Privacy Policy

Last updated 25 June 2026

Introduction

Onbold Commerce Ltd. (“Onbold”, “us”, “we”, or “our”) operates onbold.ai, a merchant business analysis tool that allows prospective clients to assess their business’s readiness for merchant account applications before formally applying. Onbold’s services are fully described on our website (the “Site”) at https://onbold.com.

With your consent, Onbold sends your data to our partner company CardCorp Ltd. (“CardCorp”), an independent payment services company that offers its clients products and services relating to e-invoicing and electronic payment transactions, including merchant account services. CardCorp’s services are fully described on their website at https://cardcorp.com. Once your data is passed to CardCorp, CardCorp processes it as an independent data controller under its own privacy policy. Onbold is not responsible for CardCorp’s processing of your data after that point.

This Privacy Policy informs you of: (1) our policies regarding the collection; (2) our use and disclosure of Personal Data when you use our Service; and (3) your rights as a visitor or user regarding that data.

We use your data to deliver and enhance the Service, to advise you of changes to the Service, to prevent illegal or potentially prohibited conduct, and to enforce our Terms and Conditions. By using the Service, you agree to the collection and use of information in accordance with this policy.

Before you access or use the Service, we will ask for your consent to process your personal data and we encourage you to read this entire Privacy Policy. A short summary is below:

  • The data controller of your personal data is Onbold Commerce Ltd., 86A, Leli Falzon Street, Naxxar, NXR2609, Malta.

  • We collect information related to your use of the Service.

  • The information we collect is used to provide the Service.

  • You have the right to request deletion of your Personal Data at any time.

  • If you have any questions about how we collect, store and use your personal information, or if you would like a copy of the information we hold about you, please contact our privacy team at privacy@onbold.com.

Definitions

Client.

Means a prospective merchant that uses the Service.

Client Data.

Means personal data, business information, names, phone numbers, email addresses, addresses and documents in electronic form that a Client provides to or that Onbold collects in connection with the Service.

Cookies.

Means small files stored on your device (computer or mobile device).

Data Controller.

Means the natural or legal person who determines the purposes for which and the manner in which any personal information is processed. For the purposes of this Privacy Policy, we are the Data Controller of your Personal Data.

Data Processor.

Means any natural or legal person who processes data on behalf of the Data Controller. We may use the services of various Service Providers in order to process your data more effectively.

Data Subject.

Means a living individual who is using our Service and is the subject of Personal Data.

Merchant Account.

Means a card payment acceptance account offered to a Client by CardCorp, following a successful merchant account application through CardCorp.

Personal Data.

Means data about a living individual who can be identified from those data (or from other information either in our possession or likely to come into our possession).

Public Area.

Means the area of the Site that can be accessed by both Clients and Visitors without needing to log in.

Service.

Means the services described and/or offered on the Site https://onbold.com by Onbold.

Start Onboarding.

Means the optional, client-selectable function of the Service where a Client consents to Onbold sending their merchant readiness analysis and details to CardCorp, so that CardCorp may offer the merchant a merchant account application service.

Usage Data.

Data collected automatically, either generated by use of the Service or from the Service infrastructure itself (for example, the duration of a page visit).

Visitor.

Means an individual who accesses the Public Area of the Site but does not submit a website for analysis or otherwise engage with the Service as a Client.

Who We Are and Our Role

Onbold Commerce Ltd. is registered in Malta. We are the Data Controller for the Personal Data we collect directly in connection with operating our platform and providing our services.

We operate Onbold.ai, a merchant business analysis tool that allows prospective clients to assess their readiness for the merchant account application process before they apply. Our role is limited to collecting lead data, conducting a pre-underwriting analysis of a merchant’s business, and, with the merchant’s consent, passing that analysis to CardCorp.

Information Collection and Use

We collect several different types of information for various purposes to provide and improve our Service to you. The legal basis for Onbold’s processing of personal data is primarily that the processing is necessary for providing the Service and that the processing is carried out in Onbold’s legitimate interests, as further explained in the “How We Use Your Data” section below. We may also process data with your consent, as appropriate.

