/

Case Studies

Bolt now claims ownership of your customer data

Stani Mihov

Founder & CEO

·

TL;DR

Vendor: Bolt
Document: Merchant Terms of Use
Date detected: June 11, 2026
Key change: A new clause claiming sole ownership of end-user data and customer relationships, plus a perpetual data license, a liability cap cut from 12 months to 3, and a breach-reporting window shortened from 48 hours to 24

Bolt revised its Merchant Terms of Use with four changes, all negative for merchants. They move in one direction: more control of customer data and relationships for Bolt, and less recourse for the merchant.

The change

On June 11, 2026, Venpo detected a new version of Bolt's Merchant Terms of Use. The document's last revised date moved from November 26, 2025 to June 10, 2026, and four substantive clauses changed. Bolt is the checkout and payments platform operated by Bolt Financial, Inc.

Bolt sits in the checkout and payments layer of the merchants that use it, handling end-user data, payment details, and customer relationships. A change to who owns that data, and to what a merchant can recover when something goes wrong, is exactly the kind of update that rarely reaches the people who approved the vendor in the first place.

Under Bolt's own Notice of Changes section, the revised terms took effect the moment they were posted, and continued use of the service counts as acceptance. The only on-page marker of the update was the changed revision date.

What changed

Four clauses changed, and all four were rated negative for merchants.

1. Data ownership. A new clause in the Proprietary Rights section states that, despite the merchant keeping ownership of its own data and materials, Bolt retains full, independent, and sole ownership of the data, relationships, account information, and personal information of any end user who interacts with, creates an account on, or processes transactions through Bolt's systems, platform, or network.

2. Perpetual data license. The license a merchant grants Bolt over its Merchant Data and Materials changed from a term-limited grant to a perpetual, irrevocable, worldwide, royalty-free license, and now expressly lets Bolt use aggregate data and derive insights even after the merchant ends the relationship.

3. Liability cap cut. Bolt's total liability cap dropped from the fees paid in the prior 12 months to the fees paid in the prior 3 months.

4. Breach window shortened. Merchants must now report an actual or suspected security breach within 24 hours of discovery instead of 48, and Bolt can run an immediate audit on suspicion of a breach rather than giving 30 days' advance notice.

What this shifts onto the merchant

Read together, the four changes move control and risk in one direction.

The ownership and license clauses change who controls the customer relationship. Bolt processes merchant data under its Data Processing Addendum, but the new ownership language asserts that the end-user data, accounts, and relationships created through Bolt's platform belong to Bolt, not the merchant, and that Bolt can keep using aggregated data and insights after the merchant leaves.

The liability cap change reduces what a merchant can recover. The common industry structure for a SaaS liability cap ties it to the fees paid in the preceding 12 months. Moving to 3 months lowers the ceiling on most claims to roughly a quarter of that, for the same relationship.

The breach clause adds obligation and removes a buffer. A 24-hour reporting window leaves far less time to investigate before notifying, and dropping the 30-day audit notice means a suspected incident can trigger an immediate audit.

Why this matters

A Terms of Use is one of the documents a company is least likely to re-read after signing, and a payment or checkout provider's terms can carry some of the most consequential clauses in the stack. This is the category of change covered in our analysis of the hidden risk of vendor legal changes.

Data ownership, liability caps, and breach obligations are not privacy-policy details. They decide who controls your customer relationships, how much you can recover if the vendor causes harm, and what you are contractually required to do during an incident. When those move, the assumptions a team approved at onboarding no longer hold, even though nothing in the product changed. Staying current with this kind of drift is the core argument for monitoring vendor terms of service rather than reviewing them once.

It is also part of a broader pattern in payments and checkout. The same direction is visible when Stripe shifted agent-transaction liability to users: providers are steadily reallocating risk toward the customer, one terms update at a time.

Potential impact for SaaS companies

Companies that use Bolt for checkout or payments may want to review whether:

  • their data processing records and customer-facing disclosures still match Bolt's claim of sole ownership of end-user data

  • their contracts and insurance assumptions account for a liability cap that now covers 3 months of fees instead of 12

  • their incident-response runbooks can meet a 24-hour breach-notification window to Bolt

  • their internal documentation reflects that Bolt can use aggregated data and insights after the relationship ends

For teams that resell or build on top of Bolt, a change to who owns end-user data and relationships can cascade into their own customer agreements and disclosures. Tracking that across a full vendor portfolio is where structured vendor contract monitoring becomes a control rather than a periodic task, and where continuous vendor risk monitoring earns its place in the compliance stack.

