Skip to content
vendor
Legal

Privacy policy

How Vendor collects, uses, and protects information when you use the platform and the marketing site.

Last updated:

This policy explains what personal data we collect, why we collect it, who we share it with, and the choices you have. It applies to our marketing site at vendor.com.mk and to the Vendor commerce platform. Where we process data on behalf of our customers (the data their own shoppers generate), we act as a processor under our Data Processing Agreement, and the customer is the controller.

1. Who we are

The data controller for personal data processed through our own services is the company below. We have appointed a Data Protection Officer who is your point of contact for any privacy matter. For questions about this policy or to exercise your rights, contact us at privacy@vendor.com.mk or through vendor.com.mk/contact.

  • Legal name: Друштво за програмирање, веб дизајн и трговија ВЕНДОР ДООЕЛ увоз-извоз Скопје (Vendor DOOEL Skopje).
  • Legal form: single-member limited liability company (ДООЕЛ).
  • Registered office: Jadranska Magistrala 47b, 1000 Skopje, North Macedonia.
  • Company registration number (ЕМБС): 7529210.
  • Tax number (ЕДБ): MK4044021519199.
  • Data Protection Officer: Dejan Milosavleski — privacy@vendor.com.mk, +389 70 321 015.

2. What we collect

We collect the categories of personal data below. We ask for the minimum needed to create your store, run your subscription, secure the service, and support you.

We do not collect a password during sign-up — after your store is provisioned, we email you a secure sign-in link and administrator code, and authentication is handled by AWS Cognito.

  • Sign-up details you give us: store name, your first and last name, email address, and optionally company name, phone number, and billing city and country.
  • Business profile answers you choose to provide during onboarding: store type, current platform, business category, expected order volume, and catalog size.
  • Authentication data, managed through AWS Cognito: your email, securely stored credentials, sign-in tokens, and multi-factor settings if you enable them.
  • Billing data: your selected plan, billing country, payment status, and the transaction references and tokens returned by our payment provider. We do not store full card numbers — card details are entered directly on the provider's secure page.
  • Usage, log, and device data: IP address, browser and device information, and records of actions in the platform, used for security, fraud prevention, troubleshooting, and product improvement.
  • Support and marketing-site data: messages you send us, and contact, sales, or newsletter forms you submit on vendor.com.mk.
  • Shopper data routed through the platform by our customers (catalog, orders, customer accounts, and payment data), which we process only as a processor on their behalf.

3. Why we collect it

We rely on the following lawful bases under the GDPR and the Law on Personal Data Protection of the Republic of North Macedonia:

Where our processing relies on consent, you can withdraw it at any time without affecting the lawfulness of processing carried out before withdrawal.

  • Performance of our contract with you (GDPR Art. 6(1)(b)): creating and provisioning your store, authenticating you, providing the platform, and processing your subscription payments.
  • Legitimate interests (Art. 6(1)(f)): keeping the service secure, preventing fraud and abuse, diagnosing problems, improving the product, and sending business communications to our customers.
  • Consent (Art. 6(1)(a)): non-essential cookies and any analytics or marketing activities that rely on consent, and our newsletter — you can withdraw consent at any time.
  • Legal obligation (Art. 6(1)(c)): keeping tax, accounting, and billing records, and responding to lawful requests from authorities.

4. How we share data

We do not sell personal data. We share it only with the sub-processors that help us run the platform — for example AWS (hosting, database, storage, transactional email, authentication, and search), Cloudflare (security and content delivery), our payment providers (subscription billing runs through Halkbank NestPay; merchant storefront payments may also use Stripe, PayPal, CPay/Casys, NLB, Payrexx, or Iute depending on the merchant's configuration), and Google and Mapbox for maps and supporting services.

Each sub-processor is bound by a data processing agreement with confidentiality and security obligations, and transfers are protected by appropriate safeguards (Standard Contractual Clauses where required) plus encryption in transit and at rest. The current, itemised list of sub-processors — what each one processes and where it operates — is maintained at vendor.com.mk/security/sub-processors and updated whenever it changes.

We may also disclose data where required by law, to protect our rights or the safety of others, or in connection with a merger, acquisition, or sale of assets, in which case we will notify affected customers.

5. Retention

We keep account and business data for as long as your subscription is active. After cancellation, we retain your store data in a recoverable state for 30 days so you can reactivate or export it, after which it is deleted from active systems and removed from backups in the ordinary backup-rotation cycle.

Billing, invoicing, and tax records are kept for as long as required by Macedonian tax and accounting legislation (generally up to ten years). Security and usage logs are kept for a limited period appropriate to their purpose, and support communications are kept for as long as needed to handle your request and our records. We may retain specific data longer where necessary for a legal hold or an active fraud or security investigation.

6. Your rights

Subject to applicable law, you have the following rights over your personal data:

You can exercise these rights through our self-service request flow at vendor.com.mk/legal/dsr or by emailing privacy@vendor.com.mk. We respond within 30 days (extendable for complex requests, as the GDPR allows) and may need to verify your identity first. You also have the right to lodge a complaint with the Agency for Personal Data Protection of the Republic of North Macedonia, or with your local EU/EEA supervisory authority if one applies to you.

  • Access — get a copy of the personal data we hold about you.
  • Rectification — correct inaccurate or incomplete data.
  • Erasure — ask us to delete your data where the law allows.
  • Restriction — limit how we use your data in certain cases.
  • Portability — receive your data in a portable, machine-readable format.
  • Objection — object to processing based on legitimate interests, including direct marketing.
  • Withdraw consent — withdraw any consent you have given, at any time.

7. International data transfers

Our primary infrastructure runs in the European Union (AWS, Frankfurt region). Some sub-processors operate outside the EU/EEA — for example certain monitoring and payment services in the United States. Where data leaves the EU/EEA, we rely on an adequacy decision or on Standard Contractual Clauses together with supplementary technical measures such as encryption.

The regions each sub-processor operates from are listed at vendor.com.mk/security/sub-processors.

8. Security

We protect data with encryption in transit (TLS 1.2+) and at rest (AES-256), keys managed in AWS Key Management Service, separate identity pools for shoppers, merchant operators, and platform administrators, least-privilege production access, audit logging of sensitive actions, and a coordinated vulnerability disclosure program. A fuller description of our controls is at vendor.com.mk/security.

If a personal-data breach occurs, we will notify the relevant supervisory authority and affected customers as required by law, including within 72 hours where the GDPR requires it.

9. Changes to this policy

We update this policy when our practices change. For material changes we notify account owners by email and/or an in-product notice. The 'Last updated' date above always reflects the current version, and continued use of the service after a change takes effect means you accept the updated policy.

Contact privacy team