Collecting payments on behalf of a third party
Collecting on behalf of third parties means that a platform receives the price a buyer pays for the benefit of a seller outside the platform. The platform holds the funds in its own accounts, keeps its commission, and pays the balance out to the seller. The money sits there for anywhere from a few hours to a few weeks, depending on the payout schedule. During that window, the platform holds money it does not own. Every jurisdiction that has legislated on payments treats this as a regulated activity, separate from running an online store.
| Jurisdiction | Legal classification | Legal basis | What triggers the requirement |
|---|---|---|---|
| European Union | Payment service: acquiring transactions, executing credit transfers | Directive (EU) 2015/2366 (PSD2) | Receiving funds intended for a third party, unless the commercial agent exemption in Article 3(b) applies. The exemption is read narrowly: the agent must act for the seller or the buyer, never both |
| United States | Money transmission, licensed state by state | CSBS model law, Money Transmission Modernization Act | Any holding of third-party funds, unless the agent-of-the-payee exemption applies (section 3.01(b)): a written agreement, the seller publicly holding the agent out as collecting on its behalf, and discharge of the buyer's debt |
| India | Payment aggregator (PA-O online, PA-P in-person, PA-CB cross-border) | RBI (Regulation of Payment Aggregators) Directions, 2025, published September 15, 2025 | Collecting funds on behalf of merchants. After June 30, 2021, marketplaces could no longer do this without separating it from their commerce business and getting the entity authorized (RBI, 2020 guidelines) |
| Brazil | Instituição de pagamento (payment institution), including sub-acquiring | Lei nº 12.865, de 9 de outubro de 2013 | Holding balances in a conta de pagamento (payment account), which Article 12 makes a pool of assets separate from the institution's own |
| Singapore | Standard or Major Payment Institution | Payment Services Act 2019 | Crossing the section 6(5) thresholds: S$3 million a month in transactions for one service, S$6 million across two or more, or S$5 million in e-money outstanding (MAS, guidelines PS-G01) |
| Nigeria | Only Mobile Money Operators and Payment Service Banks may hold funds | CBN circular of December 9, 2020 | No other license category may hold a customer balance. The others work on a pass-through basis, using an account at a partner bank |
- Who is the buyer's creditor? If it is the platform, the platform sells in its own name and an entirely different regime applies. If it is the seller, the platform is collecting for someone else.
- Who has authority to give instructions on the account holding the funds? The answer is in the bank mandate, not the commercial contract.
- What happens if the platform files for bankruptcy on a Tuesday morning? In a sound structure, sellers' funds stay out of the bankruptcy estate, because they were never on the balance sheet.
Collecting on behalf of third parties without a license is not a paperwork lapse. It is the unauthorized conduct of a regulated activity, a criminal offense in most jurisdictions. Account-holding banks end the relationship as soon as they discover the arrangement. For a platform that is already live, getting compliant then costs twice: once to rebuild the collection flow, and again to migrate the sellers already onboarded.
Four possible structures, and what each one shifts
A platform's structure is the legal position it takes between the third-party seller and the buyer when a payment is collected. Four structures are in use. The platform can sell in its own name, rely on an agency exemption, partner with a licensed platform payments provider, or apply for its own license. Most platforms use just one of them: partnering with a licensed provider. The options differ in time to launch, in cost, and in the exposure they create. They also shift different things: the payment license, tax liability, chargeback risk, and the customer relationship.
| Merchant of record | Seller's agent | Platform payments provider | Own license | |
|---|---|---|---|---|
| Seller under the contract | the platform | the third-party seller | the third-party seller | the third-party seller |
| Payment license | none | exemption, must be demonstrated | held by the provider | held by the platform |
| Liable for sales tax or VAT | the platform | the seller, unless deemed-supplier rules apply | the seller, unless deemed-supplier rules apply | the seller, unless deemed-supplier rules apply |
| Chargebacks and card disputes | the platform | negotiated | charged to the seller's account, guaranteed by the platform | the platform |
| Revenue recognized | gross amount | commission | commission | commission |
| Time to set up | immediate on the payments side | short, but fragile | a few weeks | several quarters |
Safeguarding: one goal, six mechanisms
Safeguarding is how an institution ring-fences third-party funds from its own assets. It differs from regulatory capital, which absorbs operating losses but does not protect sellers' money. The goal is the same everywhere: if the institution fails, sellers' funds remain available to be returned to their owners. The rules, however, vary from country to country, and they dictate the treasury architecture of any group operating in several markets.