How Venpo detected it

Venpo continuously monitors vendor legal documents and detects changes in real time. When Bolt published the new Merchant Terms of Use, Venpo immediately:

  • detected the updated document the day after it was posted

  • isolated the four substantive clauses from routine formatting

  • scored each as negative for merchants and explained the impact in plain English

  • flagged the data-ownership and liability-cap changes as the most material

Instead of discovering a rewritten ownership clause during a contract renewal or a customer security review, teams understood the change within a day of it shipping. Terms of Use change too rarely to watch by hand and too materially to miss, which is the core of our comparison of manual vs automated vendor monitoring.

Business outcome

Companies that caught this change early were able to:

  • review whether Bolt's sole-ownership clause conflicts with their own customer data commitments

  • reassess legal and insurance exposure under the reduced liability cap

  • update incident-response procedures to meet the 24-hour reporting window

  • brief legal and compliance before the next renewal or customer audit

Instead of reacting to a clause discovered during due diligence, they adapted on their own schedule. This is the difference between operating with current information and operating on assumptions from the last review cycle.

Key takeaway

The most consequential vendor changes are often not in the privacy policy but in the Terms of Use, where ownership, liability, and breach obligations live. Bolt's update moved all three in its favor in a single revision, and the only on-page signal was a changed date. Venpo detected it the day after it shipped and explained what each clause means for merchants. A closer look at why scheduled reviews keep missing this kind of change is in our analysis of manual vs automated vendor monitoring.

The change

On June 11, 2026, Venpo detected a new version of Bolt's Merchant Terms of Use. The document's last revised date moved from November 26, 2025 to June 10, 2026, and four substantive clauses changed. Bolt is the checkout and payments platform operated by Bolt Financial, Inc.

Bolt sits in the checkout and payments layer of the merchants that use it, handling end-user data, payment details, and customer relationships. A change to who owns that data, and to what a merchant can recover when something goes wrong, is exactly the kind of update that rarely reaches the people who approved the vendor in the first place.

Under Bolt's own Notice of Changes section, the revised terms took effect the moment they were posted, and continued use of the service counts as acceptance. The only on-page marker of the update was the changed revision date.

What changed

Four clauses changed, and all four were rated negative for merchants.

1. Data ownership. A new clause in the Proprietary Rights section states that, despite the merchant keeping ownership of its own data and materials, Bolt retains full, independent, and sole ownership of the data, relationships, account information, and personal information of any end user who interacts with, creates an account on, or processes transactions through Bolt's systems, platform, or network.

2. Perpetual data license. The license a merchant grants Bolt over its Merchant Data and Materials changed from a term-limited grant to a perpetual, irrevocable, worldwide, royalty-free license, and now expressly lets Bolt use aggregate data and derive insights even after the merchant ends the relationship.

3. Liability cap cut. Bolt's total liability cap dropped from the fees paid in the prior 12 months to the fees paid in the prior 3 months.

4. Breach window shortened. Merchants must now report an actual or suspected security breach within 24 hours of discovery instead of 48, and Bolt can run an immediate audit on suspicion of a breach rather than giving 30 days' advance notice.

What this shifts onto the merchant

Read together, the four changes move control and risk in one direction.

The ownership and license clauses change who controls the customer relationship. Bolt processes merchant data under its Data Processing Addendum, but the new ownership language asserts that the end-user data, accounts, and relationships created through Bolt's platform belong to Bolt, not the merchant, and that Bolt can keep using aggregated data and insights after the merchant leaves.

The liability cap change reduces what a merchant can recover. The common industry structure for a SaaS liability cap ties it to the fees paid in the preceding 12 months. Moving to 3 months lowers the ceiling on most claims to roughly a quarter of that, for the same relationship.

The breach clause adds obligation and removes a buffer. A 24-hour reporting window leaves far less time to investigate before notifying, and dropping the 30-day audit notice means a suspected incident can trigger an immediate audit.

