3. Information We Collect
3.1 Information merchants and their personnel provide to us
- Identity and contact: legal and DBA name, entity type, EIN/TIN, contact name, email, telephone, mobile number, business and mailing address.
- Underwriting and risk: beneficial-ownership and control-person information, government-issued identification, date of birth, Social Security Number (for principals, where required by our sponsor bank and applicable Know-Your-Customer / Customer Identification Program rules), processing history, projected volumes, average ticket, chargeback history, bank account and routing numbers, financial statements, and website or storefront details.
- Account and credentials: username, password (stored only as a salted hash), multi-factor authentication settings and phone number, roles and permissions, and activity logs.
- Support and communications: support tickets, attachments, correspondence, and — where disclosed and permitted by law — call recordings.
- Configuration: branding assets, receipt and reminder templates, tax and surcharge settings, notification preferences and recipients, product catalogs, and pricing.
3.2 Consumer and cardholder information we process on merchants' behalf
Provided by the merchant or captured through the merchant's use of the Services:
- Customer records: name, business/company, email, telephone, billing and shipping address, state, tags, payment terms, preferred contact method, and merchant-entered internal notes.
- Payment credentials: primary account number, expiration date, cardholder name, and verification values as transmitted for authorization; tokenized card-on-file references; bank account and routing numbers for ACH.
- Transaction data: amount, currency, date and time, authorization and response codes, approval or decline status, last four digits and card brand, AVS and CVV results, refunds, voids, chargebacks and representments, ACH returns and return codes, settlement and batch data, tips, taxes, discounts, and surcharges.
- Point-of-sale data: items purchased, quantities, SKUs, barcodes, categories, cart and line-level discounts, tender split, cash tendered and change, parked sales, returns, and terminal identifiers.
- Gift card data: card number (or its tokenized reference), balance and activity ledger, purchaser and recipient name and email, issuing jurisdiction, and status.
- Invoicing, estimates, and A/R data: documents and line items, due dates, aging, deposits, and payment history.
- Electronic signature evidence: the drawn signature image, typed signer name, IP address, timestamp, and a document hash captured when a customer accepts an estimate.
- Age-restriction indicators the merchant configures for regulated products.
We do not want, and instruct merchants not to submit, special-category data — including health, biometric, genetic, precise geolocation, or government-ID images of consumers — except where expressly required by a feature.
3.3 Information collected automatically
IP address, device and browser type, operating system, language, referring and exit pages, pages and features viewed, session duration, timestamps, click and scroll interactions, error and diagnostic logs, and approximate location derived from IP address. Where our technology is embedded in a merchant's website or hosted page, we may collect this information from consumers on that page.
3.4 Information from third parties
Sponsor bank, acquirer, and processor; the card networks and debit networks; credit bureaus and identity-verification, sanctions-screening, and fraud-prevention vendors; the MATCH / Terminated Merchant File; referral partners and independent sales agents; and publicly available sources.
4. How We Use Information
We use information to:
- Provide the Services — authenticate users, process and route transactions, present reporting, generate invoices, estimates, statements, receipts, and gift cards, and deliver notifications and reminders.
- Underwrite, onboard, and monitor merchants, including KYC/CIP, beneficial-ownership verification, sanctions and watch-list screening, and ongoing risk review.
- Detect, prevent, and investigate fraud, chargeback abuse, gift-card fraud, and money laundering, and to secure our systems.
- Comply with law — including the Bank Secrecy Act and anti-money-laundering rules, the Gramm-Leach-Bliley Act, tax reporting (including Form 1099-K where applicable), card-network rules, subpoenas, and court orders.
- Provide support and respond to tickets and inquiries.
- Bill and collect fees, and exercise set-off and collection rights.
- Improve and develop the Services, including analytics, testing, and troubleshooting.
- Communicate service, security, legal, and — subject to your preferences and applicable law — marketing messages.
- Enforce our agreements and protect our legal rights, property, and safety, and those of our merchants and the public.
Consumer data is used only to deliver the Services to the merchant, plus for the fraud-prevention, security, and legal-compliance purposes above. We do not use consumer data for our own independent marketing.
5. How We Disclose Information
We disclose information to:
- Our sponsor bank, acquirer, and processor — including Wells Fargo Bank, N.A. (sponsor/member bank) and Fiserv, Inc. (First Data) (acquirer/processor) — for sponsorship, underwriting, settlement, risk, tax reporting, and compliance.
- Our gateway provider, NMI (Network Merchants LLC), which supplies underlying gateway functionality.
- Card networks, debit networks, and issuers — Visa, Mastercard, American Express, Discover, and their members — in the ordinary course of authorization, clearing, settlement, and dispute processing.
