
Reviews
Part of How to avoid being moved off the marketplace platform mid-sale
Setting spending limits and refusals in a marketplace policy
A marketplace policy skeleton for small teams: who may transact, the spending limits, the refusals that never bend, and what happens after a bad deal.
Most written policies about online selling fail for the same reason: they describe threats instead of assigning authority. A person reading one learns what to be afraid of and still does not know whether they are allowed to accept a bank transfer.
A usable policy answers four questions. Who is allowed to buy or sell on the organization's behalf, up to what value, by which payment methods, and what happens when something goes wrong. Everything else is commentary. This skeleton is written for a small business, a club, a charity shop, or a household that treats itself as one, and it is a starting point rather than legal advice.
What to take away
- Assign authority and limits. A policy that only lists warnings changes nothing.
- The refusals need to be absolute, because a refusal with an exception is the thing that gets attacked.
- Write the after-the-fact section as though somebody made a mistake, because eventually somebody will.
What the policy has to decide
| The decision | Why it belongs in writing | The failure it prevents |
|---|---|---|
| Who may transact | Otherwise everybody assumes somebody senior approved it | A junior person acting on an urgent message |
| Value limits per person | Judgment varies. Numbers do not | A large deal made alone under time pressure |
| Allowed payment methods | The method decides whether a dispute exists | An irreversible payment made to save a fee |
| Absolute refusals | These have to survive a plausible reason | The exception that the next approach aims at |
| Handover rules | Safety decisions are made badly in the moment | An unaccompanied meeting at an address |
| Reporting route | People delay when they do not know who to tell | A loss discovered weeks late |
The skeleton
Scope and owner. Name the accounts and marketplaces this covers, the people it applies to, and one named person who owns it. A policy with no owner is a document, not a control.
Authority. State who may list, who may agree a price, and who may release goods or money. Keep the list short. For anything above a stated value, require a second named person to agree, and say that the second person may be asked at any time without it being an accusation.
Limits. Give a figure above which the deal must use protected checkout or happen in person. Give a second figure above which the deal does not happen at all without the owner. Pick real numbers rather than adjectives.
Payment methods. List the methods that are allowed for receiving and for paying. List the ones that are not, and say plainly that a fee saved is a dispute process given up.
The refusals. Four lines, written as absolutes rather than as guidance.
- Nobody reads out a verification code sent to a phone or an email, for any stated reason.
- Nobody refunds an overpayment except back through the original payment, in full, after it has settled.
- Nobody installs software, grants access, or approves a prompt in order to complete a deal.
- Nobody sends an identity document to a private counterparty.
Handover. Public place, daylight, and a second person for anything above the stated value. Where a home or premises visit is unavoidable, two people, and the address released only after the deal is agreed. Anyone may end a meeting without explaining why, and doing so is never questioned afterwards.
Records. Say what is kept and for how long: the listing, the conversation inside the platform, payment references, tracking, and the counterparty's account name. Say that nothing is deleted or blocked until the record is saved, because blocking often removes access to the conversation.
Reporting. Name the internal person to tell, and say the report is expected within the working day. Add the line that matters more than the rest: nobody is penalized for reporting their own mistake promptly, and the only version of this that causes real damage is the one that stays quiet.
External reporting. Name the routes rather than leaving them to be found in a bad hour. In the US that is the payment provider first, then the platform, then the FTC's fraud report route and, for internet-enabled crime, the Internet Crime Complaint Center.
Review. A date, and a trigger. Review when a marketplace changes its payment or protection arrangements, when a limit stops matching what you actually sell, or after any incident.
Adapting it honestly
Three notes for whoever writes the local version.
Keep it to two pages. Nobody reads the third, and a policy nobody reads is worse than none because it creates the impression of a control.
Write the limits for the organization you are, not the one you plan to be. A charity shop selling donated goods and a business shipping equipment have almost nothing in common except the refusals.
Do not copy the threat descriptions in. They date fast and they are not the part that changes behavior. Point at marketplace scams for the situations and keep the policy to authority, limits, and process.
The training that is worth the time
One short session, repeated when people join, covering three things: the refusals, the limits, and who to tell. That is it.
What does not work is a long briefing about scam types. People remember the feeling of having been warned and forget the specifics, and the specifics are exactly what changes. What sticks is a small number of rules with no judgment in them, which is the same finding as in phishing scams rules 2027.
After an incident
The policy should already say what happens, so that nobody is deciding it while upset.
Money first, then accounts, then the record, then the report. If a code was read out or a password entered, treat it as an account compromise rather than a marketplace problem and work through account security. If identity documents moved, the exposure is applications made in someone's name rather than access to an account, and the follow-up is different again.
Then hold a short review that asks which control was missing rather than who was at fault. A policy that produces blame produces silence, and silence is what makes the next one worse. The recovery sequence itself is in scam reporting and recovery.
Common questions
Is this a legal document?
No. It is an internal control. Anything with contractual or employment consequences should be checked by somebody qualified in your jurisdiction before it is issued.
How small does an organization have to be for this to be overkill?
If more than one person can transact, it is worth writing down. The failure this prevents is two people each assuming the other approved something.
What if a limit blocks a genuine deal?
Then the deal waits for the second person. That is the cost, and it is smaller than the cost of the limit being advisory.
Should the policy name specific scams?
No. Name the refusals instead. Scam descriptions age; a refusal that has no exception does not.
Who should own it in a very small team?
Whoever handles the money. Ownership needs to sit with the person who would notice the loss first.


