Cobaltpay
Legal

Privacy Policy

Last updated June 26, 2026

1. Overview

This Privacy Policy explains how Cobaltpay, Inc. ("Cobaltpay", "we", "us") collects, uses and protects personal data when you visit our website, use our dashboard, or integrate our payment facilitation Services. It also describes your rights and how to exercise them.

For most processing relating to our merchants, Cobaltpay acts as a data controller. When we process cardholder and end-customer data on behalf of a merchant to deliver the Services, we generally act as a processor under the merchant's instructions.

2. Data we collect

We collect the following categories of personal data:

  • Account & onboarding data — names, business details, beneficial-owner information, government identifiers and documents collected for KYC/KYB.
  • Transaction data — payment tokens, amounts, currencies, settlement details and limited cardholder data needed to process and reconcile payments.
  • Technical data — IP address, device and browser information, and logs collected for security, fraud prevention and debugging.
  • Usage & communications — dashboard activity, support requests and correspondence with our team.

3. How we use data

We use personal data to:

  • Provide, operate and improve the Services, including settlement and reporting.
  • Onboard merchants and meet legal KYC, AML and sanctions obligations.
  • Detect, prevent and investigate fraud, abuse and security incidents.
  • Communicate about your account, service changes and support.
  • Comply with legal, regulatory and card-network requirements.

4. Legal bases (GDPR)

Where the EU/UK General Data Protection Regulation applies, we rely on the following legal bases for processing:

  • Performance of a contract — to provide the Services you have requested.
  • Legal obligation — to satisfy AML, tax, accounting and regulatory duties.
  • Legitimate interests — to secure our platform, prevent fraud and improve the Services, balanced against your rights.
  • Consent — for certain cookies and optional communications, which you may withdraw at any time.

5. Sharing & processors

We share personal data only as necessary to deliver the Services and meet our obligations. We do not sell personal data. Recipients may include:

  • Acquiring banks, card networks and banking partners that settle funds.
  • Identity-verification, fraud-scoring and sanctions-screening providers.
  • Cloud hosting, infrastructure and analytics processors acting under contract.
  • Authorities, regulators or advisors where required by law or to protect our rights.

6. International transfers

We may transfer personal data to countries outside your own, including the United States. Where we do, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses, the UK International Data Transfer Agreement, or an applicable adequacy decision, together with supplementary measures where needed.

7. Data retention

We retain personal data only for as long as necessary for the purposes described in this policy. Onboarding and transaction records are typically kept for the duration of the relationship plus the periods required by financial-services and AML regulations (often five to seven years), after which they are deleted or anonymized.

8. Your rights

Subject to applicable law, you may have the right to:

  • Access, correct or delete your personal data.
  • Restrict or object to certain processing, including direct marketing.
  • Receive your data in a portable format and withdraw consent.
  • Lodge a complaint with your local data-protection authority.

To exercise these rights, contact [email protected]. We may need to verify your identity before acting on a request.

9. Security

We maintain technical and organizational measures designed to protect personal data, including encryption in transit and at rest, tokenization of card data, access controls and continuous monitoring. We maintain PCI DSS compliance for the cardholder data environment. No system is perfectly secure, but we work to reduce risk and to respond promptly to incidents.

10. Cookies

We use cookies and similar technologies on our website. For details on the categories we use and how to manage your preferences, see our Cookie Policy.

11. Contact / DPO

For privacy questions or to reach our Data Protection Officer, email [email protected] or write to Cobaltpay, Inc., Attn: Data Protection Officer. We will respond within the timeframes required by applicable law.

ZYNOREX LLCLimited Liability Company (Wyoming, United States).

Registered office: 312 W 2nd St Unit 3931, Casper, WY 82601, USA

Registered agent: Registered Agents Inc, 30 N Gould St Ste R, Sheridan, WY 82801, USA

Questions? Contact [email protected]