TabaPay Merchant Agreement
Last updated: August 31, 2026
This Merchant Agreement is entered into by and among TabaPay, Inc., a Delaware corporation ("ISO"), Cross River Bank, a New Jersey state chartered bank ("Bank"), and the entity agreeing to this Agreement as the Merchant ("Merchant;" together with ISO and Bank, the "Parties") as of the date of ISO's acceptance of the Merchant Application (the "Effective Date"). By entering into this Merchant Agreement, including the Merchant Application and any associated addenda, exhibits and attachments as amended from time to time (together, the "Agreement"), Merchant agrees to comply with and be subject to the Rules. Merchant acknowledges that it has sole responsibility to obtain the Rules and updates thereto. Any violations of the Rules by Merchant will constitute a material breach of this Agreement.
Merchant must complete and submit a signed Merchant information disclosure form titled Merchant Application (the "Merchant Application"). If ISO electronically communicates approval of the Merchant Application, this Agreement will be deemed executed by ISO and will become effective on the Effective Date without further action by ISO.
Recitals
WHEREAS, Merchant is in the business of selling goods or providing services to its customers. Merchant has entered into a written agreement with Natural AI, Inc. ("Company") to receive the technology and software solution services provided by Company, including Transaction acceptance.
WHEREAS, ISO and Company have entered into that certain Platform Funds Processing Agreement (the "Funds Agreement").
WHEREAS, ISO is in the business of processing Transactions, among other transactions comprising the Services, for Bank and pursuant to instructions received from Merchant.
WHEREAS, Bank (i) provides Transaction sponsorship for Merchant into the Card Networks; and (ii) conducts Settlement for Merchant's Transactions.
WHEREAS, to better serve its customers, Merchant has requested, and ISO has agreed to permit, Merchant's use of the Services through the establishment of the program ("Program") described in this Agreement and as specified in the Merchant Application. The Merchant Application is incorporated into this Agreement by this reference.
1. Definitions
"Applicable Law" means all applicable laws, codes, statutes, ordinances, rules, regulations, regulatory bulletins, authoritative interpretations or guidance by, or any binding memorandum of understanding, cease-and-desist order, consent order, legal settlement, written agreement or other agreement with, or enforcement order of a Governmental Authority applicable to Merchant, ISO or Bank.
"Authorization" means an affirmative response by or on behalf of a Card Issuer that the amount of a purchase Transaction is within the Cardholder's available purchasing limit.
"Beneficiary" means a Merchant's employee, customer, vendor or other Merchant affiliated party that receives funds as a result of a Disbursement.
"Business Day" means any day other than: (i) Saturday or Sunday; (ii) a day on which Bank is authorized by law or executive order to be closed (and on which Bank or ISO is in fact closed); or (iii) a day on which the Federal Reserve Bank is closed.
"Card" means (i) a valid credit, debit or prepaid debit card in the form issued under license from Visa U.S.A. Inc., Visa International, Inc., MasterCard International Incorporated, American Express or Discover Network; or (ii) any other valid credit, debit or prepaid debit card accepted by Merchant and facilitated by Bank and ISO.
"Card Issuer" means the financial institution or company that has provided a Card to the Cardholder.
"Card Network" means VISA, Mastercard, Discover, STAR, NYCE, PULSE, Maestro, Accel, CULIANCE and other networks that route Transactions to Card Issuers, as such list may be added to or shortened from time to time by ISO at its sole discretion. American Express is a Card Network under this agreement, except Bank does not provide American Express Transaction sponsorship for Merchant. In order to accept American Express Cards, Merchant will be required to agree to the separate American Express amendment, as set forth in Section 2.3.
"Cardholder" means the person in whose name the Card is issued.
"Chargeback" means the procedure by which the value of a Transaction (or disputed portion thereof) is returned by Bank to a Card Issuer.
"Custodial Account" means one or more Bank-owned and controlled accounts held "for the benefit of" the Merchant for the crediting and debiting of Transaction proceeds pursuant to this Agreement.
