Agency mandate disclosure
The legal and payment model behind every approval in FishSmash.
Who is who
- You are the buyer and cardholder in every transaction.
- The retailer you select is the seller, the merchant of record, the recipient of payment and the issuer of the invoice and consumer guarantee.
- Notsu OÜ, operating FishSmash, is your disclosed customer-side purchasing, checkout-orchestration, logistics and order-management agent. Notsu OÜ is never a reseller, seller, merchant of record or recipient of the product value.
What you approve
- Before any approval you see the exact products, SKUs, variants, quantities, the named retailer as seller and payee, item prices, shipping, a tax indication, the total and currency, the delivery estimate and the delivery address reference.
- For each retailer you set the substitution scope (no substitutions by default), the maximum authorised amount and the authorization expiry.
- A review screen may contain several merchants, but approval, payment authorization and the resulting transaction are always separate per retailer.
Payment handling
- FishSmash never collects, stores or relays a raw card number (PAN), CVC, expiry date, retailer password or any retailer credential.
- A future connected payment method is vaulted by a licensed payment provider or card network. FishSmash stores only opaque provider references and receives only short-lived payment authorization references scoped to a specific retailer, amount and time window.
- Strong customer authentication (3-D Secure) belongs to the retailer-specific payment flow, not to FishSmash.
- Supported provider-neutral modes: agentic or delegated token checkout, retailer API and connected-merchant checkout, and retailer-hosted checkout redirect as a fallback.
- Any affiliate or application fee is merchant-funded and disclosed where applicable. It is never deducted from customer funds and never influences organic ranking.
Order creation
- Your approval creates a purchase intent, not an order. Intent statuses are: draft, awaiting_user_approval, user_approved, payment_authorization_required, payment_authorized, submitted_to_retailer, retailer_confirmed, retailer_rejected, expired, canceled and failed.
- A product order record is created only after a real retailer adapter confirms the retailer's own merchant order reference and seller identity.
- The automated retailer adapter is disconnected. Flows stop at payment_authorization_required with an adapter_unavailable result. No charge, paid state or merchant order is ever simulated.
Ranking and trust
- Offers are ranked on product compatibility, total delivered cost, seller trust, delivery and returns. Affiliate commission is never an organic ranking input.
- Retailer trust combines business identity, secure checkout, returns policy, domain and business history, price anomaly detection, delivery evidence and customer-service signals.
- Offers from untrusted or unsafe sellers are disabled and the triggering risk signal is shown. Trust scoring reduces exposure to known risk signals; it cannot eliminate fraud completely.
Fishing rules
- Seasons, permits, size limits and protected-species rules change and vary by water. Always verify against a current official source before fishing.