- Service providers and sub-processors under written contract limiting them to our instructions — cloud hosting and storage, content delivery, email and SMS delivery, analytics, error monitoring, and identity-verification, sanctions-screening, credit-bureau, and terminal-management vendors. See the Sub-Processor List.
- Merchants — we return consumer data to the merchant that controls it.
- Referral partners and independent sales agents — limited account and volume information for commission and servicing.
- Professional advisors — auditors, accountants, PCI assessors, and counsel.
- Government, regulators, and law enforcement — as required by law, subpoena, warrant, or court order, or to report suspected fraud or unlawful activity, including reporting terminated merchants to the MATCH / Terminated Merchant File.
- Acquirers of our business — in a merger, acquisition, financing, reorganization, or sale of assets, subject to this Policy.
- With your direction or consent for any other purpose.
We do not sell personal information, and we do not share personal information for cross-context behavioral advertising.
6. The Payment Transaction Chain
Payment processing inherently requires disclosure among the participants in the transaction chain. When a transaction is submitted through the Services, information is disclosed among the merchant, Cobalt, our gateway provider, our processor, the acquiring and sponsoring bank, the card and debit networks and their members, and the card issuer. Each participant handles that information under its own agreements and legal obligations. Cobalt does not control, and is not responsible for, the independent privacy practices of the networks, issuers, or banks in that chain.
7. Automated Processing, Analytics, and AI Features
The Services include automated and statistical features, including:
- Anomaly detection that compares metrics — ACH returns, failed recurring payments, refund rate, dispute rate, sales volume, and estimate decline rate — against the merchant's own trailing baseline using a multiplier threshold and a standard-score (z-score) test, and surfaces a flag when both are met;
- Gift-card fraud heuristics that flag rapid draw-down and high-value depletion patterns;
- Accounts-receivable aging, escheatment, and breakage calculations; and
- Task service-level escalation based on inactivity.
These outputs are advisory analytics presented to the merchant. They are not decisions about, and are not used by Cobalt to make any decision about, any consumer — including any decision regarding credit, insurance, employment, housing, or the provision of goods or services. They do not constitute consumer reports, and Cobalt does not act as a consumer reporting agency in producing them.
AI/ML and analytics disclaimer. Automated outputs, thresholds, projections, and computed figures may be incomplete, delayed, or inaccurate. The merchant is solely responsible for independently verifying any figure or flag before relying on it, and for any action it takes or declines to take in response. See the Terms of Use for the corresponding disclaimers.
8. Aggregated and De-Identified Data
We may create and use aggregated, statistical, and de-identified information derived from use of the Services — including anonymized benchmarks, industry and vertical trends, fraud-pattern intelligence, and product analytics — for any lawful business purpose, including improving the Services, publishing benchmarks, and developing new features. Such information does not identify any merchant, consumer, or individual, and we will not attempt to re-identify it. This right survives termination.
9. We Do Not Sell Personal Information
Cobalt does not sell personal information for money or other valuable consideration, and does not share personal information for cross-context behavioral advertising or targeted advertising, as those terms are defined under the California Consumer Privacy Act as amended by the California Privacy Rights Act ("CCPA/CPRA") and comparable state laws. We have not sold or shared personal information in the preceding twelve months. We do not knowingly sell or share the personal information of individuals under 16.
10. GLBA and the Financial-Institution Exemption
Cobalt is a financial institution for purposes of the Gramm-Leach-Bliley Act ("GLBA") and Regulation P, because it is significantly engaged in activities that are financial in nature — including payment processing and related financial services provided as a registered Independent Sales Organization. Much of the information we handle is nonpublic personal information ("NPI") collected and used in connection with providing a financial product or service.
NPI subject to GLBA is exempt from the CCPA/CPRA and from most comparable state privacy statutes. Where information falls within that exemption, our handling of it — including our disclosure and safeguarding obligations — is governed by GLBA, Regulation P, the GLBA Safeguards Rule, and applicable financial-privacy law rather than by state consumer-privacy statutes.
Where information is not GLBA-exempt — for example, information about website visitors and prospects that is unrelated to a financial product or service — we honor the state rights described in Section 11. Where the exemption’s application to particular data is uncertain, we apply the more protective standard.
Regulation P notices. Regulation P’s initial and annual privacy-notice requirements apply to individuals who obtain a financial product or service primarily for personal, family, or household purposes. Because Cobalt provides its Services to businesses for business purposes, we do not have consumer "customers" within the meaning of that rule and do not issue a Regulation P annual notice. This Privacy Policy serves as our privacy disclosure.
