Vendor Privacy Policy

How Markood collects, uses and protects Vendor information

Last updated:
26/02/2026
Version:
1.0

This Vendor Privacy Policy explains how Markood collects, uses, shares, stores and protects personal information relating to Vendors, business owners, authorised representatives and Vendor staff.

It applies when you: Apply to become a Markood Vendor; create or manage a Vendor account; operate a store through Markood; process customer orders; receive Vendor payouts; communicate with Markood; or use the Markood Vendor Dashboard.

1. Who is responsible for your information?

The data controller is:

Legal company name: MARKOOD

Privacy email: support@markood.com

Markood determines why and how Vendor personal information is processed for the purposes described in this Policy.

2. Information Markood collects

The information collected depends on the Vendor’s business structure, product category and use of Markood.

2.1 Vendor and contact information

Markood may collect:

  • Full name
  • Business email address
  • Telephone number
  • Position or job title
  • Preferred language
  • Account profile information
  • Authorised-representative information

2.2 Business information

Markood may collect:

  • Legal business name
  • Trading name
  • Organisation number
  • Registered business address
  • Store or operating address
  • Company type
  • Business category
  • Website and social-media information
  • Licences, permits and insurance details

Information relating only to a legal entity may not always constitute personal data. This Policy applies when business information identifies or relates to an individual.

2.3 Tax and VAT information

Markood may collect:

  • VAT number
  • F-tax or FA-tax status
  • Tax residence
  • Taxpayer identification details
  • Information required for tax reporting
  • Transaction and payout information
  • Documents supporting tax status

2.4 Owners and authorised representatives

Markood may collect information about:

  • Business owners
  • Beneficial owners
  • Directors
  • Authorised representatives
  • Account administrators
  • Vendor employees

This may include names, ownership percentages, positions, contact details and verification information.

2.5 Identity-verification information

To verify the Vendor and prevent fraud, Markood or an approved verification provider may collect:

  • Government-issued identification
  • Date of birth
  • Nationality
  • Photograph or identity-verification image
  • Document number and expiry date
  • Verification status
  • Sanctions or compliance-check results
  • Information confirming the right to represent the business

Markood should collect only the information necessary for the relevant verification purpose.

2.6 Bank and payout information

Markood or its payment provider may collect:

  • Account-holder name
  • Bank name
  • IBAN or bank-account number
  • Clearing or routing information
  • Payout-provider account identifier
  • Payout status and history
  • Refunds, reversals and adjustments

Banking information is used to verify the payout recipient and send Vendor proceeds.

2.7 Store, product and order information

Markood may collect:

  • Store name and profile
  • Product listings
  • Product photographs and descriptions
  • Prices and stock
  • Orders and cancellations
  • Preparation and handover times
  • Delivery and pickup information
  • Returns and refunds
  • Customer complaints
  • Vendor performance information
  • Customer ratings and reviews
  • Commission, fees and payout records

2.8 Device, login and security information

Markood may collect:

  • IP address
  • Device and browser type
  • Operating system
  • Login time and activity
  • Account changes
  • Cookie identifiers
  • Security and fraud signals
  • Approximate location derived from an IP address
  • Crash and diagnostic information

2.9 Communications

Markood may retain:

  • Support tickets
  • Emails
  • Live-chat messages
  • Call records where lawfully recorded
  • Uploaded documents and attachments
  • Complaint and appeal communications
  • Communications involving active orders

2.10 Fraud, dispute and compliance information

Markood may collect:

  • Suspected fraud indicators
  • Chargeback information
  • Customer disputes
  • Product-authenticity complaints
  • Product-safety reports
  • Policy violations
  • Account restrictions
  • Appeal records
  • Legal or regulatory enquiries

3. How Markood receives information

Markood may receive information:

  • Directly from the Vendor
  • Through the Vendor Dashboard
  • From Vendor employees or representatives
  • From payment providers
  • From identity-verification providers
  • From delivery companies
  • From customers
  • From public business registers
  • From tax or regulatory authorities where legally permitted
  • Automatically when the Vendor uses the platform

The Vendor must ensure that it is authorised to provide information concerning its owners, employees and representatives.