| Jurisdiction | Mechanism | What to check |
|---|---|---|
| European Economic Area | Either segregation in a dedicated account at a credit institution, or investment in secure, liquid assets; or an equivalent insurance policy or guarantee | Who has signing authority over the safeguarding account, and which group entity employs that person |
| UK | Regulation 23 of the Payment Services Regulations 2017 and regulation 20 of the Electronic Money Regulations 2011, supplemented by chapter CASS 15 of the FCA Handbook: a segregated trust account, or comparable insurance or a guarantee | The obligation arises as soon as the institution is entitled to receive the funds. Small payment institutions are exempt, and their status can be checked on the FCA register (source: FCA, safeguarding requirements for EMIs and PIs) |
| United States | Permissible investments whose market value, calculated under US GAAP, never falls below total outstanding money transmission obligations. In insolvency, these assets are deemed held in trust for the benefit of the holders of those obligations | The list of permissible investments varies from state to state, as does the basis for the surety bond (CSBS, Money Transmission Modernization Act, sections 10.01 to 10.03) |
| Brazil | No safeguarding account: Article 12 of Lei nº 12.865/2013 provides that funds in a conta de pagamento form a patrimônio separado (segregated estate) that cannot be seized, pledged, or included in bankruptcy assets | How much is actually held in cash at the central bank or in federal government securities, and how liquid it is in a run |
| India | An escrow account at a Scheduled Commercial Bank, funded on Tp+0 or Tp+1, with no other flows allowed | The auditor's quarterly certificate on how the escrow operates, which serves as enforceable evidence (RBI, payment aggregator guidelines) |
| Singapore | A trust account at a safeguarding institution, never commingled with the licensee's own funds | The threshold for becoming a Major Payment Institution, which triggers the requirement (MAS, Payment Services Act 2019 and guidelines PS-G01) |
- Daily reconciliation: total seller balances must equal the safeguarded balance, every day. An unexplained difference is a compliance incident, not an accounting glitch.
- Deposit deadline: most regimes require funds to reach the protected account no later than the end of the business day after receipt. Delays are measured, documented, and penalized.
- Platform commission: it cannot stay commingled with safeguarded funds. The deduction must be identifiable, dated, and moved out of the account.
- Account-holding bank: safeguarding protects against the failure of the payment institution, not the failure of the bank holding the account. Splitting funds across two banks is a treasury decision, not a compliance one.
ORD-2026-84512 cart EUR 120.00 platform commission 12.5%
D+0 card payment collected +120.00 safeguarded account
- seller A (sneakers) +72.00 seller A balance
- seller B (accessories) +33.00 seller B balance
- platform commission +15.00 platform balance
check: 72 + 33 + 15 = 120.00 -> OK
D+2 seller A delivery confirmed
D+3 payout to seller A -72.00 to verified IBAN
D+9 partial refund, seller B -12.00 seller B balance: 33 -> 21
commission reversed -1.50 platform balance: 15 -> 13.50
D+10 payout to seller B -21.00 to verified IBAN
D+70 chargeback, seller A share -72.00 seller A balance: 0 -> -72.00
-> amount owed by the seller, to recover from future sales
-> if the seller stops selling: loss borne by the platform
or the provider, depending on liability settingsStripe Connect and Adyen for Platforms: two ways to scale platform payments
Stripe Connect and Adyen for Platforms are infrastructure products for platforms that collect payments on behalf of third-party sellers. Their data models differ. Stripe exposes connected accounts and charge types, while Adyen exposes a balance platform made up of account holders and balance accounts. The choice determines which entity holds a seller's balance, where a negative balance is charged, and how much development has to be redone if the platform switches providers.