Safeguards Rule. We maintain a written information security program consistent with the GLBA Safeguards Rule, as described in Section 13.
Financial-transaction data typically falls outside general consumer-privacy statutes. If you are a consumer seeking information about a specific payment, please contact the merchant you transacted with, or the bank or issuer of your card or account — they hold the relationship and the records that answer those questions.
Flagged for counsel. This determination should be confirmed against Cobalt’s actual activities. GLBA defines "financial institution" broadly by reference to activities financial in nature, and payment processing is commonly treated as such — including for FTC Safeguards Rule purposes. Note the two rules can apply independently: the Safeguards Rule may bind Cobalt’s security program even where the Regulation P notice rules do not, because the notice rules turn on the presence of consumer customers while the Safeguards Rule does not.
11. Your Privacy Rights by State
Subject to the GLBA exemption in Section 10, verification, and applicable exceptions, residents of states with comprehensive privacy laws — including California, Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, Delaware, Iowa, Nebraska, New Hampshire, New Jersey, Tennessee, Minnesota, Maryland, Indiana, Kentucky, and Rhode Island — may have the rights to:
- Know / Access the categories and specific pieces of personal information we hold, the sources, our purposes, and the categories of recipients;
- Delete personal information, subject to legal, regulatory, security, fraud-prevention, and recordkeeping exceptions;
- Correct inaccurate personal information;
- Portability — receive a copy in a portable format;
- Opt out of sale, targeted advertising, and profiling in furtherance of decisions producing legal or similarly significant effects — note: we do not engage in any of these;
- Limit use of sensitive personal information — we use it only as permitted for providing the Services, security, and legal compliance;
- Non-discrimination for exercising rights; and
- Appeal a denial, where your state provides an appeal right.
How to exercise. Email privacy@cxbolt.com or write to Privacy Office, Cobalt Payments Inc., 2264 Silas Deane Hwy, Suite 105, Rocky Hill, CT 06067. We will verify your request using information already in our possession and respond within the period your state's law requires (generally 45 days, extendable once). An authorized agent may submit a request with proof of authorization.
If your data is controlled by a merchant. For customer records, transactions, gift cards, invoices, estimates, or signature evidence that a merchant submitted or generated, the merchant is the Controller. We will refer your request to that merchant and assist them in responding, as required by our Data Processing Addendum. Direct such requests to the merchant.
California "Shine the Light." We do not disclose personal information to third parties for their own direct-marketing purposes.
Connecticut residents. As a Connecticut company, we note that the Connecticut Data Privacy Act provides these rights to Connecticut residents, including an appeal right; use the contacts above.
12. Data Retention
We retain information for as long as necessary to provide the Services, comply with law and card-network rules, resolve disputes, and enforce our agreements. Our schedule mirrors prevailing payments-industry practice:
| Category | Retention |
|---|---|
| Merchant account, underwriting, and KYC records | Duration of the relationship, then at least 5 years after closure (Bank Secrecy Act / AML), and up to 7 years where tax or audit rules apply |
| Transaction and settlement records | Minimum 18 months to support retrieval, chargeback, and representment rights under card-network rules; generally 7 years for tax, audit, and legal-hold purposes |
| Dispute, chargeback, and ACH-return records | Minimum 24 months from resolution |
| Tokenized card-on-file credentials | Until the merchant or consumer deletes the token, or 90 days after account termination, whichever is first |
| Full card numbers and verification values | Not retained by Cobalt after authorization; sensitive authentication data is never stored post-authorization |
| Gift-card balances and activity ledger | Until fully redeemed or escheated, plus 7 years — unclaimed-property law generally requires long-tail records |
| Electronic signature evidence (estimates) | 7 years from execution. Available to the merchant that generated it and, on lawful request, to a party to the signed document |
| In-Portal alerts and notifications | 45 days rolling, by design |
| Support tickets and correspondence | 3 years |
| Server, access, and security logs | 12–24 months |
| Aggregated / de-identified data | Indefinitely (no longer identifies anyone) |
Backups and archives may persist for a limited additional period. Data subject to legal hold is retained until the hold is released.
13. Data Security
We maintain a written information security program with administrative, technical, and physical safeguards designed to protect information, consistent with the GLBA Safeguards Rule and applicable PCI DSS requirements. Controls include encryption of cardholder data in transit and at rest, tokenization, role-based access controls and least privilege, multi-factor authentication for administrative access, network segmentation, logging and monitoring, vulnerability management and penetration testing, secure development practices, vendor due diligence, personnel background screening and training, and a documented incident-response plan.
