Vendor Privacy Policy
How Markood collects, uses and protects Vendor information
- Last updated:
- 26/02/2026
- Version:
- 1.0
This Vendor Privacy Policy explains how Markood collects, uses, shares, stores and protects personal information relating to Vendors, business owners, authorised representatives and Vendor staff.
It applies when you: Apply to become a Markood Vendor; create or manage a Vendor account; operate a store through Markood; process customer orders; receive Vendor payouts; communicate with Markood; or use the Markood Vendor Dashboard.
1. Who is responsible for your information?
The data controller is:
Legal company name: MARKOOD
Privacy email: support@markood.com
Markood determines why and how Vendor personal information is processed for the purposes described in this Policy.
2. Information Markood collects
The information collected depends on the Vendor’s business structure, product category and use of Markood.
2.1 Vendor and contact information
Markood may collect:
- Full name
- Business email address
- Telephone number
- Position or job title
- Preferred language
- Account profile information
- Authorised-representative information
2.2 Business information
Markood may collect:
- Legal business name
- Trading name
- Organisation number
- Registered business address
- Store or operating address
- Company type
- Business category
- Website and social-media information
- Licences, permits and insurance details
Information relating only to a legal entity may not always constitute personal data. This Policy applies when business information identifies or relates to an individual.
2.3 Tax and VAT information
Markood may collect:
- VAT number
- F-tax or FA-tax status
- Tax residence
- Taxpayer identification details
- Information required for tax reporting
- Transaction and payout information
- Documents supporting tax status
2.4 Owners and authorised representatives
Markood may collect information about:
- Business owners
- Beneficial owners
- Directors
- Authorised representatives
- Account administrators
- Vendor employees
This may include names, ownership percentages, positions, contact details and verification information.
2.5 Identity-verification information
To verify the Vendor and prevent fraud, Markood or an approved verification provider may collect:
- Government-issued identification
- Date of birth
- Nationality
- Photograph or identity-verification image
- Document number and expiry date
- Verification status
- Sanctions or compliance-check results
- Information confirming the right to represent the business
Markood should collect only the information necessary for the relevant verification purpose.
2.6 Bank and payout information
Markood or its payment provider may collect:
- Account-holder name
- Bank name
- IBAN or bank-account number
- Clearing or routing information
- Payout-provider account identifier
- Payout status and history
- Refunds, reversals and adjustments
Banking information is used to verify the payout recipient and send Vendor proceeds.
2.7 Store, product and order information
Markood may collect:
- Store name and profile
- Product listings
- Product photographs and descriptions
- Prices and stock
- Orders and cancellations
- Preparation and handover times
- Delivery and pickup information
- Returns and refunds
- Customer complaints
- Vendor performance information
- Customer ratings and reviews
- Commission, fees and payout records
2.8 Device, login and security information
Markood may collect:
- IP address
- Device and browser type
- Operating system
- Login time and activity
- Account changes
- Cookie identifiers
- Security and fraud signals
- Approximate location derived from an IP address
- Crash and diagnostic information
2.9 Communications
Markood may retain:
- Support tickets
- Emails
- Live-chat messages
- Call records where lawfully recorded
- Uploaded documents and attachments
- Complaint and appeal communications
- Communications involving active orders
2.10 Fraud, dispute and compliance information
Markood may collect:
- Suspected fraud indicators
- Chargeback information
- Customer disputes
- Product-authenticity complaints
- Product-safety reports
- Policy violations
- Account restrictions
- Appeal records
- Legal or regulatory enquiries
3. How Markood receives information
Markood may receive information:
- Directly from the Vendor
- Through the Vendor Dashboard
- From Vendor employees or representatives
- From payment providers
- From identity-verification providers
- From delivery companies
- From customers
- From public business registers
- From tax or regulatory authorities where legally permitted
- Automatically when the Vendor uses the platform
The Vendor must ensure that it is authorised to provide information concerning its owners, employees and representatives.
4. Why Markood uses Vendor information
Markood must have a lawful basis for every use of personal information.
