Storeborn Partner Agreement (partneravtal)
Senast uppdaterad: 2026-08-07
Parter och accept
Avtalet ingås på engelska och återges nedan i sin helhet på engelska. Vid frågor om innehållet, kontakta oss innan du skickar in din ansökan.
This Partner Agreement (the “Agreement”) is entered into between Storeborn (the “Platform”) and the company submitting a partner application (the “Partner”). The Agreement is accepted by ticking the acceptance checkbox in the partner application form; the accepted version and timestamp are recorded. The Agreement takes effect for the Partner when the Platform approves the application.
It includes the data-processing terms (section 4) under which the Partner processes personal data as a sub-processor when accessing merchant stores.
1. The Partner Program
1.1 The Partner is an independent company (typically a web agency or reseller) that refers merchants to the Platform and may assist those merchants with building and operating their stores.
1.2 Approval of a partner application is at the Platform’s discretion. The Platform assigns the Partner’s public identifier (slug) at approval.
1.3 The Partner acts in its own name and is not an agent, franchisee or employee of the Platform. The Partner may not make commitments on the Platform’s behalf.
2. Partner portal and user accounts
2.1 The Platform provides a partner portal in which named users (“Partner Users”) invited by the Partner’s owner account can view the Partner’s referred merchants, revenue statistics scoped to those merchants, commission statements, and — where enabled — support tickets and announcements.
2.2 The Partner is responsible for all activity under its Partner Users’ accounts and for revoking access for personnel who leave the Partner. Each Partner User account is personal and may not be shared.
3. Security
3.1 Two-factor authentication is technically enforced for Partner Users with the owner or admin role. The Partner shall contractually require two-factor authentication also for its member and readonly Partner Users, since those roles can read support conversations that may contain personal data.
3.2 The Partner shall protect all credentials, keep them confidential, and use reasonable organisational and technical measures (updated systems, malware protection, access control on Partner devices) when accessing the Platform.
3.3 The Partner shall notify the Platform within 24 hours of discovering any compromise (or suspected compromise) of a Partner User’s credentials or any unauthorised access to the partner portal or a merchant store reached through it, via the Platform’s support channel.
4. Data processing (sub-processor terms)
4.1 For data in merchant stores, the merchant is the controller of its end customers’ personal data and the Platform is the merchant’s processor under the Platform’s Terms of Service. When the Partner accesses merchant store data through the partner portal or through impersonation (section 5), the Partner processes such personal data as a sub-processor of the Platform (Art. 28(4) GDPR). This section flows the Platform’s processor obligations down to the Partner.
4.2 The Partner shall process merchant and end-customer personal data only on the Platform’s documented instructions, which are: to service, support and administer the specific merchant’s store within the scope of the Partner’s engagement with that merchant, and for no other purpose.
4.3 Purpose limitation. The Partner may use data obtained from the partner portal or from impersonation sessions solely to service that merchant. The following are expressly prohibited:
– marketing to a merchant’s end customers, in any channel;
– exporting, copying or retaining customer lists or other end-customer personal data outside the merchant’s store, except transiently as strictly required to service that merchant;
– using data about one merchant — or aggregate data across merchants — for the Partner’s own benchmarking, analytics, products or commercial purposes.
4.4 Confidentiality. The Partner shall ensure that every Partner User who may access merchant or end-customer data is bound by a confidentiality undertaking (contractual or statutory) covering that data. This obligation survives termination of this Agreement.
4.5 No onward sub-processing. The Partner may not engage any third party (including freelancers and subcontractors) to process merchant or end-customer personal data accessed through the Platform without the Platform’s prior written authorisation. Personnel employed by the Partner and bound under 4.4 are not third parties for this purpose.
4.6 The Partner shall assist the Platform, insofar as reasonably possible, in responding to data-subject requests and supervisory-authority inquiries that concern processing performed by the Partner, and shall notify the Platform without undue delay — and in any case within 24 hours — of any personal data breach involving data processed under this Agreement.
4.7 Upon request, the Partner shall demonstrate compliance with this section and permit audits as required by Art. 28(3)(h) GDPR, conducted with reasonable notice and during normal business hours.
5. Store access (“Log in as merchant”)
5.1 Where enabled, Partner Users with the owner or admin role may open an administrative session in a referred merchant’s store (“impersonation”). The Partner acknowledges and accepts that:
– every impersonation session is logged, and the merchant can see that the Partner has accessed the store;
– actions performed during a session are recorded in the merchant’s audit trail attributed to the Partner;
– the merchant can turn off the Partner’s store access at any time, and the merchant is notified the first time the Partner accesses their store;
– the Partner is liable for all actions taken during its impersonation sessions as if performed by the Partner itself.
5.2 Impersonation may be used only to service the merchant in question and never to create durable access for the Partner (such as inviting the Partner’s own staff as store users) outside the mechanisms the Platform provides.
6. Commission and payouts
6.1 The Partner earns commission on the Platform’s paid revenue from referred merchants: a merchant invoice qualifies for commission only once the merchant has paid it to the Platform. No commission accrues on invoices that are issued but unpaid. Commission is calculated according to the commission plan assigned to the Partner; the current plan, rates and per-row calculation basis are visible in the partner portal.
6.2 Settlement is quarterly: once a quarter is settled and shows a positive net total, the Partner issues an invoice to the Platform through the partner portal. Payment terms are shown in the portal. Commission is reversed symmetrically if the underlying merchant invoice is credited or written off as bad debt.
6.3 The Partner is responsible for its own tax treatment, including VAT declarations on payout invoices.
7. Term, suspension and termination
7.1 The Agreement runs until terminated. Either party may terminate with 30 days’ written notice. The Platform may suspend or terminate the Partner with immediate effect on material breach of this Agreement — including any breach of sections 3–5 — or where required by law.
7.2 On suspension, portal access is disabled; commission accrued before suspension is retained. On termination, accrual stops; commission periods after a later re-activation do not accrue retroactively for the gap.
7.3 Deletion on termination. Upon termination the Partner shall delete all merchant and end-customer personal data in its possession that was obtained through the Platform — expressly including any CSV exports (commission ledger and merchant list exports) and any local copies — except where retention is required by mandatory law, in which case the data remains protected under section 4.4 until deleted.
8. Data-subject assistance
8.1 The Platform will provide reasonable assistance to the Partner and the affected merchant in handling erasure and access requests that touch data the Partner has processed. The Partner shall forward any data-subject request it receives concerning merchant store data to the merchant and the Platform without undue delay and shall not respond on their behalf.
9. Liability
9.1 Each party is liable for its own breach of this Agreement. The Partner indemnifies the Platform against claims, fines and costs arising from the Partner’s processing of personal data in breach of section 4 or from actions taken during impersonation sessions (section 5).
9.2 The Platform’s aggregate liability under this Agreement is capped at the commission paid to the Partner during the twelve months preceding the claim, except in cases of intent or gross negligence.
10. Changes to this Agreement
10.1 The Platform may update this Agreement on reasonable notice. The current version is always published on this page. When a new version is published, the Partner’s owner is asked to accept it at the next portal sign-in; continued use of the partner program requires acceptance of the current version. The accepted version and timestamp are recorded.
11. Governing law and disputes
11.1 This Agreement is governed by Swedish law. Disputes shall be resolved by Swedish courts, with Stockholm District Court as the court of first instance, unless mandatory law provides otherwise.