How does this work legally, are you acting as an agent, proxy or other authorized representative of the customer, when interacting with the vendor?
On the topic of security: is the customer's identity information, e.g. authorization passcodes required by the vendor, deleted from your database after the transaction is complete? You may also want to add some details on encryption.