The challenge
An e-commerce and distribution business in Thailand ran an online marketplace that sold from its own warehouse stock. It wanted partner shops to sell through the same platform, which meant adding a multi-vendor marketplace seller portal to what it already had.
Each shop needed its own users, items, stock and orders, without seeing or touching the rest of the catalog. At the same time, the marketplace had to stay in charge. Staff needed to vet every shop with its Thai business and ID numbers, decide which categories it could sell in, and switch it on or off.
Some data also had to stay private. Fields that matter only to the marketplace, such as cost price and markup, could not be shown to shops.
What we built: a multi-vendor marketplace seller portal
We added a shop layer to the existing platform, with two sides that share one set of records.
The admin side. Staff register each shop with its 13-digit business ID and Thai ID, its contacts, the full Thai address down to sub-district and postcode, GPS coordinates and up to five attachments. From there, admins:
allocate the categories each shop may sell in;
allow or block loyalty points for that shop;
send login details to shop users, and activate or deactivate shops;
link items, view orders across shops and keep the list of courier partners up to date.
The shop side. Each partner logs in to manage its own users, items and stock. New items get the shop's SKU prefix automatically.
Shops record incoming stock in bulk, with date, allocation type, quantity and notes, and they import or export their items and images. They see only their own customer orders, and they fulfill them.
The portal runs on MongoDB on an Ubuntu cloud server.
How it works day to day
Take a marketplace admin onboarding a new partner. They enter the shop's business ID, Thai ID and address, pin its GPS location and attach its documents. They choose the categories it may sell in and decide whether it takes part in the loyalty points scheme. Only then do they send the shop its login details and switch it on.
On the shop's side, a staff member uploads the catalog in one import, and every new item carries the shop's own SKU prefix, so its codes never clash with another seller's. When a delivery arrives, they record the stock inwards in bulk rather than item by item.
When a customer orders, the shop sees that order in its own list and fulfills it. It never sees other shops' orders, or the marketplace's cost and markup fields. The admin, meanwhile, can view orders across every shop.
The result
Partner shops now run their own catalog, stock and orders inside the marketplace, without seeing each other's data. Admins control which shops are live and what they can list. Because each shop stores GPS coordinates, search can show products from the nearest shop.
Shops and their orders are linked in the business's warehouse management system, and its shopping app lets admins issue coupons tied to a single partner shop.
What the research says
Access control is the top web risk. The OWASP Top 10:2025 keeps broken access control at number one: 100% of the applications tested had some form of it. OWASP advises denying access by default and enforcing record ownership on the server (OWASP Top 10:2025, A01). That is how each shop sees only its own items, stock and orders, and never the cost and markup fields.
Thai shoppers browse on phones. Statcounter measured 78.38% of web traffic in Thailand coming from mobile devices in September 2026, against 18.31% from desktops (Statcounter Global Stats). With most browsing done on the move, each shop's stored GPS point is what lets search show products from the nearest one.
Where AI fits next
No AI is involved yet. If the marketplace adds it, these are the obvious places. A model could check new shop registrations against their uploaded documents and flag mismatches for an admin. It could suggest categories and tidy item descriptions when a shop bulk-uploads its catalog, and flag slow-moving stock in each shop with a suggested promotion.
Planning something similar?
Before you open your marketplace to other sellers, it helps to answer four questions:
What must a seller prove before going live, and who checks it?
Which fields, such as cost and markup, must sellers never see?
Will sellers manage their own stock, or sell from yours, or both?
Which promotions, such as loyalty points or shop coupons, should each seller be allowed to join?
Deciding whether a packaged marketplace plugin will do? Our build-or-buy comparison lays out the trade-offs. See also how we plan web application projects, our wider e-commerce portfolio, and the delivery system and driver app this marketplace started with.



