1. You haven't given them enough time to acknowledge it.
2. They are not acknowledging it to limit their liability. Suppose a black hat subsequently finds it and uses it to cause harm, and a victim sues. The acknowledgement to you could be used as proof that they knew about the bug before it was exploited.
You've done all you should do for now. You should now wait long enough for them to fix it. Take into account that there may be complications you are unaware of due to how their backend works, or due to how their development and testing is done, or how their bureaucracy works, so be generous.
Then check to see if the problem is still there. If it is, then go public anonymously, with just the technical details. Leave out the history of attempting to contact them (it could compromise your anonymity).