Stripe Connect
A connected account is the object Stripe uses to represent a seller on a platform, and the platform creates one for each seller. Three settings then shape the rest of the integration: how the seller is onboarded, which dashboard the seller can access, and who is liable for negative balances. New integrations use the Accounts v2 API. Stripe offers three charge types, and the choice among them depends more on what is being sold than on the accounting treatment.
- Direct charges: the payment is collected directly on the connected account, and the platform takes an application fee. The customer transacts with the seller, often without knowing the platform exists. This is the model for commerce software.
- Destination charges: the payment is created on the platform's account, then immediately transferred to the designated connected account. The customer transacts with the platform. This is the model for services marketplaces.
- Separate charges and transfers: the charge is decoupled from the transfers, so a payment can be split among several sellers, or collected before the recipient is known. It is more flexible but heavier to operate: the platform has to monitor its own available balance.
- Negative balance liability: either the platform, which then handles risk monitoring and remediation flows, or Stripe, which handles risk signals and recovery. The second option requires integrating the embedded components for onboarding, account management, and notification banners.
- Regional constraint: unless the account is eligible for cross-border payouts, the platform and the connected account must be in the same region for destination charges or separate transfers. Any attempt outside that scope returns an error.
Account object, which means onboarding the seller again and rerunning verification. The choice of who is liable for negative balances commits the organization as much as the code, because it determines who builds risk monitoring and who deals with the seller when fraud occurs. Both decisions are made before the first line of integration code is written, with the risk and compliance teams involved (source: Stripe Connect documentation).Adyen for Platforms
Adyen exposes a balance platform populated by account holders. Each account holder has one or more balance accounts and transfer instruments for moving money out. Payments are divided using splits, and business lines describe what the seller sells. Adyen onboards and verifies users, notifies the platform of the result, and blocks payouts until verification is complete. The platform remains the seller's point of contact. Because Adyen is licensed as a bank in the Netherlands, it holds seller balances without relying on a third-party bank.
| Company | License | Best fit |
|---|---|---|
| Stripe Connect | E-money institution licensed in Ireland | Software platforms and the on-demand economy; highly automated seller onboarding, hosted in more than 46 countries and 14 languages |
| Adyen for Platforms | Dutch banking license (Adyen N.V.) | Large international platforms; in-house acquiring and omnichannel; balance accounts held on Adyen's own books |
| Mangopay | E-money institution licensed in Luxembourg | European consumer-to-consumer marketplaces; white-label wallet |
| Lemonway | Payment institution licensed in France | B2B marketplaces, crowdfunding, regulated platforms |
| PayPal Commerce Platform | Banking license in Luxembourg | Mid-size marketplaces that tap into PayPal's buyer network |
| Mercado Pago | Payment institution operating in Argentina, Brazil, Mexico, Chile, Colombia, Peru, and Uruguay | Latin America; unusual in being a wallet, an acquirer, a lender, and a marketplace at the same time |
Seller KYB: three overlapping obligations
Seller KYB is the verification of a business seller by the marketplace and by the institution holding the funds. It serves three distinct obligations, which come from three branches of law and are rarely handled by the same team. Anti-money laundering rules require identifying whoever receives the funds. Digital platform law requires tracing business sellers who sell remotely. Tax law requires collecting a national tax ID before any income is reported. The data these three regimes require overlaps by 80%. Their compliance deadlines, however, do not line up.
| Regime | What it requires from the seller | Who is responsible | Penalty for non-compliance |
|---|---|---|---|
| AML/CFT due diligence | Identity of the legal representative, existence of the legal entity, beneficial owners, sanctions and politically exposed person screening, transaction monitoring | The licensed institution holding the funds | Payouts blocked; repeated failures lead to supervisory sanctions against the institution |
| Trader traceability | Name, address, phone, email, ID document, payment account details, trade register number, self-certification of compliance | The platform, under Article 30 of Regulation (EU) 2022/2065 (DSA), which has applied to all platforms since February 17, 2024 | The trader may not be allowed to use the service; suspension is required if the data is unreliable |
| Tax data collection | Tax identification number, country of residence, business identifier, financial account number used for payouts | The platform, as the reporting platform operator | Non-compliant seller blocked: reporting regimes require closing or freezing the account of a seller who does not provide the information |
- Payout account changed just before a large payout: a sign that the seller account has been taken over. Apply a cooling-off period.