What Information is Collected?

User Provided Personal Data

When you use our Service, you will provide, and we will collect certain personally identifiable information (“Personal Data”). The specific data collected depends on the stage of your engagement with us, as set out below.

We may use your Personal Data to contact you with information that may be of interest to you, including marketing or promotional materials. You may opt out of receiving any or all of these communications by following the unsubscribe link in our emails or contacting us directly.

Onbold.ai Merchant Business Analysis Data

We operate onbold.ai, a merchant business analysis tool that allows prospective Clients to assess their readiness for merchant account applications before formally applying. When you use onbold.ai, we collect:

  • Cookies and Usage Data (IP address, geo-location, device unique identifiers) relating to how you reached the Site and your ongoing usage of the service;

  • The website URL of the business submitted for analysis;

  • The phone number listed on the submitted website, recorded as part of the automated analysis;

  • Other publicly available information about the submitted website, gathered automatically as part of the analysis, including company name, country, registered address information, and other business information, policies and credibility indicators (see “Personal Data of Other Individuals Found on Submitted Websites” below);

  • A star rating and review count relating to the submitted business, sourced from a search for the business’s public Trustpilot listing;

  • Where you choose to answer onboarding questions about your business, your responses to those questions, whether selected from a fixed list of options or entered as free text, together with a log of the conversation and any structured information our system derives from your free-text answers (for example, recognising that an answer describing a prior account closure relates to a past account termination);

  • A screenshot of the submitted website’s homepage, captured automatically as part of the analysis (see “Website Screenshots” below);

  • After the AI chat session described below, your full name and email address, which you can enter directly into onbold.ai.

This data is used to assess merchant readiness for onboarding, identify potential underwriting concerns, and contact you regarding the analysis results and any future onboarding process. This data is processed using Cloudflare Workers and stored using Cloudflare D1 databases and R2 storage, as described in the Data Transfer and Storage of Personal Data and Our Service Providers sections below. Cached data gathered about a submitted website (for example, the raw pages fetched during analysis) is generally retained for no more than 24 hours before being discarded, separately from the underlying lead record described in the Retention of Data section below.

After we assess your business as ready for onboarding, you can elect to start onboarding, and we will send your merchant readiness data to CardCorp. CardCorp will use this data to determine whether to initiate a merchant account onboarding process with your business. CardCorp’s processing of your data from that point is governed by CardCorp’s own privacy policy.

Personal Data of Other Individuals Found on Submitted Websites

When we analyse a submitted website, the automated crawl may incidentally capture Personal Data relating to individuals other than the person who submitted the website for analysis. This can include, for example, names, email addresses or phone numbers shown on a business’s “About,” “Contact,” “Team” or legal pages, the name of a registered agent or company officer found through a company registry lookup, or information contained in the snippet of a public Trustpilot review (which may include a reviewer’s name or comments).

We process this data on the basis of our legitimate interest in assessing the credibility, legitimacy and risk profile of a business applying for merchant services. We do not use this data for marketing, and we do not seek to build profiles of these individuals beyond the specific business-verification context in which their data appears. Because this data is not collected directly from the individuals concerned, it falls within the scope of Article 14 of the GDPR; we provide the transparency information required by this Privacy Policy and, where individually informing each such individual would involve disproportionate effort relative to the limited, business-verification purpose of the processing, we rely on the exemption available under Article 14(5)(b) GDPR, while still honouring access, objection and erasure requests from any individual who contacts us at privacy@onbold.com.

Where this data is sent to our AI service providers for analysis (see “How onbold.ai Uses Artificial Intelligence” below), it may be transferred outside the EEA or UK; we rely on Standard Contractual Clauses and the other safeguards described in the Data Transfer and Storage of Personal Data section to protect it.

How Onbold.ai Uses Artificial Intelligence

Onbold.ai aims to analyse a Client’s business based on its website and other publicly available data, to provide the merchant with feedback on how to improve their business presentation and to provide initial pre-underwriting information to send to CardCorp.