4. Why Markood uses Vendor information

Markood must have a lawful basis for every use of personal information.

4.1 Creating and managing Vendor accounts

Markood uses information to:

  • Process Vendor applications
  • Create accounts
  • Approve stores
  • Manage account permissions
  • Maintain Vendor profiles
  • Communicate operational information

The usual lawful bases are performing the Vendor Agreement, taking requested steps before entering the Agreement and Markood’s legitimate interests in operating the marketplace.

4.2 Verification and compliance

Markood uses information to:

  • Verify the business and its representatives
  • Confirm ownership and authority
  • Verify tax and payout information
  • Prevent duplicate or fraudulent accounts
  • Meet marketplace and tax-reporting obligations
  • Conduct sanctions or compliance checks where required

The lawful bases may include legal obligations and legitimate interests in protecting Markood and its users.

4.3 Operating the marketplace

Markood uses information to:

  • Publish and operate Vendor stores
  • Display products
  • Manage orders
  • Provide delivery options
  • Process returns and complaints
  • Measure Vendor performance
  • Provide reports and analytics

4.4 Payments and payouts

Markood uses information to:

  • Process customer payments
  • Calculate commissions and fees
  • Process refunds
  • Send Vendor payouts
  • Manage holds and reserves
  • Handle chargebacks and payment disputes
  • Produce transaction records

Payment and banking information may be processed by an authorised provider such as [CONFIRM PROVIDER—e.g. Stripe].

4.5 Fraud prevention and security

Markood uses information to:

  • Protect Vendor accounts
  • Detect unauthorised access
  • Investigate suspicious transactions
  • Prevent fraud and platform abuse
  • Enforce Vendor policies
  • Protect customers, Vendors and Markood

4.6 Customer and Vendor support

Information may be used to:

  • Respond to support requests
  • Investigate order problems
  • Resolve returns and refunds
  • Handle complaints and appeals
  • Communicate policy or account changes

4.7 Legal and regulatory obligations

Markood may use and retain information to:

  • Meet accounting and tax requirements
  • Respond to lawful authority requests
  • Meet trader-verification requirements
  • Address product-safety obligations
  • Establish, exercise or defend legal claims
  • Comply with court orders and applicable laws

4.8 Improving Markood

Markood may analyse platform activity to:

  • Improve Vendor tools
  • Fix errors
  • Improve performance
  • Understand how features are used
  • Develop new marketplace services
  • Protect platform stability

Where possible, Markood should use aggregated or anonymised information for analytics.

4.9 Marketing

Markood may send information about Vendor features, services or campaigns where legally permitted.

When consent is required, marketing will be sent only after consent is obtained.

Vendors may opt out of promotional communications. Opting out does not stop operational, security, payment or legal messages.

5. Who may receive Vendor information?

Markood shares information only when necessary for the purposes described in this Policy.

5.1 Payment providers

Payment providers may receive identity, business, banking, transaction and payout information to:

  • Process customer payments
  • Verify payout accounts
  • Send Vendor proceeds
  • Process refunds
  • Manage disputes and chargebacks
  • Conduct fraud and compliance checks

Payment providers may also act as independent data controllers for some processing under their own privacy policies.

5.2 Delivery companies

Approved delivery companies may receive information necessary to:

  • Collect orders
  • Contact the Vendor
  • Confirm handover
  • Complete delivery
  • Investigate loss, damage or delays

They should not receive information unrelated to fulfilment.

5.3 Identity-verification providers

Verification providers may process:

  • Identification documents
  • Business information
  • Representative information
  • Beneficial-owner information
  • Verification and compliance results

5.4 Cloud and technology providers

Markood may use providers for:

  • Hosting
  • Data storage
  • Communications
  • Customer support
  • Security
  • Analytics
  • Error monitoring
  • Document management

Providers acting as processors must use the information only according to Markood’s instructions and contractual requirements.

5.5 Professional advisers

Information may be shared with:

  • Lawyers
  • Accountants
  • Auditors
  • Insurance providers
  • Security advisers
  • Other professional consultants

They receive only information reasonably necessary for their work.