- Self-purchasing: the seller buys its own listings with stolen cards to turn fraud into a clean bank transfer. Matching buyer and seller data (address, device, card fingerprint) catches it.
- Triangulation fraud: the seller takes a legitimate order and fulfills it with a fraudulent purchase elsewhere. The chargeback lands on the third party, and the reputational damage on the platform.
- Reactivated dormant seller: an account verified three years ago that went inactive and suddenly shows heavy activity in a different category. Due diligence doesn't stop at onboarding.
- Pre-verification build-up: balances grow in the name of sellers who never finished onboarding. Capping collections before full verification prevents orphaned balances that can't be returned.
The platform as an arm of the tax authority
Tax law imposes two separate obligations on platforms. They are often confused, and they draw on different data and different teams. The first is a reporting obligation: the platform must tell the tax authority how much each seller earned. The second is substantive: the platform itself becomes liable for sales tax in place of the seller. The reporting obligation produces an annual filing. The substantive obligation changes the invoice issued, the price shown to the buyer, and the amount paid out to the seller.
| Regime | Reach | Exclusion threshold | Deadline |
|---|---|---|---|
| DAC7, Directive (EU) 2021/514 | Sales of goods, personal services, rental of real estate, rental of any means of transport | Sellers of goods: fewer than 30 sales and €2,000 or less in the year | January 31 after the calendar year; first reports filed in January 2024 |
| Platform Operators (Due Diligence and Reporting Requirements) Regulations 2023, UK | Same OECD model rules, transposed into UK law | Fewer than 30 sales and €2,000 (about £1,700), for goods only: not for services, vehicle rental, or property rental | January 31 after the calendar year, to HMRC (source: gov.uk) |
| Sharing Economy Reporting Regime, Australia | Services: passenger transport, short-term accommodation, asset rental, food delivery, digital goods. Sales of goods are not covered | No de minimis threshold | Twice a year, to the ATO: January 31 for July–December, and July 31 for January–June. In effect since July 1, 2023 |
| Form 1099-K, US | Gross receipts, not income. Card payments are still reported with no threshold at all | More than $20,000 and more than 200 transactions per payee, a threshold retroactively restored by the 2025 One, Big, Beautiful Bill | Annual IRS calendar (source: Internal Revenue Service) |
- Collect the tax ID at onboarding, not in December. A seller chased 11 months later won't respond.
- Reconcile reported amounts with payouts: the tax authority compares the reported amount with the seller's bank flows. An unexplained gap triggers an audit, and the seller turns to the platform.
- Separate gross amounts, commissions, and refunds: regimes don't all use the same basis, and a single aggregate for all of them produces an incorrect return in half the countries.
- Plan for blocking: the account of a seller who refuses to provide information must be freezable, with a reminder sequence and a timestamped audit trail.
Paying out in 20 countries is a separate discipline
A payout is the transfer of a seller's sales proceeds, net of commission, from the platform to the seller. It runs on a different chain from collection, with its own rails, licenses, and cost structure. A platform that sells in one country and pays sellers in 15 others therefore faces a distribution problem, not a payment problem. The payout rail is almost always domestic, addressed by a local identifier, and bound by local operating hours. Currency conversion happens before the payment enters the rail, not while the transfer executes.
