A retailer can fund an online store yet remain dependent on a supplier for its domain, payments, product data or recovery. This handover checklist makes operational ownership visible before launch or a change of partner.
Ownership is more than a clause saying the client owns the website. An online store depends on accounts, data, credentials, code, licences, policies and operating knowledge. If those assets sit in a former employee's email or a supplier account, the retailer may be unable to change prices, receive money, restore service or appoint a new partner without delay.
1. Domain and DNS
- The registrant and account belong to the retailer or agreed legal entity.
- At least two current staff members can access the registrar securely.
- Recovery email, phone and multi-factor authentication are controlled.
- Renewal date, payment method and automatic renewal are recorded.
- DNS records and nameserver ownership are documented.
- A change lock and transfer procedure are understood.
ICANN's registrant resources explain domain-holder responsibilities and common account issues. Record the actual registrar and support route because the web agency may not be the registrar.
2. Storefront, hosting and source
List the commerce platform, hosting provider, environments, repositories, deployment process and third-party themes or extensions. Confirm the retailer's rights to use and modify delivered work. Create named business administrators. Document recurring costs, renewal dates, data limits, support contacts and the steps to export or move the store.
3. Payments and settlement
- Merchant accounts are contracted to the correct entity.
- Settlement bank accounts and authorised signatories are verified.
- Production credentials are held in a secret manager, not shared chat.
- Webhook endpoints, signatures and duplicate-event handling are documented.
- Refund, reversal, reconciliation and dispute procedures have owners.
- Test and production accounts are clearly separated.
- Finance can match orders, payment references, fees and settlements.
For Kenyan integrations, use the official Safaricom Daraja portal for M-Pesa API documentation. If card or regional payment processing uses Paystack, its webhook documentation explains signature verification and event delivery. Provider documentation supports the technical setup, but the business still needs a reconciliation and exception process.
4. Product, customer and order data
Identify the source of truth for product identifiers, descriptions, prices, tax treatment, inventory and fulfilment status. Confirm an authorised export includes products, variants, media references, customers, orders, discounts, refunds and fulfilment records in a usable format. Document imports, validation rules and how duplicate or conflicting records are resolved.
5. Customer communications
List the email, SMS and messaging providers, sending domains, templates, consent records and suppression lists. Confirm that the retailer controls sender verification and can continue essential order communication after a supplier change. Separate service messages from marketing permissions, and preserve opt-out records during migration.
6. Analytics and marketing accounts
- Analytics property and tag manager container.
- Search console and merchant listings.
- Advertising accounts and conversion definitions.
- Product feeds and catalogue connections.
- Cookie or consent management configuration.
- Dashboard definitions and raw data access.
- A record of which supplier has which permission.
7. Integrations and automation
Map every connection to accounting, inventory, delivery, CRM, support, analytics and messaging. Record the system owner, direction of data flow, credentials, event identifiers, retry behaviour, failure alert and manual continuity step. Revoke obsolete credentials only after replacement access is tested.
8. Security, privacy and access
Use individual accounts, least privilege and strong authentication. Inventory personal data and where each provider processes it. Record retention, deletion, access-request and incident procedures. Remove former staff and suppliers promptly. Make the Kenyan Data Protection Act part of the legal and operational handover review.
9. Backups, recovery and continuity
Confirm what is backed up, how often, where it is stored and how long it is retained. Restore a representative copy and record the result. Document how orders are captured, customers are informed and payments are reconciled if the storefront or a dependency is unavailable.
10. Acceptance and final handover
| Evidence | Acceptance test |
|---|---|
| Account register | Retailer signs in and confirms recovery methods |
| Credential transfer | Production secrets rotate without service loss |
| Data export | Retailer opens and checks a current export |
| Runbook | Staff complete a common change and an exception |
| Recovery test | Store or data is restored in an isolated environment |
| Payment test | Order, payment, settlement and refund reconcile |
| Access review | Old and excessive permissions are removed |
| Support plan | Named contacts, hours, severity and escalation are clear |
Avidni's e-commerce service includes account ownership, payment-state design, operating documentation and handover as part of the store, not as an afterthought.
Plan an Owned Online Store