"Disbursement" means the payment to a Beneficiary through a Card Network, using the Beneficiary's Card to receive the funds.
"Governmental Authority" means any federal, state, foreign, local or other governmental department, commission, board, bureau, administrative or regulatory agency, or instrumentality, or any political subdivision thereof, or any court, commission, arbitrator, mediator or similar dispute resolution party.
"Purchase" means the exchange of goods or services from Merchant to a Cardholder in exchange for payment through the use of a Card.
"Receipt" means an electronic receipt or confirmation provided to the Cardholder subsequent to a Transaction.
"Representatives" means a Party's employees, directors, officers, service providers and agents.
"Reversal" means the reversal of a completed Transaction.
"Rules" means all rules and regulations, as amended from time to time, of the Card Networks and all Applicable Law.
"Sensitive Data" means any Cardholder's Card account number, security code, and expiration date.
"Services" means the processing services, including Transactions, address verifications, Reversals, Voids, Authorizations, Chargeback processing, Program setup, periodic reports, and ongoing Program support provided by Bank and ISO under this Agreement.
"Settlement" means each Business Day, Bank, using ISO reports, crediting the Custodial Account after receiving proceeds for Purchases from the Card Networks and/or debiting the Custodial Account to pay the Card Networks for Disbursements.
"Transaction" means any or all of Purchases, Disbursements, Reversals, Voids, and Chargebacks.
"Void" means the elimination of a prior Authorization.
2. Merchant Covenants and Agreements
2.1. Company Services
- Merchant will use only the technology, mobile application and software services provided by Company (collectively, the "Company Services") for the processing of all Transactions submitted for processing under this Agreement. Merchant will not use any other third-party service or software for Transaction processing, Sensitive Data capture and/or Sensitive Data storage, unless ISO approves it in writing.
- Merchant acknowledges that Company provides the Company Services under a separate written agreement between Merchant and Company.
- Merchant's indemnification obligations relating to the Company Services are set forth in Section 6.
- Merchant will provide Company with all instructions needed to process and settle Transactions and disburse funds under this Agreement. ISO and Bank may rely on instructions received from Company without further verification. ISO and Bank are not liable for inaccurate or erroneous information that Merchant provides to Company or that Company provides to ISO or Bank.
2.2. Compliance With Applicable Law and Rules
- Merchant represents, warrants, and covenants that it is and will remain throughout the Term of this Agreement in full compliance with Applicable Law and the Rules and maintain policies and procedures designed for such compliance. Merchant is responsible for obtaining legal advice regarding its compliance obligations. If a Governmental Authority files a complaint against Merchant arising from Merchant's activities under this Agreement, Merchant will reimburse Bank and ISO for resulting third-party fines, fees, and legal fees.
- Merchant will report to ISO, within five days after receipt, any inquiry, investigation, notice, or other correspondence from a Governmental Authority regarding Merchant's alleged violation of Applicable Law.
- Merchant will comply with the Rules regarding use of the Card Network marks, acceptance of Cards, risk management and Transaction processing, including without limitation the terms and conditions set forth in the American Express amendment, pursuant to Section 2.3.
- Merchant will not submit any Transaction that it knows or should have known violates the Rules or Applicable Law.
- Merchant will not invoice to or collect from any Cardholder directly for any Purchase, except only if (i) a Chargeback has been exercised, (ii) Merchant has fully paid the amount of such Chargeback, and (iii) Merchant otherwise has the right to do so.
- Merchant will not (i) commit fraud or otherwise violate Applicable Law in connection with a Transaction, (ii) accept or provide to ISO Transaction instructions that Merchant knows or should have known was fraudulent or otherwise in violation of Applicable Law, or (iii) accept or provide to ISO Transaction instructions that originate from any source other than Merchant's legitimate customers.
