A Shopify handoff should leave the merchant in durable control of the store while the agency retains only the collaborator access required for ongoing work. The handoff should cover ownership, users, theme/source code, domains, apps, billing, payments, analytics, content, QA, and post-launch support.

Shopify provides collaborator accounts specifically so partners can access merchant stores with controlled permissions, and its development workflow includes client transfer stores that can be transferred to the merchant when the build is ready.

AxiomLift’s white label Shopify development page covers the development service. Use this checklist before launch or partner offboarding.

1. Confirm the store ownership model

Record:

  • store name and URL
  • organization/store owner
  • agency/partner role
  • whether the build began as a client transfer/development store
  • expected ownership transfer date
  • billing owner

The merchant should understand which account becomes responsible for the store and plan after transfer.

2. Use collaborator access appropriately

Shopify collaborator accounts allow partners to access client stores without being counted like normal staff users in the same way, and merchants control the permissions granted.

For each collaborator:

  • identity/company is known
  • permissions match the work
  • access is reviewed before launch
  • unnecessary permissions are removed
  • access will be removed when the relationship ends

Do not share the merchant’s owner credentials with development teams.

3. Document theme and source-code ownership

Confirm:

  • active theme
  • backup theme/version
  • custom theme repository if used
  • source-control location
  • build commands/tooling if used
  • custom Liquid/sections/blocks
  • JavaScript/CSS architecture
  • third-party theme license
  • deployment process

If a local or CI build pipeline is required, document it so another developer can reproduce the deployment.

4. Audit apps and recurring costs

Create an app inventory:

AppPurposeBilling ownerCritical permissions/dataCan it be removed?
App nameBusiness functionMerchant/agencyNoteNote

Review:

  • paid apps
  • trial expiration dates
  • apps installed only for development
  • apps with customer/order data access
  • apps that inject theme code
  • apps required for checkout, subscriptions, reviews, search, feeds, or marketing

Remove unnecessary development utilities before handoff when safe.

5. Confirm domain and DNS ownership

Record:

  • domain registrar
  • DNS provider
  • primary domain
  • redirect domains
  • email-related DNS records
  • CDN/proxy services if used
  • who can make DNS changes

The agency should not leave the merchant dependent on a developer’s personal registrar account.

6. Review payments and checkout ownership

The development team should not retain access or credentials beyond what the merchant has authorized.

Confirm merchant ownership of:

  • payment provider settings
  • payout/bank information
  • tax settings
  • shipping settings
  • checkout configuration
  • markets/currency settings where applicable
  • legal/policy pages

Sensitive financial configuration should be reviewed by the merchant rather than silently completed by the agency without authority.

7. Validate product and content data

Before launch:

  • product titles/descriptions are final or status is known
  • variants/options are correct
  • inventory rules are understood
  • collections are correct
  • navigation links are correct
  • images/alt text are present where supplied
  • pages/blog content are migrated as agreed
  • redirects exist for changed URLs where required

Data migration should have a reconciliation step, not only a successful import message.

8. Verify analytics and marketing integrations

Record ownership/access for:

  • analytics
  • Google tag/GTM if used
  • Google Ads
  • Meta/TikTok/other pixels if used
  • Merchant Center/product feeds
  • email/SMS platform
  • consent/privacy tooling

Test important conversions after production launch rather than assuming staging behavior carries over.

9. Run a launch QA checklist

Test:

  • home and key collection/product pages
  • navigation
  • search
  • cart
  • checkout path within safe test procedures
  • forms
  • customer accounts if used
  • responsive layouts
  • discounts/promotions if in scope
  • shipping/tax behavior with merchant-approved scenarios
  • email notifications
  • 404s and redirects
  • performance issues visible to users

Document which tests the agency performed and which require merchant verification.

10. Transfer ownership using Shopify’s current workflow

If a store was built through a partner/client-transfer workflow, follow Shopify’s current transfer procedure rather than relying on an old guide.

After transfer:

  • confirm the merchant can access the store
  • confirm billing/plan responsibilities
  • verify agency collaborator access if ongoing work continues
  • confirm partner development credentials are no longer required

Shopify’s documentation explains that after a client transfer store is transferred, the merchant owns the store while the partner may retain collaborator access when appropriate.

11. Define post-launch support

Separate:

  • defects against the agreed build
  • training/questions
  • routine content work
  • theme enhancements
  • new app integrations
  • conversion-rate experiments
  • ongoing maintenance

The client should know how to request each type of work and whether it is included or separately scoped.

12. Remove unnecessary access at offboarding

When development ends:

  • remove inactive collaborators
  • remove unused staff access
  • revoke third-party development tools
  • rotate any shared secrets that were unavoidable
  • confirm merchant recovery/admin access
  • archive final source and documentation
  • verify agency-owned tools no longer contain unnecessary merchant data

Use the broader website handoff checklist for domains, source files, analytics, integrations, and documentation that sit outside Shopify itself.

If the Shopify work is part of a larger outsourced website engagement, the guide to outsourcing web development for agency clients helps define scope, staging, QA, ownership, and agency review before the handoff stage.

Shopify handoff summary

  • Merchant/store ownership confirmed.
  • Collaborator permissions reviewed.
  • Theme/source code documented.
  • Apps and recurring costs inventoried.
  • Domain/DNS ownership known.
  • Payments/checkout settings merchant-controlled.
  • Product/content migration reconciled.
  • Analytics/marketing integrations verified.
  • Launch QA completed.
  • Transfer workflow completed where applicable.
  • Post-launch support boundary defined.
  • Unnecessary access removed.

Research sources

Related reading