MyDealList · Guides
The Ultimate Checklist for Transferring Stripe, Domain & AWS After a SaaS Sale
Post-acquisition handover checklist for Stripe, domains, DNS, AWS, repos, and customer data. A step-by-step playbook so nothing critical stays in the seller’s accounts.
Escrow releasing funds is not the finish line. The finish line is you controlling billing, DNS, hosting, source code, and customer data—with the seller locked out of production.
Miss one transfer and you can lose revenue (Stripe), traffic (DNS), or the product itself (repo + cloud). Use this playbook before, during, and after close.
Pair with Post-Acquisition: First 90 Days and Asset Migration Protocol. Browse deals on the feed.
Before Close: Lock the Transfer Plan into the APA
Your asset purchase agreement (or bill of sale) should list every account and asset:
- Legal entity / DBA and product name
- Domains and registrars
- Stripe (or Paddle/Lemon Squeezy) account IDs
- Cloud accounts (AWS, GCP, Azure, Vercel, Railway, Render, Fly)
- GitHub/GitLab/Bitbucket orgs and repos
- Email (Google Workspace / Microsoft 365)
- Analytics, error tracking, support desks, CDN, DNS
- Customer databases and backup locations
- App store listings, Chrome Web Store, API keys, third-party OAuth apps
- Social handles and brand assets
Phase 1: Identity, Email & Access Hygiene (Day 0–1)
- Create your own password manager vault for the acquisition.
- Stand up buyer-owned email (e.g. [email protected]) before transfers.
- Inventory every login the seller uses—shared spreadsheets lie; ask for export of password manager entries + SSO list.
- Enable MFA everywhere under your phone/hardware keys.
- Revoke unknown OAuth apps and old contractor access after cutover.
Phase 2: Domain, DNS & Email (Highest Traffic Risk)
Domains
- Initiate registrar transfer or push to your account (Namecheap, Cloudflare Registrar, Google Domains successor, etc.).
- Unlock domain, obtain auth/EPP code, disable privacy blockers that stall transfer.
- Confirm WHOIS contact updates after transfer completes.
DNS
- Prefer moving DNS to Cloudflare (or your standard) only after documenting every record: A, AAAA, CNAME, MX, TXT (SPF/DKIM/DMARC), and verification records.
- Lower TTLs 24–48 hours before cutover.
- Keep seller DNS read-only until you verify mail + app health.
- Migrate Google Workspace / Microsoft 365 tenants or recreate mailboxes.
- Re-publish SPF, DKIM, DMARC for transactional senders (Postmark, SES, Resend, Mailgun).
- Send a test sequence: signup confirmation, password reset, invoice receipt.
Phase 3: Stripe (or Payment Provider) Transfer
Stripe does not “magically” move with the company in every structure. Plan the path:
Option A: Keep the Stripe account (asset deal with account transfer)
- Stripe account ownership change / team invite flow per Stripe's process
- Update legal entity, bank account, tax IDs, statement descriptor
- Rotate restricted keys and webhook signing secrets
- Point webhooks to your endpoints and verify signature validation
- Confirm subscriptions, customer portal, tax settings, and Radar rules
Option B: New Stripe account + customer migration
- Export customers/subscriptions carefully; pause new signups during cutover
- Communicate card-update flows; expect involuntary churn
- Rebuild products/prices/coupons IDs—hardcode mismatches break billing
- Dual-run webhooks until the old account is drained
Checklist items regardless of path:
- Payout bank account is yours
- Dispute / evidence emails go to your team
- Accounting exports (Balance, Payouts, Customers) accessible
- Connected accounts / Stripe Connect mapped if used
- Apple/Google IAP untouched if mobile—separate process
Phase 4: AWS / Cloud Hosting Handover
AWS
- Root account email + MFA device under buyer control (or Organizations invite into your org).
- Inventory: IAM users/roles, access keys, S3 buckets, RDS/Aurora, ECS/EKS/Lambda, CloudFront, Route53, SES, Secrets Manager, ACM certs.
- Rotate all access keys; delete unused IAM users.
- Confirm billing alerts and Budgets → your email.
- Verify backups: RDS snapshots, S3 versioning, AMI schedules.
- Update domain validation for certificates after DNS moves.
Vercel / Netlify / Railway / Render / Fly
- Transfer project ownership or re-link GitHub app to buyer org.
- Move env vars into your secret store; never leave production secrets only in Slack.
- Confirm preview deploys and production branch protections.
Phase 5: Source Code, CI/CD & Secrets
- Transfer GitHub org or export repos + transfer
- Confirm license headers, private submodule access, and package registry tokens (npm, GHCR)
- Move CI secrets (GitHub Actions, CircleCI) to buyer-owned orgs
- Rotate database URLs, JWT secrets, OAuth client secrets, and third-party API keys
- Tag a
post-acquisition-cutoverrelease for rollback
Related: Technical Due Diligence Checklist and IP & Copyright Diligence.
Phase 6: Customer Data, Privacy & Support
- Confirm database ownership and encryption-at-rest settings.
- Export a full logical backup before and after cutover; store offline.
- Update privacy policy / DPA contacts if you are the new controller/processor.
- Transfer Intercom, Crisp, Zendesk, or shared inboxes.
- Notify customers only as required—and when it reduces support chaos (new billing entity, new support email).
Day-7 & Day-30 Verification Gate
| Check | Day 7 | Day 30 |
|---|---|---|
| Domains in buyer registrar | Required | Confirmed |
| DNS + TLS healthy | Required | Confirmed |
| Stripe payouts to buyer bank | Required | Confirmed |
| Seller access fully revoked | Required | Spot-check |
| Backups restorable | Test restore | Retest |
| Webhooks / emails working | Required | Confirmed |
| Cloud bill under buyer payment method | Required | Confirmed |
Common Failure Modes
- DNS moved but MX forgotten → support black hole
- Stripe keys rotated but old webhooks still firing to seller servers
- AWS root still on seller's phone MFA
- GitHub transfer done but npm tokens still seller-owned → broken deploys
- Domain transferred but Apple Developer / Google Play left behind
Conclusion
Treat asset transfer like a product launch: sequenced, checklist-driven, and verified with real transactions (test purchase, password reset, payout). Until that passes, the acquisition is incomplete.
Screen acquisition targets with transfer complexity in mind on MyDealList, and use Pro plans when you want faster access to documented, buyer-ready listings.
See also: Micro-SaaS Tech Stack Audit.
Comments from Pro members
Selected feedback from verified Pro subscribers. Timestamps update while you read.
- Jordan K.…
Switched to Pro mainly for the extra analyses and Reddit/X coverage. This workflow section matches how I screen listings now—saves me hours every week.
Pro
- Priya S.…
The cross-marketplace point is huge. I used to miss duplicates across sites. Premium paid for itself after one decent lead I would have skipped.
Pro
- Marcus T.…
As a Pro user I appreciate the emphasis on red flags before diligence. If you are still on Free, at least read the checklist twice before you wire funds.
Pro
- Elena R.…
I send founders here when they ask how I find sub-$10k deals. The internal link to pricing is honest—you really do need Premium or Pro if you are serious.
Pro
- Chris V.…
MyDealList + a simple spreadsheet is my stack for 2026. Dynamic feed + alerts beats refreshing five marketplaces manually. Worth upgrading from Premium to Pro if you scale volume.
Pro
Leave a Reply
Your email address will not be published.