- Merchant will not originate a Transaction to any Beneficiary other than Merchant's legitimate customers, vendors, employees, or other entity known to Merchant on which Merchant has conducted the required "know your customer" diligence. Merchant warrants that each Disbursement is the result of a bona fide and legitimate business need and substantially consistent with Merchant Application.
2.3. American Express
As demonstrated by Merchant's acceptance of its first American Express Card for payment, Merchant accepts and agrees to the separate American Express OptBlue amendment for acceptance of American Express Cards https://www.tabapay.net/optblue/tabapay/AmexOptBlueAddendum.pdf. ISO will enable American Express for Transactions, except Disbursements, only if (i) Merchant requests such Transaction through ISO; and (ii) Merchant's business is in full compliance with American Express OptBlue Rules.
2.4. Disbursement Prefunding
- Merchant will not request a Disbursement unless the Custodial Account contains good and available funds, less all unpaid prior Disbursements, in an amount at least equal to Merchant's requested Disbursements (the "Prefunding Obligation").
- Bank and ISO have no obligation to process any Disbursement for which Prefunding Obligation has not been met.
- Merchant must immediately cure any shortfall in the Prefunding Obligation by Fedwire to the U.S. bank account designated by ISO.
2.5. Settlement
- Merchant authorizes Bank and ISO to initiate credits to and debits from the Custodial Account for Transactions based on instructions received from Company. Bank will debit the Custodial Account each day for the prior day's Disbursements (the "Settlement Funds"). Custodial Account funds are not FDIC-insured. Merchant will indemnify and hold harmless ISO and Bank for actions taken under this Section 2.5 with respect to the Custodial Account.
- Merchant may instruct Bank to transfer Settlement Funds deriving from Purchases to a bank account held in the name of Merchant at any U.S. bank that participates in the ACH network.
2.6. Sensitive Data
- Merchant represents, warrants, and covenants that throughout the Term, Merchant and its third-party service providers will comply with the Rules, PCI DSS, Visa's Account Information Security ("AIS") Program, American Express's Data Security Requirements ("DSR"), Discover's Information Security and Compliance ("DISC") Program, Mastercard's Site Data Protection ("SDP") Program, and any successor standards, in each case as amended or replaced. Merchant will require each service provider, subcontractor, and agent that accepts, stores, processes, or transmits Sensitive Data on Merchant's behalf to maintain the same compliance. Merchant will promptly report any noncompliance to ISO and pay any Card Network fines and penalties resulting from Merchant's or its Representatives' or service providers' noncompliance or failure to validate compliance. As indicated in the Merchant Application: (i) if Merchant uses only the Company Services for all Card entry and storage, Merchant appoints Company to complete, sign, and deliver Merchant's required compliance attestation to ISO before accessing Services and annually thereafter; or (ii) if Merchant uses its own systems or an ISO-approved third party for any Card entry or storage, Merchant will deliver the required compliance attestation to ISO before Services begin and annually thereafter.
- Each Party will be responsible to the other Parties for third-party fines, fees, and legal fees that the non-breaching Party incurs in responding to a data breach, including the cost of notifying affected Cardholders. Merchant acknowledges that it may be prohibited from participating in Card Network programs if Merchant does not comply with this Section 2.6.
3. Representations and Warranties
3.1. Representations, Warranties and Covenants of Merchant
Merchant represents, warrants, and covenants to Bank and ISO on the Effective Date and throughout the Term that:
- all information in the Merchant Application and any other document Merchant delivers to Bank or ISO is true and complete in all material respects;
- Merchant has the power to execute, deliver, and perform this Agreement, and this Agreement is duly authorized and does not violate Applicable Law or conflict with any other agreement binding Merchant;
- Merchant has all licenses required to conduct its business and is qualified to do business in each jurisdiction where required;
- the Merchant Application lists all URLs through which Merchant sells or provides its goods or services; all such URLs, prima facie, accurately and clearly represent all goods and services provided by Merchant; Merchant will submit a new Merchant Application for any new URL used to sell or provide Merchant's goods or services; no Merchant URL using the Services is prohibited as listed at https://tabapaypaymentservices.com; and each Merchant URL will use a different ISO-provided identifier to access the Services; and
- no existing or, to Merchant's knowledge, threatened circumstance would substantially impair Merchant's ability to conduct its business as currently conducted or materially and adversely affect its financial condition or operations.
