This text is not about choosing a new agency. It is about the mechanics of the move: what to recover, in what order, and why terminating the contract belongs near the end rather than at the start. You can check all of it yourself, before you write to anyone.
When switching is justified, and when the problem is on your side
Three situations justify a change regardless of who is on the other side. First: you do not know what you are paying for. A fixed invoice arrives, with no task list, no hours consumed, and a narrative answer to "what did you do in March". Second: the store runs on a version outside vendor support and nobody has called that a problem for over a year. Magento 2.4.5 and 2.4.6 are outside standard support, and PrestaShop 1.7 is no longer developed, so paid modules stop receiving updates. Third: requests get lost. No single channel, no ticket number, no classification, so a broken cart and a button colour change share one inbox.
Two other situations no provider can fix, because they sit on the client side. First: no single decision maker. If marketing asks for one thing and the CEO cancels it on Friday afternoon, everyone looks incompetent. Second: work handed over through five channels, by email, chat, phone, spreadsheet comments and a developer friend, after which "I did tell you". With that input no SLA works, because you cannot measure response time on something never reported.
The most expensive mistake: terminating before you hold the accounts
Do not terminate until access to every key account is confirmed on paper and in practice. Termination changes the relationship: your provider stops being a partner and starts delivering the contractual minimum at its own pace. The people who knew your store go on holiday, and replies arrive every three days.
The order is the opposite of what emotion suggests. First the inventory and the recovery of accounts, then a handover date, then termination with the notice period observed, and only at the end cutting the old provider off. If asking for a list of accounts feels like announcing a breakup, dress it in something neutral: updating documentation, an insurer requirement, a security audit. This is housekeeping you have every right to ask for.
The list of things to recover
For each item the question is not access, but ownership: can you remove other people from the account.
- Domain: the registrar account, not just the DNS panel.
- Hosting and server: service panel, SSH access, database credentials, DNS settings, mail configuration.
- Platform account: Shopify store ownership, PrestaShop licences, the Adobe Commerce or Magento account with repository keys.
- Code repository: administrator access rather than guest access, with the full commit history.
- Module and plugin licences: whose account they were bought on decides who gets updates.
- Third party accounts: payment gateway, carrier integrations, transactional email, monitoring, CDN, newsletter tools.
- Backups: where they sit, how often they run, who can reach them and when anyone last restored one.
- Documentation and request history: integration notes, configuration data, known issues, the ticket archive.
- Google accounts: Analytics, Search Console, Merchant Center, Tag Manager. Almost always owned by the agency.
- Certificates: SSL, API keys, signing certificates, access to public body and integrator accounts.
What usually goes wrong
Four scenarios repeat in almost every handover. First: the credentials sit in the private mailbox of a former agency employee who left eighteen months ago. Nobody noticed, because everything worked. Second: the domain is registered to the agency account. This can be unwound, but it takes from several days to several weeks and needs goodwill from the other side, so start here.
Third: module licences bought on the agency account. Two options then, a licence transfer if the vendor allows it, or a new purchase. For a typical PrestaShop store with a dozen or so paid modules that is from roughly 1,000 to 4,000 USD as a one off, a cost to plan for, not to discover in week three. Fourth: the code exists only on the production server, with no repository, no change history and no staging environment, so every change over the past few years went straight onto the live store. The new provider has to build the basics before improving anything, and an honest quote should reflect that.
A 14 day handover procedure
Days 1 to 3, inventory and technical audit. We collect the list above and check: platform version and support status, PHP version, module compatibility, repository, backups, DNS and certificates, integrations, log errors, server load. The output is one risk table with priorities.
Days 4 to 7, taking over accounts and backups. Every account moves to the store owner, and permissions for the new provider are granted from there. We pull a full copy of files and database and restore it outside production, to see whether the store can be rebuilt at all. A backup nobody has restored is just a file.
Days 8 to 10, staging environment and repository. The code goes into a repository, a staging environment mirroring production is created, and we agree how deployments work. From that point, no change goes directly onto the store.
Days 11 to 14, monitoring and first fixes. We start availability monitoring, apply the most urgent patches, and set one reporting channel and a classification of events: critical outage, bug, ordinary change. Until the last day the old provider should still have a valid contract, because they know this store.
The transition period and overlapping contracts
A month of double cost looks bad in a spreadsheet, until you price the alternative. Take a store with 1.5 million USD in annual revenue. That is around 125,000 USD a month and around 4,000 USD a day. If sales concentrate into a dozen or so hours of the day, an hour of full downtime is around 330 USD of sales that never happen, not counting complaint handling and ad budget driving traffic into a broken cart.
The Advanced package costs 500 USD a month, roughly an hour and a half of downtime in a store like that. One month paying both providers in parallel costs you what a single afternoon without a store costs. A week with nobody at all, because the old provider no longer replies and the new one has no accounts yet, costs many times more. Overlapping contracts are not waste, they are cheap insurance.
GDPR when changing providers
A company maintaining your store processes your customers' data, so it is a processor and a data processing agreement under Article 28 GDPR is required. It has to exist before the new provider first touches the data, not after. It should set out the subject matter and duration of processing, the categories of data and of data subjects, the confidentiality obligation, the security measures under Article 32, the rules for approving sub-processors, assistance with data subject rights and with breach notification, where the 72 hour deadline for notifying the supervisory authority applies, return or deletion of data at the end of the engagement, and the right to audit. This article is not legal advice, and outside the European Union and outside the United Kingdom other data protection regimes apply, so confirm your own situation with a lawyer.
Two things are owed to you by the old provider. First, return or deletion of the data once the contract ends, in line with the data processing agreement. Second, withdrawal of access on the same day the engagement ends, not the following week. Turn that into a list of accounts and tick them off one by one, because a forgotten administrator account is a risk that stays with you for years.
How we do it
We start with an audit, the first three days of the procedure above, and you get the result whether or not you sign. Then you choose a support package: Basic 250 USD for 10 hours a month, Advanced 500 USD for 20 hours, Premium 1,000 USD for 40 hours. Availability monitoring, reacting to what stopped working on its own, is a separate service from 240 USD a month. The minimum term is 3 months, then a symmetrical notice period applies, the same for both sides. We say this openly: if the text is about leaving a provider, it is worth knowing on what terms you can leave us too.
The status of every request and your current hour consumption are visible in Gorilla Panel, so the question "what did I pay for this month" has an answer in one place. That is the same thing whose absence most often triggers a change of provider.
Before you terminate anything, check the state of the store and what is missing from the list of accounts. We will run a free technical review and hand you a list of risks and missing accounts, with no obligation, regardless of who maintains the store afterwards. Write to us through /en/sla-help-desk.