Data & Security

Who Owns Your Customer List? Questions for Any Ordering Platform

Customer data ownership on ordering platforms: what to check in the contract, how exports work, and what happens to your orders and customers when you leave.

By the Inlay team · · 4 min read

Your customer list should belong to you, in writing, with a way to take all of it out whenever you want. Customer data ownership on an ordering platform comes down to three things: what the contract says, what the export actually contains, and what the vendor does with the data after you leave. This post gives you the questions to ask.

Why customer data ownership matters in custom home products

A custom manufacturer's customer list is worth more than most retailers'. Each record can hold a homeowner's address, room measurements, finish choices, past orders and saved quotes. Dealer records hold price tiers, credit terms and order history going back years.

That data drives repeat business. A homeowner who ordered kitchen doors may come back for a vanity or closet. A dealer's order history is the basis for every price conversation you have with them. If the data is hard to get out, switching software means starting that history from zero.

There is also a legal angle. In Canada, the business that collects personal information is generally accountable for it, including when a third party processes it on its behalf. We cover that in PIPEDA and Quebec Law 25.

Read the contract for these clauses

Ownership is decided in the terms of service and any data processing agreement. Marketing pages carry no weight if the contract says otherwise. Look for:

  • An ownership statement. A plain sentence saying your customer and order data belongs to you.
  • Licence scope. The vendor needs a licence to host and process your data to run the service. Check whether that licence extends to anything else, such as product analytics, benchmarking or marketing.
  • Use of aggregated data. Some vendors reserve the right to use anonymized or aggregated data. Decide whether you are comfortable with that.
  • Marketing to your customers. The contract should rule out the vendor contacting your customers for its own purposes.
  • Deletion after cancellation. A specific timeframe, in days, for deleting your data once you leave.
  • Subprocessors. A list of the other companies that touch your data (hosting, email delivery, payments).

If any of these are missing or vague, ask for clarification in writing before you sign.

Test the export before you need it

A right to export is only useful if the export is complete. During a trial or demo, ask to see a real export and check it against this list:

Data type What a useful export includes
Customers Name, email, phone, addresses, account creation date
Orders Line items with every option chosen, sizes, prices, tax, status
Quotes Saved and abandoned quotes, not only completed orders
Dealers Account details, price tier, terms, order history
Payments Deposit and balance records, or a clear link to your processor's records
Emails Which automated emails went to which customer

Then ask how often you can export, in what formats, and whether there is a charge. A CSV you can open in a spreadsheet and an API your developer can pull from regularly are both good signs. A one-time export available only on request is weaker.

Payment data is a separate question

Card details should never be part of the ordering platform's data at all. When card numbers are entered into a payment processor's secure fields, the platform never stores them. Payment records then live in your processor account. If payments run through your own Stripe account, you keep that history whatever software you use. See why payouts should land in your own Stripe account.

Where and how the data is stored

Ownership and security go together. Ask:

  1. Which country hosts the data? Some businesses and customers prefer Canadian hosting.
  2. Is your data stored in its own database, or in a shared database with other companies' records?
  3. Is it encrypted at rest and in transit, and to what standard?
  4. Who at the vendor can access it, and is that access logged?

Shared versus isolated storage is worth understanding before you compare vendors. Our post on isolated customer data explains the difference.

The questions, in one list

Send these to any ordering platform before you sign:

  1. Do we own our customer, order, quote and dealer data?
  2. What licence do you take to our data, and for what purposes?
  3. Do you ever sell our data or market to our customers?
  4. Can we export everything, at any time, in CSV and by API, at no extra cost?
  5. Which country is our data hosted in, and can we choose?
  6. Is our data stored separately from other customers' data?
  7. How is it encrypted?
  8. Within how many days of cancellation is our data deleted?

Keep the answers with the contract. If a vendor will not answer in writing, treat that as an answer.

How Inlay handles this

  • Each company owns its customer data and can export everything at any time, by CSV or API.
  • Inlay never sells your data or markets to your customers.
  • Each company's orders live in a separate encrypted database, with AES-256 encryption at rest and TLS 1.2 or higher in transit.
  • Data is deleted within 30 days of cancellation, and you can choose Canadian or US hosting.
  • Card numbers are entered in Stripe's secure fields and never touch Inlay's servers.

Book a 20-minute demo and ask us to show you a full export.

See it on your own site

Send us your website and one product line.

We'll build a themed demo of your checkout and dealer portal and walk you through it on a 20-minute call.

Book a 20-minute demo