4.1 Creating and managing Vendor accounts
Markood uses information to:
- Process Vendor applications
- Create accounts
- Approve stores
- Manage account permissions
- Maintain Vendor profiles
- Communicate operational information
The usual lawful bases are performing the Vendor Agreement, taking requested steps before entering the Agreement and Markood’s legitimate interests in operating the marketplace.
4.2 Verification and compliance
Markood uses information to:
- Verify the business and its representatives
- Confirm ownership and authority
- Verify tax and payout information
- Prevent duplicate or fraudulent accounts
- Meet marketplace and tax-reporting obligations
- Conduct sanctions or compliance checks where required
The lawful bases may include legal obligations and legitimate interests in protecting Markood and its users.
4.3 Operating the marketplace
Markood uses information to:
- Publish and operate Vendor stores
- Display products
- Manage orders
- Provide delivery options
- Process returns and complaints
- Measure Vendor performance
- Provide reports and analytics
4.4 Payments and payouts
Markood uses information to:
- Process customer payments
- Calculate commissions and fees
- Process refunds
- Send Vendor payouts
- Manage holds and reserves
- Handle chargebacks and payment disputes
- Produce transaction records
Payment and banking information may be processed by an authorised provider such as [CONFIRM PROVIDER—e.g. Stripe].
4.5 Fraud prevention and security
Markood uses information to:
- Protect Vendor accounts
- Detect unauthorised access
- Investigate suspicious transactions
- Prevent fraud and platform abuse
- Enforce Vendor policies
- Protect customers, Vendors and Markood
4.6 Customer and Vendor support
Information may be used to:
- Respond to support requests
- Investigate order problems
- Resolve returns and refunds
- Handle complaints and appeals
- Communicate policy or account changes
4.7 Legal and regulatory obligations
Markood may use and retain information to:
- Meet accounting and tax requirements
- Respond to lawful authority requests
- Meet trader-verification requirements
- Address product-safety obligations
- Establish, exercise or defend legal claims
- Comply with court orders and applicable laws
4.8 Improving Markood
Markood may analyse platform activity to:
- Improve Vendor tools
- Fix errors
- Improve performance
- Understand how features are used
- Develop new marketplace services
- Protect platform stability
Where possible, Markood should use aggregated or anonymised information for analytics.
4.9 Marketing
Markood may send information about Vendor features, services or campaigns where legally permitted.
When consent is required, marketing will be sent only after consent is obtained.
Vendors may opt out of promotional communications. Opting out does not stop operational, security, payment or legal messages.
5. Who may receive Vendor information?
Markood shares information only when necessary for the purposes described in this Policy.
5.1 Payment providers
Payment providers may receive identity, business, banking, transaction and payout information to:
- Process customer payments
- Verify payout accounts
- Send Vendor proceeds
- Process refunds
- Manage disputes and chargebacks
- Conduct fraud and compliance checks
Payment providers may also act as independent data controllers for some processing under their own privacy policies.
5.2 Delivery companies
Approved delivery companies may receive information necessary to:
- Collect orders
- Contact the Vendor
- Confirm handover
- Complete delivery
- Investigate loss, damage or delays
They should not receive information unrelated to fulfilment.
5.3 Identity-verification providers
Verification providers may process:
- Identification documents
- Business information
- Representative information
- Beneficial-owner information
- Verification and compliance results
5.4 Cloud and technology providers
Markood may use providers for:
- Hosting
- Data storage
- Communications
- Customer support
- Security
- Analytics
- Error monitoring
- Document management
Providers acting as processors must use the information only according to Markood’s instructions and contractual requirements.
5.5 Professional advisers
Information may be shared with:
- Lawyers
- Accountants
- Auditors
- Insurance providers
- Security advisers
- Other professional consultants
They receive only information reasonably necessary for their work.