Onbold.ai primarily uses deterministic, rules-based code, not artificial intelligence. When a merchant submits their website, Onbold.ai gathers evidence through web crawling, pattern-matching and lookups: fetching pages, detecting payment methods, grading legal pages, identifying regulated categories, recognising the e-commerce platform, classifying the type of any registered address found, and finding company registry information. Where a website cannot be reached directly (for example, because it blocks automated visitors), our system may route the request through Bright Data’s Web Unlocker proxy service or fall back on information available through a search engine to complete the analysis. Onbold.ai also searches for the business’s Trustpilot page, then a small AI model reads the star rating and review count from the search result snippet.

A Client may then choose to answer further onboarding questions about their business, either by selecting from a fixed list of options (which does not involve AI) or by typing a free-text answer, which a small AI model reads in order to map it to the relevant structured field and provide a short conversational acknowledgement. This chat flow is designed to confirm the business model, follow up on reasons for any prior account termination, and clarify the merchant’s product offering, and is not designed to request Personal Data; however, because Clients type free-text answers, we cannot guarantee that a merchant will not voluntarily include Personal Data (their own, or a third party’s) in a free-text response, and any such data is handled in accordance with this Privacy Policy. After this process, the merchant Client may enter their full name and email address into Onbold.ai.

When assessing a merchant, Onbold.ai uses artificial intelligence selectively for business assessment, data extraction, and writing. We use models provided by Anthropic, as follows:

  • Claude Sonnet is used to assess whether the submitted website is consistent with a real, coherent business, and to identify risk signals in the business model, such as undisclosed recurring billing, undeclared dropshipping, or exaggerated claims;

  • Claude Haiku is used to extract clean facts from raw page content (such as company name, country, products sold, and probable merchant category code) and search results, to convert this information into plain text for merchants and reviewers, to draft recommended next steps, and to interpret free-text answers given during the onboarding conversation described above.

Under our current commercial terms with Anthropic, including the signed Anthropic DPA, data we submit through the API is retained for a short operational period and not used to train Anthropic’s models. Further detail on Anthropic’s data handling and retention practices is available at https://www.anthropic.com/legal/privacy and https://privacy.claude.com.

Human Decision-Making

Onbold.ai does not use artificial intelligence to make final decisions about a Client’s business or risk assessment. Deterministic code reviews the output produced by our AI models, corrects factual errors, and applies a transparent, fixed rules engine with no AI to compute the Onboarding Score and Vertical Risk shown to our underwriting team. Artificial intelligence may raise flags for human or automated review, but the resulting score is produced by an auditable formula, and every result is shown together with the specific facts that drove it. A human underwriter always reviews the data, flags and computed scores before any decision is made to offer to send the Client data to CardCorp, so that no decision producing legal or similarly significant effects on a merchant is made by automated means alone within the meaning of Article 22 of the GDPR. If you believe a decision affecting you was made without appropriate human review, please contact privacy@onbold.com.

Website Screenshots

As part of our analysis, we may capture a screenshot of the homepage of the website you submit. This screenshot is stored in Cloudflare R2 and may inadvertently display Personal Data that appears on the page at the time it was captured (for example, names, photographs, or contact details shown on the homepage). Screenshots are visible only to Onbold’s authenticated underwriting staff and are not shared with CardCorp or any other third party except as otherwise described in this Privacy Policy. We currently limit the number of screenshots captured each calendar month.

Automatically Collected Information

Usage Data

We may collect information on how the Service is accessed and used (“Usage Data”). This may include your computer’s IP address, geolocation, browser type and version, device unique identifiers, the pages of our Service you visit, the time, date and duration of your visit, and other diagnostic data.

Location Data

We may use and store information about your location if you give us permission. We use this data to enable and enhance features of our Service. You can enable or disable location services at any time through your device settings.

Tracking Cookies Data

We use cookies and similar tracking technologies to track activity on our Service. Cookies are small files of data that may include an anonymous unique identifier. Other tracking technologies, such as beacons, tags and scripts, are also used to collect and track information and to improve and analyse our Service. Non-essential cookies (including advertising cookies) are only placed with your prior consent, which you can manage through our cookie consent tool on the Site.

