Skip to content
vendorCommerce
Vendor Standard

Privacy policy

[Replace this opening with the attorney-reviewed introduction.] This policy explains what we collect, why we collect it, and the choices you have. It applies to vendor.com.mk and the Vendor platform.

1. What we collect

[Replace with attorney-reviewed text.] Describe the categories of personal data Vendor processes — account information, contact details, billing data, usage telemetry, and any data customers route through the platform on behalf of their own shoppers.

Note: Vendor processes some categories of data only as a processor on behalf of its customers under the Data Processing Agreement linked at the bottom of this page.

  • Account information you provide when signing up.
  • Billing and tax details required to operate the contract.
  • Usage telemetry for security, fraud detection, and product improvement.
  • Storefront analytics events your shoppers generate, processed on your behalf.

2. Why we collect it

[Replace with attorney-reviewed text.] List the lawful bases under GDPR Art. 6 — performance of contract, legitimate interest, consent, and legal obligation — and tie each category above to the basis it relies on.

If you operate in regulated industries, additional bases may apply per local regulation.

3. How we share data

[Replace with attorney-reviewed text.] Identify sub-processors (cloud hosting, payment processors, observability vendors, analytics), the type of data shared with each, and the safeguards in place (DPAs, SCCs, encryption in transit and at rest).

A current list of sub-processors is maintained at /security/sub-processors and updated whenever a new vendor joins the stack.

4. Retention

[Replace with attorney-reviewed text.] State the default retention windows per data category, the conditions under which we hold data longer (legal hold, fraud investigation), and the deletion guarantees when a contract ends.

5. Your rights

[Replace with attorney-reviewed text.] Describe the GDPR data-subject rights (access, rectification, erasure, restriction, portability, objection) and how individuals exercise them. Include the contact channel and the timeline you commit to.

6. International data transfers

[Replace with attorney-reviewed text.] Cover where data is stored and processed, the Standard Contractual Clauses or adequacy decisions you rely on for transfers out of the EEA, and any supplementary measures.

7. Security

[Replace with attorney-reviewed text.] Summarize the controls (encryption, access control, audit logging, vulnerability management, incident response) and reference /security for the detailed control inventory.

8. Changes to this policy

[Replace with attorney-reviewed text.] Describe how you notify users of material changes (in-product banner, email to account owners) and how the version history is maintained.

Last updated:

Privacy questions?

Reach our Data Protection Officer for any access, deletion, or processing inquiries — replies within five business days.