5.6 Authorities
Markood may disclose information to tax, law-enforcement, court or regulatory authorities when:
- Required by law
- Required by a valid legal order
- Necessary to report unlawful activity
- Necessary to address serious fraud or product-safety risks
5.7 Business transfers
If Markood is involved in a merger, restructuring, financing, acquisition or sale, relevant Vendor information may be disclosed subject to appropriate confidentiality and data-protection safeguards.
Markood does not sell Vendor personal information.
6. International data transfers
Some providers may process information outside Sweden or the European Economic Area.
Where personal information is transferred outside the EEA, Markood will use a legally recognised transfer mechanism, such as:
- An EU adequacy decision
- European Commission Standard Contractual Clauses
- Another approved legal safeguard
Markood will apply additional security measures where appropriate.
7. How long Markood retains information
Markood retains personal information only for as long as necessary for its purpose and applicable legal requirements.
Markood may retain:
- Account information while the Vendor account is active
- Agreement and acceptance records for the relevant contractual period
- Orders, payments and payouts for accounting and tax requirements
- Identity and verification records while required for fraud, tax or regulatory compliance
- Complaints and disputes until resolution and the expiry of relevant legal-claim periods
- Product-safety and recall records for required safety and regulatory periods
- Security records for a limited period based on the identified risk
- Marketing preferences until withdrawn or no longer required
Markood must maintain an internal retention schedule specifying the approved period for every category.
Closing a Vendor store does not mean every record will be deleted immediately. Records may be retained for:
- Accounting
- Tax reporting
- Fraud prevention
- Product safety
- Chargebacks
- Outstanding disputes
- Legal claims
- Regulatory compliance
Information will be deleted or anonymised when it is no longer required.
8. Vendor privacy rights
Subject to applicable law, an individual may request:
Access
A copy of the personal information Markood holds about them and information about its use.
Correction
Correction of inaccurate or incomplete personal information.
Deletion
Deletion of eligible personal information when Markood no longer has a lawful reason to retain it.
Restriction
Restriction of certain processing in circumstances permitted by GDPR.
Data portability
A portable copy of eligible information provided to Markood and processed automatically based on consent or contract.
Objection
Objection to certain processing based on legitimate interests and objection at any time to direct marketing.
Withdrawal of consent
Withdrawal of consent where Markood relies on consent. Withdrawal does not affect processing that occurred lawfully before withdrawal.
Complaint
A complaint may be submitted to the Swedish Authority for Privacy Protection:
Integritetsskyddsmyndigheten (IMY)
www.imy.se
To exercise a right, contact:
privacy@markood.com
Markood may request reasonable identity verification before responding.
These rights are not absolute. Markood may retain or continue processing information when required by law or necessary for legal claims.
9. Security and incident reporting
Markood uses reasonable technical and organisational measures designed to protect Vendor information, including where appropriate:
- Encryption during transmission
- Secure password hashing
- Multi-factor authentication
- Role-based access controls
- Security monitoring
- Restricted employee access
- Backups
- Incident-response procedures
- Provider security requirements
No online system can guarantee absolute security.
The Vendor must immediately notify Markood if it suspects:
- Unauthorised account access
- A stolen password or device
- Disclosure of customer information
- Misuse of Markood data
- A security or personal-data incident
Incidents should be reported to:
security@markood.com or support@markood.com
10. Automated checks
Markood or its providers may use automated tools to identify:
- Fraudulent accounts
- Suspicious payments
- Account takeovers
- Policy violations
- Unusual transaction activity
Where a decision is based solely on automated processing and produces legal or similarly significant effects, Markood will provide the safeguards required by applicable law, including human review where required.
11. Changes to this Policy
Markood may update this Policy to reflect changes in its services, providers or legal obligations.
The updated Policy will be published with a revised “Last updated” date. Material changes will be communicated where required.
12. Contact Markood
[INSERT MARKOOD’S FULL REGISTERED COMPANY NAME]
Organisation number: [INSERT]
Registered address: [INSERT]
Privacy email: privacy@markood.com
Support email: support@markood.com
Data Protection Officer: [INSERT IF APPLICABLE]