Examples of cookies we use:

  • Session Cookies – to operate our Service;

  • Preference Cookies – to remember your preferences and settings;

  • Security Cookies – for security purposes;

  • Advertising Cookies – to serve advertisements relevant to your interests (only with your consent).

How We Use Your Data

We use the data we collect for the following purposes:

  • To provide, maintain and improve our Service;

  • To analyse submitted merchant websites and produce readiness assessments;

  • To deliver correspondence and notify you about changes to our Service;

  • To allow you to participate in interactive features of our Service;

  • To provide assistance and customer support;

  • To create aggregated statistical data to improve our Service;

  • To monitor usage of our Service;

  • To detect, prevent and address technical issues;

  • To enhance fraud prevention and security capabilities;

  • To administer merchant readiness analysis;

  • To provide you with news, special offers and general information about our Service and other goods, services and events which we offer that are similar to those you have already purchased or enquired about, unless you have opted out.

The legal bases and purposes for processing are set out in the table below:

Purpose Legal Basis
To analyse a submitted merchant website and produce a readiness assessment Legitimate interest (Onbold’s and CardCorp’s interest in assessing merchant suitability and preventing fraud)
To conduct the readiness assessment conversation and collect merchant responses Legitimate interest at the merchant’s request
To contact the merchant regarding their analysis results and the onboarding process Legitimate interest
To send merchant readiness data to CardCorp to initiate a merchant account application process Consent (the merchant elects to Start Onboarding)
To communicate with merchants and market our services Contract performance or prior consent
To manage our IT systems, conduct security monitoring and maintain platform integrity Legal obligation or legitimate interest
To detect and prevent fraud, abuse and misuse of the platform Legitimate interest
To manage legal claims and comply with court orders, regulatory requests or law enforcement requirements Legal obligation, legitimate interest or legal claims
To improve our platform, products and services Legitimate interest or prior consent
To improve Onbold’s assessment engine using data submitted to the Service Legitimate interest (using only anonymised and aggregated data)

Where we process Sensitive Personal Data (such as information about an individual’s role as a company officer or information relevant to compliance checks), we do so only where required by law, necessary for legal claims, or with your explicit consent.

Our Legal Basis for Processing Personal Data under the GDPR

If you are located in the European Economic Area (EEA), the collection and storage of your Personal Data falls within the scope of the General Data Protection Regulation (“GDPR”). Onbold may process your Personal Data because:

  • You have given us permission to do so;

  • The processing is in our legitimate interests and is not overridden by your rights;

  • To comply with a legal obligation.

If you are a resident of the United Kingdom, your data is also subject to the UK GDPR. You may make a complaint to the Information Commissioner's Office (ICO) at www.ico.org.uk.

Your Data Protection Rights under the GDPR

If you are a resident of the European Economic Area (EEA) or UK, you have certain data protection rights. Onbold aims to take commercially reasonable steps to allow you to correct, amend, delete or limit the use of your Personal Data. If you wish to be informed about what Personal Data we hold about you, or if you want to be removed from our systems, please contact our privacy team at privacy@onbold.com.

In certain circumstances, you have the following rights:

  • The right to request access to your Personal Data;

  • The right to request correction or deletion of your Personal Data;

  • The right to object to the use and processing of your Personal Data;

  • The right to request that we restrict the use and processing of your Personal Data;

  • The right to request portability of your Personal Data;

  • The right to withdraw your consent to the use and processing of your Personal Data;

  • The right to make a complaint to a government supervisory authority.

Please email privacy@onbold.com with any requests, questions or concerns. We may ask you to verify your identity before responding. For more information about your rights under the GDPR, or to make a complaint, you may contact the Information and Data Protection Commissioner (IDPC), the Maltese data protection supervisory authority, at https://idpc.org.mt.

Data Transfer and Storage of Personal Data

Onbold.ai Analysis Platform – Cloudflare Infrastructure

Our Onbold.ai merchant business analysis platform operates on infrastructure provided by Cloudflare, Inc. Personal Data submitted to or generated by this platform, including the website URL submitted for analysis, contact details you enter into Onbold.ai, and the findings produced by the analysis, is processed using Cloudflare Workers and stored using Cloudflare D1 databases and R2 storage.