3.2. Representations and Warranties of ISO
ISO represents and warrants to Merchant on the Effective Date and throughout the Term that:
- ISO has the power to execute, deliver, and perform this Agreement, and this Agreement is duly authorized and does not violate Applicable Law or conflict with any other agreement binding ISO;
- ISO has all licenses, if any, required to conduct its business and is qualified to do business in each jurisdiction where required;
- no circumstance known to ISO, threatened by, against, or affecting ISO, would substantially impair ISO's ability to conduct its business as currently conducted or materially and adversely affect its financial condition or operations;
- ISO complies with PCI DSS, AIS, DSR, DISC, and SDP; and
- ISO will promptly and accurately process Transaction instructions received from Company on Merchant's behalf in accordance with Card Network technical specifications.
4. Term and Termination
4.1. Term
The initial term of this Agreement is two years beginning on the Effective Date (the "Initial Term"). The Agreement will automatically renew for successive one-year terms (each, a "Renewal Term," and together with the Initial Term, the "Term") unless a Party gives the other Party written notice of nonrenewal at least thirty (30) days before the current Term expires.
4.2. Termination
- This Agreement may be terminated:
- by Merchant, Bank, or ISO with 30 days' prior notice without cause;
- immediately by ISO upon written notice if: (A) Merchant experiences a material adverse change in its financial condition, (B) Merchant or any of its Representatives is involved in a fraudulent Transaction, (C) legal process is served on Bank seeking to attach or garnish Merchant funds or property in Bank's possession and Merchant does not satisfy or appeal the process within fifteen (15) days, (D) Merchant becomes insolvent, is placed in receivership, makes an assignment for the benefit of creditors, admits in writing that it cannot pay its debts, seeks relief under the federal Bankruptcy Code, or has a bankruptcy petition filed against it, or (E) Merchant materially breaches this Agreement; or
- immediately by any Party if: (A) any Rule is amended such that the continued performance of this Agreement would cause such Party to be in breach of those Rules, or (B) the continued performance of this Agreement will cause harm or loss of goodwill to any Card Network, any Card Network requires Bank or ISO to limit or terminate this Agreement, or any Card Network is no longer willing to accept Transactions from Merchant.
- This Agreement will automatically terminate if the Funds Agreement between ISO and Company terminates or ISO's sponsorship agreement with Bank terminates, for any reason.
5. Limitation of Liability
5.1. Limitation of Liability
- IN NO CASE WILL MERCHANT OR ANY THIRD PARTY BE ENTITLED TO RECOVER DAMAGES FROM BANK FOR ANY REASON. To the extent the foregoing provision is unenforceable in an applicable jurisdiction, Bank's liability will be limited to the portion of the Transaction fees received by Bank for Merchant's Transactions that are processed under this Agreement for the one-calendar-month period immediately preceding the date of occurrence of the event giving rise to the claim for damages.
- The liability, if any, of ISO under this Agreement, whether to Merchant or to any other person, will not exceed in the aggregate, the portion of the Transaction fees received by ISO for Merchant's Transactions, exclusive of associated fees paid to Card Networks, that are processed under this Agreement for the one-calendar-month period immediately preceding the date of occurrence of the event giving rise to the claim for damages.
- NO PARTY SHALL HAVE ANY LIABILITY FOR CONSEQUENTIAL, EXEMPLARY, INCIDENTAL, SPECIAL, PUNITIVE OR INDIRECT DAMAGES (INCLUDING LOSS OF PROFITS OR BUSINESS OPPORTUNITIES) REGARDLESS OF WHETHER SUCH PARTY HAS BEEN ADVISED, OR IS AWARE, THAT SUCH DAMAGES HAVE BEEN OR MAY BE INCURRED.
