Review vendor account control by identifying the contracting entity, approved users, administrative permissions, recovery contacts and connected services. Follow the applicable provider process and verify the buyer’s required access before closing out the handover. A copied password, invitation or changed billing email does not alone establish authorized ownership transfer or reliable operating control.
- Inventory account authority and recovery control separately.
- Review the actual contract and provider transfer process.
- Create approved user access rather than sharing personal credentials.
- Verify required functions and document unresolved dependencies.
Which accounts and agreements belong in the handover?
List the accounts needed to run the wash, including reports, point-of-sale, member billing, utilities and service portals. Each supplier may have its own transfer process, so check the actual arrangement.
The buyer hub connects account review with the handover. Record the provider, service, entity and wash covered; one account may serve several washes. An owner’s personal login may control a business service without making that personal account an asset the buyer should receive.
Ask where records are kept and who can confirm the setup. A sale summary may omit a recovery email, outside administrator or linked service. Note these links before deciding what must change at closing.
Review the actual agreement, order form and provider instructions with the right advisers. A working login proves access, but does not prove that the contract permits a transfer. Keep the provider’s approval separate from a test of the account.
DRB’s August 2026 general terms address assignment, notices and ownership changes. Section 11.8 describes advance notice of a planned wash sale and related transfer records. Counsel should check the wash’s actual agreement and which terms take priority. These public terms do not set another vendor’s rules or prove that this wash’s transfer is approved.
Record whether the provider needs consent, notice, a new account or another step under the reviewed terms. Keep requests, submitted items and completed steps separate. A seller’s statement that an account can transfer gives the buyer something to check. It does not prove that the provider has agreed.
How should account control and user roles be mapped?
Use a register with separate fields for authority, access and recovery. This worksheet organizes the handover without storing passwords or claiming that a provider has approved the sale.
| Control item | Evidence to obtain | Handover question |
|---|---|---|
| Contracting entity | Applicable agreement and account details | Which entity may use the service after closing? |
| Administrative role | Approved user and permission records | Who can manage necessary account functions? |
| Recovery control | Reviewed recovery contact and authentication arrangement | Can the receiving administrator recover approved access? |
| Connected service | Integration inventory and provider confirmation | Which dependencies need separate authorization? |
Use account IDs suited to the restricted working file. Keep passwords, security codes and full customer records out of an ordinary sale summary. The register should show where protected records are held and who may review them.
Give each user the access needed for their work through roles the provider supports. Someone who reads reports may not need to change billing, export customer data or create new administrators. Review each permission instead of giving everyone full control.
The FTC security guide discusses limited administrator access, individual accounts and ways to protect logins. Apply those principles through the provider’s approved process with qualified technical review. General advice does not prove that this account is secure or that a given role suits every user.
Record proposed users, approved roles and who reviewed them. Keep buyer diligence access separate from the authority needed to run the wash. Set a purpose and end point for temporary access. An export or demo should not give ongoing control over services outside the deal.
Why do recovery contacts and shared accounts need separate review?
Check how approved users can regain access and who controls each recovery route. An account may look transferred while recovery still relies on the seller’s email, phone or login device.
Check recovery without sharing security details widely. Identify who controls the contact and what proof the provider needs to change it. An email address named after the wash does not prove buyer control. It also does not prove that recovery will work after closing.
Have approved staff check the agreed setup through a suitable process. Do not disable a working login safeguard during diligence. Record completed checks and any remaining reliance on the seller. A new username alone does not prove that the wash can keep running.
Separate the services, records and users for the purchased wash from those the seller keeps. A shared account may need to be split through the provider’s process or handled through another reviewed plan. Do not assume the buyer should receive the portfolio administrator’s login.
The membership transfer guide connects account control with ongoing billing and customer terms. Check which records may be viewed, kept or moved, and how the services will run. The ability to export data does not prove that the contract allows it or that privacy requirements have been met.
Define the limits of any temporary shared access. Record who will make each change and what proves it is complete. Other washes and their customers are not part of the transfer simply because their records appear in the same portal.
Which integrations and access checks need provider support?
List services linked to the main account and who controls each link. Report feeds, message services or payment tools may depend on a separate agreement or administrator, so check which provider process applies.
Ask the provider or technical reviewer how the buyer’s approved access affects each link. Keep settings, data transfers and operating decisions separate. A new login for one account may leave another service tied to the seller’s account.
The fleet-contract diligence guide adds context when a business customer uses an account or redemption process. Review the agreement and actual setup together. Changing the billing contact does not prove that every linked customer remains eligible. It also does not authorize a new use of customer data.
Check approved tasks through an agreed process after the required account steps are complete. A welcome email or login screen does not prove that the new user can do the work. Verify a needed task that the user is allowed to perform.
- Define the service and account scope needed after closing.
- Confirm the applicable contract and provider transfer requirements.
- Establish approved users, roles and recovery arrangements.
- Verify selected permitted functions with authorized personnel.
- Record provider evidence, completed checks and unresolved dependencies.
- Close temporary access through the reviewed timetable.
Use safe demonstrations suited to the account. Do not charge real customers, change live equipment controls or expose personal records just to test a login. State what was tested and which tasks still need provider or specialist review.
How should seller access end and the evidence be protected?
Time access removal around the approved closing and transition plan. The buyer needs lasting control, but the seller may have an agreed role for a limited time with a defined purpose and access.
List current users and decide which roles should stay, change or end. Confirm how the provider supports those changes, including any service credentials. Removing one visible user does not prove that all seller-controlled recovery routes or linked access have ended.
The first 90 days guide connects open access questions with the buyer’s work plan. Record temporary roles, their limits and who will follow up. The handover remains incomplete if needed control depends on an undocumented favor from the former owner.
Keep useful handover records without collecting passwords in the register. Use a restricted file to record account scope, status, approved reviewers and where evidence is kept. Give approved staff the information needed for their work.
The FTC personal-information guide advises businesses to know what sensitive data they hold, keep only what they need and limit access. Have qualified advisers review the actual transfer and data. Control of a portal does not give permission to share every record stored there.
The final register should show completed checks, open items and who will resolve them. Approved report access, an accepted change of entity and tested recovery are separate results. Do not call the whole account transferred when the evidence supports only one step.