Cloudflare operates a global network, and data processed through Onbold.ai may therefore be processed or transiently routed through Cloudflare’s infrastructure in various locations, some of which may be outside the EEA or the UK. Where this involves a transfer of Personal Data outside the EEA or UK to a jurisdiction not deemed to provide an adequate level of protection, we rely on appropriate safeguards, including Standard Contractual Clauses, to protect that data. Further information about Cloudflare’s data processing practices is available in Cloudflare’s own privacy policy at https://www.cloudflare.com/privacypolicy/.

If a submitted website blocks or otherwise impedes our standard automated crawl, our system may route that request through Bright Data Ltd.’s Web Unlocker proxy service to complete the fetch. Any Personal Data captured from the website (see “Personal Data of Other Individuals Found on Submitted Websites” above) may therefore pass through Bright Data’s infrastructure, which operates a global network and may be located outside the EEA or UK; we rely on Standard Contractual Clauses or other appropriate safeguards for any such transfer. Further information about Bright Data’s data processing practices is available in Bright Data’s privacy policy at https://brightdata.com/legal/privacy.

Accessing Your Results

When your analysis is complete, we provide you with a unique link to view your results and continue onboarding. Anyone who has this link can view the information associated with it, including your name, email address, phone number and business analysis, without needing to log in separately. Because the link itself functions as the credential for access, you should treat it with the same care as a password and avoid forwarding or sharing it with anyone you do not want to have access to this information. The link and any associated session cookies expire after 90 days.

Disclosure and Sharing of Personal Data

Onbold does not sell, license or rent your Personal Data to third parties. However, we may share your Personal Data with third parties for the following stated reasons and conditions:

To Satisfy Legal Requirements

Where we are doing so in the good faith belief that such action is necessary to:

  • Comply with a legal obligation, legal action or court order;

  • Protect or defend the rights or property of Onbold, our users or anyone else;

  • Prevent or investigate possible wrongdoing in connection with the Service;

  • Protect the personal safety of users of the Service or the public;

  • Protect against legal liability.

With CardCorp

With your consent, and only when you elect to Start Onboarding, Onbold shares your merchant readiness data with CardCorp for the purpose of initiating a merchant account application. As your merchant assessment session may be closed after you start onboarding, you can withdraw your consent to share your merchant readiness data with CardCorp by emailing us at privacy@onbold.com. Withdrawing consent does not affect the lawfulness of processing carried out before the withdrawal.

Once received by CardCorp, your data is processed by CardCorp as an independent data controller under CardCorp’s own privacy policy. You should review CardCorp’s privacy policy for information about how they handle your data.

With our Affiliates

We may share your Personal Data with our affiliates, meaning entities that directly or indirectly control, are controlled by, or are under common control with Onbold.

With our Service Providers

We may disclose information to organisations that provide services to us, on the understanding that they will keep the information private, confidential and compliant with the GDPR. These may include:

  • Technical providers who support our services;

  • Third-party software and SaaS providers hosting data on our behalf;

  • Professional advisors such as solicitors, accountants, tax advisors, auditors and insurance brokers;

  • Our advertising, promotional agencies and marketing consultants;

  • Providers assisting with data storage, organisation and security;

  • Regulators and public authorities.

In a Change of Ownership Event

We may transfer your Personal Data to potential purchasers and their advisors, subject to appropriate confidentiality obligations, if we decide to dispose of all or part of our business. Information about Clients and Visitors, including Client Data and Usage Data, may be disclosed and otherwise transferred to any acquirer, successor or assignee as part of any merger, acquisition, debt financing, sale of assets or similar transaction, provided that the recipient commits to a Privacy Policy with terms substantially consistent with this Privacy Policy.

Data Controller

Onbold Commerce Ltd. is the Data Controller for Personal Data collected directly from Clients and Visitors in connection with the Service. We determine the purposes and means of processing that data and are responsible for ensuring it is handled in accordance with applicable data protection law, including the GDPR.