No method of transmission or storage is completely secure. We cannot guarantee absolute security. You are responsible for safeguarding your credentials, enabling multi-factor authentication, managing your users' roles and permissions, promptly deactivating departed personnel, and securing your own devices, networks, and systems — including any server or environment you or your designee operates.
Breach notification. If we become aware of a security incident involving personal information we process, we will notify affected merchants without undue delay and provide information reasonably necessary for them to meet their own notification obligations, and will notify individuals and regulators where law requires us to do so directly.
Urgent reporting. To report a suspected breach, vulnerability, or compromise — including compromise of your customers' data — contact security@cxbolt.com immediately.
14. Cardholder Data and PCI DSS
Card data entered through the Services is captured directly by our gateway provider, NMI, using hosted fields and tokenization, and does not transit or reside on Cobalt-controlled servers. Cobalt receives only a token and non-sensitive transaction metadata such as the card brand and last four digits. NMI and Fiserv, Inc. (First Data) each maintain their own PCI DSS validation. Because card data never enters a Cobalt-controlled environment, Cobalt's environment is not a cardholder data environment and Cobalt does not hold a separate Attestation of Compliance. Cobalt never stores full card numbers or sensitive authentication data.
Each merchant is independently responsible for its own PCI DSS compliance — including completing the correct Self-Assessment Questionnaire or Report on Compliance, maintaining a compliant environment, and securing all cardholder data residing on any system it or its designee controls, such as a web host, shopping cart, terminal, or point-of-sale device. Using the Services does not make a merchant PCI compliant. See the PCI DSS Responsibility Matrix.
Prohibited storage. Merchants must never store sensitive authentication data after authorization — full magnetic-stripe or chip track data, the CVV/CVC/CID verification value, or the PIN or PIN block. Merchants must not enter cardholder data into free-text fields such as internal notes, descriptions, or task comments.
15. Electronic Communications
The Services send email and SMS on merchants' behalf — receipts, invoices, statements, payment reminders, estimate and eGift delivery, alerts, and digests.
- Service communications. We may send you administrative, security, legal, and transactional messages related to your account; these are not marketing and you cannot opt out of them while your account is active.
- Marketing. You may opt out of marketing email at any time using the unsubscribe link or by contacting us. Message and data rates may apply to SMS.
- Merchant-originated messaging. When a merchant uses the Services to message its own customers, the merchant is the sender. The merchant is solely responsible for obtaining and maintaining all consents required by the Telephone Consumer Protection Act, honoring opt-outs and STOP requests, maintaining its suppression list, complying with CAN-SPAM, and completing A2P 10DLC registration. See the Terms of Use.
16. Cookies and Tracking
We use strictly necessary, functional, and analytics cookies and similar technologies. We do not use cookies for cross-context behavioral advertising. See the Cookie Notice for detail and controls. We honor Global Privacy Control signals where required.
17. Children's Privacy
The Services are business tools intended solely for use by adults acting for a business. They are not directed to children, and we do not knowingly collect personal information from anyone under 18 in that capacity. If we learn we have done so, we will delete it. Merchants using age-restriction features are solely responsible for lawful age verification.
18. Third-Party Sites and Integrations
The Services may link to or integrate with third-party sites, applications, terminals, and services. Those parties operate under their own privacy policies and terms, and Cobalt is not responsible for their privacy or security practices. Review their notices before providing information.
19. Geographic Scope
The Services are offered to businesses in the United States, and information is processed and stored in the United States. The Services are not offered to, and this Policy does not address, individuals in the European Economic Area, United Kingdom, or Switzerland, and we make no representation that the Services comply with the GDPR or UK GDPR. Do not use the Services to process personal data subject to those regimes without a separate written agreement with us.
20. Changes to This Policy
We may update this Policy at any time. We will post the revised Policy with a new "Last Updated" date and, for material changes, provide additional notice — such as an in-Portal notice or email — before it takes effect. Your continued use of the Services after the effective date constitutes acceptance. If you object, your remedy is to stop using the Services and terminate your account.
21. Contact Us
Cobalt Payments Inc. Privacy Office 2264 Silas Deane Hwy, Suite 105, Rocky Hill, CT 06067
| Purpose | Contact |
|---|---|
| Privacy inquiries and rights requests | privacy@cxbolt.com |
| Security incidents and vulnerabilities | security@cxbolt.com |
| Legal notices and process | legal@cxbolt.com |
| Support | support@cxbolt.com |
© 2026 Cobalt Payments Inc. All rights reserved. Cobalt Payments Inc. is a registered ISO of Wells Fargo Bank, N.A., Concord, CA. The Clover trademark logo is owned by Clover Network, Inc., a First Data company. All other trademarks, service marks and trade names referenced in this material are the property of their respective owners.