5.2. Warranty Disclaimers
NEITHER BANK NOR ISO MAKES ANY EXPRESS OR IMPLIED REPRESENTATION OR WARRANTY REGARDING THE SERVICES. BANK AND ISO DISCLAIM ALL IMPLIED WARRANTIES, INCLUDING MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE. IF BANK'S OR ISO'S PERFORMANCE OR FAILURE TO PERFORM RESULTS IN AN ERROR, OMISSION, INTERRUPTION, OR DELAY, ITS LIABILITY IS LIMITED TO CORRECTING THE ISSUE IF COMMERCIALLY REASONABLE.
6. Indemnification
Merchant will indemnify, defend and hold harmless Bank, ISO and their Representatives from any losses arising out of or related to: (a) any claim relating to a dispute between Merchant and a Cardholder or a customer of Merchant, or any claim regarding a completed Transaction that is made by anyone by way of defense, dispute, offset, counterclaim or affirmative action; (b) Merchant's breach of any representation, warranty, obligation or term of or under this Agreement, including the Merchant Application; (c) Merchant's failure to comply with the Rules or violation of Applicable Law; (d) a breach of the security of Merchant's system safeguarding Cardholder information or Merchant's failure to comply with PCI DSS, AIS, DSR, DISC or SDP; (e) Merchant's negligence or willful misconduct in the performance of its obligations under this Agreement; (f) fraud by Merchant, its Representatives or any Cardholder; (g) a breach of Merchant's systems that exposes Sensitive Data; (h) Merchant's use of the Company Services; and (i) all third-party claims arising from the foregoing.
7. Confidentiality
7.1. Definition
"Confidential Information" means any nonpublic information disclosed by or on behalf of one Party (the "Disclosing Party") to another Party (the "Receiving Party"), whether disclosed before or after the Effective Date and whether disclosed electronically or in writing, that is designated as confidential or that reasonably should be understood to be confidential based on the nature of the information or the circumstances of disclosure. Confidential Information includes business, financial, technical, operational, security, customer, Merchant, and Transaction information; pricing; fees; trade secrets; business plans; processes; systems; software; documentation; and the terms of this Agreement.
7.2. Exclusions
Confidential Information does not include information that the Receiving Party can demonstrate:
- is or becomes publicly available through no breach of this Agreement by the Receiving Party or its Representatives;
- was lawfully known to the Receiving Party without restriction on disclosure before receiving it from the Disclosing Party;
- is lawfully received from a third party without breach of any confidentiality obligation; or
- is independently developed by the Receiving Party without use of or reference to the Disclosing Party's Confidential Information.
7.3. Use and Disclosure
The Receiving Party will:
- use the Disclosing Party's Confidential Information only to exercise its rights and perform its obligations under this Agreement.
- protect the Confidential Information using at least the same degree of care it uses to protect its own confidential information of a similar nature, but no less than reasonable care; and
- not disclose the Confidential Information to any third party without the Disclosing Party's prior written consent, except to the Receiving Party's Representatives who have a need to know the Confidential Information for purposes of this Agreement and are bound by written confidentiality obligations at least as restrictive as those in this Section.
The Receiving Party is responsible for any breach of this Section by its Representatives.
7.4. Authorized Disclosures
Merchant authorizes Bank and ISO to disclose Transaction information and Merchant information to third parties that, in Bank's or ISO's reasonable discretion, need such information to provide the Services, provided that those third parties are subject to confidentiality obligations at least as restrictive as those in this Section.