Security of Data

We use industry-standard technologies to safeguard your information from unauthorised use and disclosure and to prevent possible security breaches of the Service. Our information security programme is based on defence-in-depth principles and spans people, processes, systems and third-party providers. Specific measures include:

  • Access controls based on the principle of least privilege;

  • Strong authentication for access to critical systems;

  • Encryption of sensitive data in transit and at rest;

  • Continuous security monitoring and vulnerability management;

  • Incident response procedures;

  • Regular security reviews and audits;

  • Contractual security obligations imposed on all third-party Service Providers.

Retention of Data

Onbold will retain your Personal Data only for as long as is necessary for the purposes set forth in this Privacy Policy. We will retain and use your Personal Data to the extent necessary to comply with our legal obligations (for example, if we are required to retain your data to comply with applicable laws), resolve disputes and enforce our legal agreements and policies.

Onbold will also retain Usage Data for internal analysis purposes. Usage Data is generally retained for a shorter period, except when it is used to strengthen the security or improve the functionality of our Service, or when we are legally obligated to retain it for longer periods.

We retain lead records for as long as is necessary for the purposes set out in this Privacy Policy. An automated process runs nightly that anonymises submitted assessments after 24 months — removing your contact details and redacting the free-text answers you gave, while retaining non-identifying structured findings for audit and dispute purposes — and that deletes the lead record associated with a verified erasure request within 30 days. Data cached about a submitted website during analysis (such as raw fetched pages) is generally discarded within 24 hours, separately from this nightly process.

Where data is no longer required, it is securely deleted, destroyed or anonymised.

Our Service Providers

We may employ third-party companies and individuals to facilitate our Service (“Service Providers”, sometimes called sub-processors), to provide the Service on our behalf, or to assist us in analysing how our Service is used. These third parties have access to your Personal Data only to perform these tasks on our behalf and are obligated not to disclose or use it for any other purpose. We maintain an up-to-date list of our sub-processors and will make it available on request to privacy@onbold.com. Our current sub-processors for the onbold.ai platform are described below.

Infrastructure and Hosting Providers

Our onbold.ai analysis platform is hosted on infrastructure provided by Cloudflare, Inc., including Cloudflare Workers (application processing), Cloudflare D1 (database storage), Cloudflare R2 (screenshot storage), Cloudflare Queue (background processing), and Cloudflare Access (administrator authentication). Cloudflare processes Personal Data on our behalf as a Service Provider, subject to contractual data processing obligations. Cloudflare’s privacy policy is available at https://www.cloudflare.com/privacypolicy/.

Search Providers

To analyse a submitted website and to locate public information about it (including its Trustpilot listing), we use the Brave Search API as our primary search provider, with DuckDuckGo’s public search results used as a fallback where needed. These providers may process the website URL submitted for analysis and the search snippets returned, which may include publicly available information about the submitted business. Brave Search is operated by Brave Software, Inc. Further information about Brave’s data practices is available at https://brave.com/privacy/browser. DuckDuckGo is operated by Duck Duck Go, Inc.; further information is available at https://duckduckgo.com/privacy.

Website Access — Proxy Provider (Bright Data)

Where a submitted website actively blocks or impedes our standard automated crawl (for example, because it uses bot-protection technology that prevents our servers from fetching it directly), our system escalates the request to Bright Data Ltd.’s Web Unlocker proxy service to complete the fetch. Bright Data is an Israeli company headquartered at HaCharash 12, HaKrayot Industrial Zone, Bnei Brak, Israel, operating a global proxy network with infrastructure in multiple jurisdictions.

The data Bright Data processes in this context is limited to: the URL of the submitted website and the raw page content returned from it. This raw content may incidentally include Personal Data of individuals displayed on the website (such as names, contact details or photographs), as described in “Personal Data of Other Individuals Found on Submitted Websites” above. Bright Data does not receive any Personal Data you enter into onbold.ai (such as your name or email address).