Why this matters

A Terms of Use is one of the documents a company is least likely to re-read after signing, and a payment or checkout provider's terms can carry some of the most consequential clauses in the stack. This is the category of change covered in our analysis of the hidden risk of vendor legal changes.

Data ownership, liability caps, and breach obligations are not privacy-policy details. They decide who controls your customer relationships, how much you can recover if the vendor causes harm, and what you are contractually required to do during an incident. When those move, the assumptions a team approved at onboarding no longer hold, even though nothing in the product changed. Staying current with this kind of drift is the core argument for monitoring vendor terms of service rather than reviewing them once.

It is also part of a broader pattern in payments and checkout. The same direction is visible when Stripe shifted agent-transaction liability to users: providers are steadily reallocating risk toward the customer, one terms update at a time.

Potential impact for SaaS companies

Companies that use Bolt for checkout or payments may want to review whether:

  • their data processing records and customer-facing disclosures still match Bolt's claim of sole ownership of end-user data

  • their contracts and insurance assumptions account for a liability cap that now covers 3 months of fees instead of 12

  • their incident-response runbooks can meet a 24-hour breach-notification window to Bolt

  • their internal documentation reflects that Bolt can use aggregated data and insights after the relationship ends

For teams that resell or build on top of Bolt, a change to who owns end-user data and relationships can cascade into their own customer agreements and disclosures. Tracking that across a full vendor portfolio is where structured vendor contract monitoring becomes a control rather than a periodic task, and where continuous vendor risk monitoring earns its place in the compliance stack.

How Venpo detected it

Venpo continuously monitors vendor legal documents and detects changes in real time. When Bolt published the new Merchant Terms of Use, Venpo immediately:

  • detected the updated document the day after it was posted

  • isolated the four substantive clauses from routine formatting

  • scored each as negative for merchants and explained the impact in plain English

  • flagged the data-ownership and liability-cap changes as the most material

Instead of discovering a rewritten ownership clause during a contract renewal or a customer security review, teams understood the change within a day of it shipping. Terms of Use change too rarely to watch by hand and too materially to miss, which is the core of our comparison of manual vs automated vendor monitoring.

Business outcome

Companies that caught this change early were able to:

  • review whether Bolt's sole-ownership clause conflicts with their own customer data commitments

  • reassess legal and insurance exposure under the reduced liability cap

  • update incident-response procedures to meet the 24-hour reporting window

  • brief legal and compliance before the next renewal or customer audit

Instead of reacting to a clause discovered during due diligence, they adapted on their own schedule. This is the difference between operating with current information and operating on assumptions from the last review cycle.

Key takeaway

The most consequential vendor changes are often not in the privacy policy but in the Terms of Use, where ownership, liability, and breach obligations live. Bolt's update moved all three in its favor in a single revision, and the only on-page signal was a changed date. Venpo detected it the day after it shipped and explained what each clause means for merchants. A closer look at why scheduled reviews keep missing this kind of change is in our analysis of manual vs automated vendor monitoring.

Real-time change notifications

Stay ahead of every legal change

Get updates, product news and expert tips on navigating legal changes

Stripe updated Terms of Service

Dispute resolution clause now requires mandatory arbitration in all regions

High Impact2 hours ago
AWS modified Privacy Policy

Data retention period extended from 2 years to 5 years for all services

Medium Impact5 hours ago
Shopify revised Acceptable Use Policy

New restrictions on AI-generated content in product descriptions

Review1 day ago
Slack changed Data Processing Agreement

Third-party data sharing expanded to include analytics partners

High Impact1 day ago

Real-time change notifications

Stay ahead of every legal change

Get updates, product news and expert tips on navigating legal changes

Stripe updated Terms of Service

Dispute resolution clause now requires mandatory arbitration in all regions

High Impact2 hours ago
AWS modified Privacy Policy

Data retention period extended from 2 years to 5 years for all services

Medium Impact5 hours ago
Shopify revised Acceptable Use Policy

New restrictions on AI-generated content in product descriptions

Review1 day ago
Slack changed Data Processing Agreement

Third-party data sharing expanded to include analytics partners

High Impact1 day ago