| Market | Payout rail | Operator, launch year | What matters for a platform |
|---|---|---|---|
| Euro area | SEPA Instant Credit Transfer (SCT Inst) | European Payments Council, 2017 | Sending mandatory since October 9, 2025, at the same price as a standard credit transfer, with payee name verification |
| United Kingdom | Faster Payments Service (FPS) | Pay.UK, operated by Vocalink, 2008 | 5.55 billion payments in 2025 (Pay.UK, Annual Summary of Payment Statistics 2025); the backbone of every UK payout |
| United States | RTP network and FedNow Service | The Clearing House, 2017; Federal Reserve Banks, 2023 | Bank participation is optional, so an ACH fallback is still required. RTP limit raised to $10 million in 2025 |
| Brazil | Pix | Banco Central do Brasil, 2020 | Addressed by a chave (key) linked to the CPF or CNPJ, so the identity is verifiable. 79.8 billion transactions in 2025 (BCB) |
| Mexico | SPEI | Banco de México, 2004 | Operated by the central bank; open to nonbanks since the Ley Fintech. More than 7.3 billion transfers in 2025 (Banxico) |
| India | UPI | National Payments Corporation of India, 2016 | Standard limit of ₹1 lakh (₹100,000) per transaction, higher for certain categories (NPCI, UPI FAQ) |
| Thailand | PromptPay | National ITMX, under a Bank of Thailand mandate, 2017 | Addressed by mobile number, national ID number, or corporate tax ID; free below a limit |
| Malaysia | DuitNow (Real-time Retail Payments Platform) | Payments Network Malaysia (PayNet), 2018 | Alias addressing, including by business registration number, which helps tell individual sellers from business sellers |
| Singapore | PayNow | Association of Banks in Singapore, operated by BCS, 2017 | Businesses addressed by UEN (Unique Entity Number); open to nonbank institutions |
| Indonesia | BI-FAST | Bank Indonesia, 2021 | Fee capped at Rp2,500 per transaction. Not to be confused with QRIS, which is used to collect payments, not to pay out |
| Australia | New Payments Platform, addressed by PayID | NPP Australia, a subsidiary of Australian Payments Plus, 2018 | The account holder's name is displayed before confirmation: built-in payee verification |
| Canada | Interac e-Transfer | Interac Corp., 2002 | Finality is slower than the user experience suggests: settlement is deferred through ACSS, not real-time |
| Japan | Zengin System | Zengin-Net, 1973 | Available 24/7 since the Zengin More Time System; transfers of ¥100 million or more move to RTGS on BOJ-NET |
- Instant rails have no chargebacks. On Pix, UPI, PromptPay, DuitNow, BI-FAST, or PayNow, the transfer is final. Paying out too early means giving up any chance of recovery.
- The FX decision is made before the rail, and its cost shows in the spread over the reference rate, not in the posted fee. Paying out in local currency is almost always cheaper for sellers than leaving them to convert.
- Local operating hours drive treasury: a 24/7 rail on the seller's side is useless if the funding account is topped up on a business-day calendar.
- Paying a seller in a country where you hold no license is a licensing question, not an engineering one. The payout provider has to prove it holds its own license, country by country.
- Trigger thresholds are local: amounts, frequency, and recipient categories can tip a flow from a simple regime into a money transmission regime.
What breaks in day-to-day operations
Marketplace operating incidents follow the same pattern from one country to the next. They stem from the gap between the moment funds go out to the seller and the moment the risk attached to the order expires. The chosen regulatory structure doesn't close that gap. It only determines who ultimately bears the loss. Three situations come up in nearly every operating review, and the most expensive is a chargeback received after the payout.
- Orphaned balances: funds held for sellers who were never verified, which can neither be paid out nor kept indefinitely. Unclaimed property has its own rules, which differ by jurisdiction, and they apply even when individual amounts are trivial.
- Refund after payout: the commission has been taken, the seller has been paid, and the buyer is entitled to a refund. The marketplace agreement must specify, before any incident, who advances the funds.
- A broken link in the chain: the licensed provider loses its license, its account-holding bank ends the relationship, or its own partner stops providing service. The funds are protected; the service is not. A backup collection chain tested twice a year is worth more than a written continuity plan.
- Out-of-sync ledgers: the platform's internal balance diverges from the provider's. This symptom precedes almost every serious incident, and it is caught by automated daily reconciliation, not by an annual audit.
- Multi-account sellers: the same beneficial owner behind several seller accounts, to get around a limit, a freeze, or a ban. Matching by beneficial owner and by payout account exposes it.