7.5. Required Disclosures
A Receiving Party may disclose Confidential Information to the extent required by a Governmental Authority, Applicable Law, court order, subpoena, or other valid legal process. To the extent legally permitted, the Receiving Party will provide the Disclosing Party with prompt written notice of the required disclosure and reasonable assistance, at the Disclosing Party's expense, if the Disclosing Party seeks a protective order or other appropriate remedy. The Receiving Party will disclose only the portion of the Confidential Information legally required to be disclosed and will use reasonable efforts to obtain confidential treatment for the disclosed information. For clarity:
- ISO and Bank may produce records in response to a subpoena in accordance with this Section;
- Company can share Merchant Confidential Information with ISO and Bank; and
- ISO can share Merchant Confidential Information with Bank.
8. Miscellaneous
8.1. Notices
All notices and other communications required or permitted under this Agreement will be deemed delivered when delivered via overnight carrier or certified mail, addressed as follows:
- if to ISO or Bank: TabaPay, 450 Cambridge Avenue, Palo Alto, CA 94306; or
- if to Merchant, at the address on the Merchant Application.
8.2. Modifications to Agreement
Amendments to this Agreement must be in writing and signed by the Parties, except that ISO may amend this Agreement as reasonably necessary to conform to the Rules, Bank regulatory requirements, or Applicable Law by giving Merchant at least thirty (30) days' written notice. Merchant may terminate this Agreement after receiving the notice; otherwise, the amendment becomes effective at the end of the notice period. An amendment required by Applicable Law, the Rules, or a judicial decision may become effective sooner if ISO specifies that a shorter period is necessary for compliance.
8.3. General
If any provision of this Agreement is illegal or unenforceable, the remaining provisions will remain in effect. This Agreement binds and benefits the Parties and their respective successors and permitted assigns. This Agreement, including the Merchant Application, is the Parties' entire agreement regarding its subject matter and may be modified only as provided in this Agreement. Merchant may not assign this Agreement, directly or by operation of law, without the other Party's prior written consent. California law governs this Agreement, without regard to its conflict-of-laws rules. Any claim or controversy arising from this Agreement that the Parties do not resolve by agreement will be decided by binding arbitration under Section 8.4. A Party's failure to enforce a provision is not a waiver of that provision or any other provision, and any waiver must be signed by the waiving Party. A Party is not liable for a loss, delay, or failure to perform to the extent caused by an event beyond its reasonable control, including fire, flood, explosion, accident, war, strike, embargo, pandemic, governmental action, civil or military authority, civil unrest, cyberattack, inability to obtain materials or labor, or a similar event. Singular terms include the plural and vice versa. "Including" and "includes" mean "including without limitation."
8.4. Arbitration Agreement for Claims
Any dispute, claim, or controversy arising out of or relating to this Agreement, or its breach, termination, enforcement, interpretation, or validity, including the determination of the scope or applicability of this agreement to arbitrate, will be resolved by arbitration in San Jose, California before one arbitrator reasonably acceptable to both Parties and experienced in the subject matter of the dispute. If the Parties cannot agree on an arbitrator, the arbitrator will be selected under the JAMS Rules. JAMS will administer the arbitration under its Comprehensive Arbitration Rules and Procedures and the Expedited Procedures in those Rules (together, the "JAMS Rules"). Judgment on the award may be entered in any court with jurisdiction. This clause does not prevent a Party from seeking provisional remedies in aid of arbitration from a court with appropriate jurisdiction. No claim may be arbitrated on a class or representative basis or on behalf of the general public or similarly situated persons. This Section 8.4 is made under a transaction involving interstate commerce and is governed by the Federal Arbitration Act (the "FAA"). The arbitrator will apply California procedural law and applicable statutes of limitations and will honor legally recognized privileges. The arbitrator's decision is final and binding, except for appeal rights under the FAA. The arbitration and all information submitted or presented in connection with it are confidential and may not be disclosed to anyone who is not a party to the arbitration.
Fee Schedule
Merchant will pay Company for the Services under Merchant's separate agreement with Company. ISO, rather than Company, will bill and collect from Merchant any fines, non-Transaction fees charged by a Card Network, and similar non-Transaction fees, which are due from Merchant on ISO notice.