5.6 Authorities

Markood may disclose information to tax, law-enforcement, court or regulatory authorities when:

  • Required by law
  • Required by a valid legal order
  • Necessary to report unlawful activity
  • Necessary to address serious fraud or product-safety risks

5.7 Business transfers

If Markood is involved in a merger, restructuring, financing, acquisition or sale, relevant Vendor information may be disclosed subject to appropriate confidentiality and data-protection safeguards.

Markood does not sell Vendor personal information.

6. International data transfers

Some providers may process information outside Sweden or the European Economic Area.

Where personal information is transferred outside the EEA, Markood will use a legally recognised transfer mechanism, such as:

  • An EU adequacy decision
  • European Commission Standard Contractual Clauses
  • Another approved legal safeguard

Markood will apply additional security measures where appropriate.

7. How long Markood retains information

Markood retains personal information only for as long as necessary for its purpose and applicable legal requirements.

Markood may retain:

  • Account information while the Vendor account is active
  • Agreement and acceptance records for the relevant contractual period
  • Orders, payments and payouts for accounting and tax requirements
  • Identity and verification records while required for fraud, tax or regulatory compliance
  • Complaints and disputes until resolution and the expiry of relevant legal-claim periods
  • Product-safety and recall records for required safety and regulatory periods
  • Security records for a limited period based on the identified risk
  • Marketing preferences until withdrawn or no longer required

Markood must maintain an internal retention schedule specifying the approved period for every category.

Closing a Vendor store does not mean every record will be deleted immediately. Records may be retained for:

  • Accounting
  • Tax reporting
  • Fraud prevention
  • Product safety
  • Chargebacks
  • Outstanding disputes
  • Legal claims
  • Regulatory compliance

Information will be deleted or anonymised when it is no longer required.

8. Vendor privacy rights

Subject to applicable law, an individual may request:

Access

A copy of the personal information Markood holds about them and information about its use.

Correction

Correction of inaccurate or incomplete personal information.

Deletion

Deletion of eligible personal information when Markood no longer has a lawful reason to retain it.

Restriction

Restriction of certain processing in circumstances permitted by GDPR.

Data portability

A portable copy of eligible information provided to Markood and processed automatically based on consent or contract.

Objection

Objection to certain processing based on legitimate interests and objection at any time to direct marketing.

Withdrawal of consent

Withdrawal of consent where Markood relies on consent. Withdrawal does not affect processing that occurred lawfully before withdrawal.

Complaint

A complaint may be submitted to the Swedish Authority for Privacy Protection:

Integritetsskyddsmyndigheten (IMY)

www.imy.se

To exercise a right, contact:

privacy@markood.com

Markood may request reasonable identity verification before responding.

These rights are not absolute. Markood may retain or continue processing information when required by law or necessary for legal claims.

9. Security and incident reporting

Markood uses reasonable technical and organisational measures designed to protect Vendor information, including where appropriate:

  • Encryption during transmission
  • Secure password hashing
  • Multi-factor authentication
  • Role-based access controls
  • Security monitoring
  • Restricted employee access
  • Backups
  • Incident-response procedures
  • Provider security requirements

No online system can guarantee absolute security.

The Vendor must immediately notify Markood if it suspects:

  • Unauthorised account access
  • A stolen password or device
  • Disclosure of customer information
  • Misuse of Markood data
  • A security or personal-data incident

Incidents should be reported to:

security@markood.com or support@markood.com

10. Automated checks

Markood or its providers may use automated tools to identify:

  • Fraudulent accounts
  • Suspicious payments
  • Account takeovers
  • Policy violations
  • Unusual transaction activity

Where a decision is based solely on automated processing and produces legal or similarly significant effects, Markood will provide the safeguards required by applicable law, including human review where required.

11. Changes to this Policy

Markood may update this Policy to reflect changes in its services, providers or legal obligations.

The updated Policy will be published with a revised “Last updated” date. Material changes will be communicated where required.

12. Contact Markood

[INSERT MARKOOD’S FULL REGISTERED COMPANY NAME]

Organisation number: [INSERT]

Registered address: [INSERT]

Privacy email: privacy@markood.com

Support email: support@markood.com

Data Protection Officer: [INSERT IF APPLICABLE]