Bright Data processes this data on our behalf as a Data Processor, subject to a Data Processing Agreement incorporating Standard Contractual Clauses for transfers of Personal Data outside the EEA and UK. Because Bright Data’s infrastructure operates globally, Personal Data may be routed through servers located outside the EEA or UK during the proxy fetch; we rely on those Standard Contractual Clauses as the transfer mechanism for any such onward transfer. Bright Data’s privacy policy is available at https://brightdata.com/legal/privacy.

Customer Relationship Management

When a merchant’s analysis is approved and the merchant consents to send it to CardCorp, the merchant’s details are also recorded at Attio Ltd., our customer relationship management (CRM) provider, which we use to track and manage the merchant relationship internally. Attio processes this data on our behalf as a Service Provider, subject to contractual data processing obligations.

Administrator Authentication

Access to our internal underwriting dashboard for Onbold staff is authenticated via Google sign-in, managed through Cloudflare Access. This relates to the authentication of our own staff and does not involve Google accessing merchant Personal Data beyond what is necessary to operate this access control layer.

Artificial Intelligence Providers

As described in the “How Onbold.ai Uses Artificial Intelligence” section above, Onbold.ai uses AI models provided by Anthropic, PBC to analyse merchant websites and other publicly available business information. Anthropic processes data submitted to these models on our behalf as a Service Provider, subject to contractual data processing obligations. Anthropic’s privacy policy is available at https://www.anthropic.com/legal/privacy.

Data Analytics

We may use third-party Service Providers, including Google Analytics, to monitor and analyse the use of our Service. Please review Google’s Privacy Policy at https://policies.google.com/privacy.

Advertising and Remarketing

We may use third-party Service Providers to show you advertisements to help support and maintain our Service, including Google Ads and Google Ads Remarketing. You can opt out of Google interest-based advertising through Google’s opt-out tools. Please review Google’s Privacy Policy for further information.

Children and Privacy

Our Service is not directed towards anyone under the age of 18 (“Children”). Onbold is committed to protecting the privacy of Children and to complying with all applicable laws and regulations, including Article 8 of the GDPR. We do not knowingly collect, store, maintain or share personally identifiable information from Children under the age of 18. If you are a parent or guardian and believe your Child has provided us with Personal Data, please contact us. If we become aware that we have collected Personal Data from Children without appropriate consent, we will take steps to remove that information from our servers.

Links to Other Sites

Our Service may contain links to other sites that are not operated by us. If you click a third-party link, you will be directed to that third party’s site. We strongly advise you to review the Privacy Policy of every site you visit. We have no control over, and assume no responsibility for, the content, privacy policies, or practices of any third-party sites or services.

US Privacy Clauses

You may have the right to opt out of the sale/sharing of your personal data. We honour this right - we do not sell your personal data or share your personal data with third parties for cross-context behavioral advertising.

We do not track our users over time and across third-party websites so our services do not alter their behavior in response to browser Do Not Track (DNT) signals or Global Privacy Control (GPC) headers.

Residents of some states may request a list of the categories of personal data we have disclosed to third parties for their direct marketing purposes. We do not disclose personal data to third parties for their direct marketing purposes.

Depending on your US state of residence, you may have the right to access, correct, or delete your personal data. To exercise these rights, please contact us at privacy@onbold.com. We will respond to your request within 45 days. If we decline your request, you may appeal by contacting privacy@onbold.com within 30 days, and we will respond within 30 days.

Notification of Changes to This Privacy Policy

Onbold may at any time, and at our sole discretion, add, modify or remove any feature, function or portion of the Service, the Terms, and/or this Privacy Policy, in whole or in part. Any changes to the Privacy Policy will be effective as of the posting date at the top of this Privacy Policy. Onbold will provide prominent notice on the Site of any major changes. Your continued use of the Service after Onbold posts any modifications shall constitute your acceptance of those modifications. Where a change affects processing for which we rely on your consent, we will seek your renewed consent before the change takes effect.

Contact Us

If you have any questions about this Privacy Policy, please contact our privacy team.

End of Privacy Policy

© 2026 Onbold

We use cookies to run this site and, with your consent, to improve it. See our Cookie Policy and Privacy Policy .