Back to articles

"Own your audience" is not an export specification

By Simon

Test whether customer, content, purchase and permission records remain usable after an export, with an acceptance sheet for platform buyers.

An open carrying case of tabbed folders beside a sample card bundle and magnifying glass.

AI-generated conceptual illustration: rehearse an export by checking a sample of organized records, not by relying on an audience-ownership slogan.

You can download every email address from a platform and still have trouble leaving it. The file might tell you who a member is but leave out what they bought, when their access ends or which messages they agreed to receive.

Before buying, ask for a sample export and have your likely destination try to use it. Can it reconstruct the records you need to keep the business running? That's worth finding out while you can choose another vendor or negotiate the missing work into the agreement. The download button won't tell you, and a live billing cutover will need a separate migration plan.

Ask what each file contains

Ghost's export documentation separates content, members, themes and post analytics. Its member CSV includes fields such as id, subscribed_to_emails, complimentary_plan and stripe_customer_id. A destination can inspect those fields and tell you what it can do with them.

The fields answer different questions. A Stripe customer identifier points to a payment-provider record; it doesn't describe all of a member's benefits or billing arrangements. Ask what else has to travel with it.

Shopify's customer CSV documentation is useful because it spells out some limits: that import path cannot import order information or migrate passwords from another online store. Those are limits of the customer CSV route, not necessarily every way of moving a store. Ask how the missing records would move.

When a vendor promises "all your data", ask for a field list and exclusions for each export. You need to know what that promise means before relying on it.

Give the export a practical test

Use this acceptance sheet with each candidate, including Stackmodo. Have the vendor supply its actual formats and exclusions, then test the result in the destination. A tick in an "available" column isn't a passed test.

Record group: Customer identity

Ask the source to provide: Stable ID, relevant profile fields, merge rules

Test in the destination: Recognize returning customers without merging different people

Record group: Content

Ask the source to provide: Structured text, slugs, authors, publication status

Test in the destination: Open a draft and a published page with their relationships intact

Record group: Media

Ask the source to provide: Files or an agreed retrieval route, captions, rights information

Test in the destination: Load an image or video without relying on the old account

Record group: Purchases

Ask the source to provide: Order and line-item IDs, currency, status, refunds

Test in the destination: Explain what a selected customer bought and what was refunded

Record group: Membership access

Ask the source to provide: Benefit or tier, start and end dates, exceptions

Test in the destination: Grant the right access without creating a new charge

Record group: Email permissions

Ask the source to provide: Subscription state, suppression records, supporting history

Test in the destination: Keep an unsubscribed contact out of a marketing send

Record group: Reporting

Ask the source to provide: Event definitions, dates, available historical exports

Test in the destination: Interpret the history without silently changing the metric

Add columns for format, destination field, transformation needed, test evidence and unresolved issue. Keep the original export unchanged and record transformations separately. If an import looks wrong, you'll need to know whether the exporter or your spreadsheet changed the value.

Export acceptance diagram showing source records, field mapping and destination testsView full-size image

An exit rehearsal checks whether records can be used elsewhere, not merely downloaded. Conceptual checklist, not a product screenshot.

Choose a small, deliberately awkward sample. It could include someone who changed their email address, a member with complimentary access, a refunded order and an unpublished page with an image. Use approved test records where possible. You don't need to send a vendor your whole customer database to find out whether its importer can read a date.

Follow a record through the destination

Start with a member. Ask the destination to find that member's purchase, identify the benefit they bought and show the correct access end date. Only mark the sample as passed when those relationships work. Matching row counts won't reveal a purchase attached to the wrong account.

Then work backward from a refunded order to the customer and the affected entitlement. If you can't follow that connection, record the gap even if every row imported successfully.

Check date formats and time zones. Preserve leading zeros in identifiers, and ask how the importer distinguishes blank values from false ones. Does an empty cell clear an existing field or leave it alone? Shopify's customer CSV guidance also warns that matching existing customers by email or phone can overwrite customer data, including import tags. Review those rules before testing against records you want to keep.

Give content its own inspection. Open embedded media, internal links and redirects in the test environment. Check whether a media URL points to an asset you can keep independently or to something that disappears when the old service ends. An image appearing in an article today doesn't mean the JSON export contains the image file.

Keep the evidence behind email permissions

A "subscribed" field can help decide whether to send an email. It may not tell you what the person agreed to or which purpose their agreement covered. Review permissions separately from whether the contact imported correctly.

The UK's Information Commissioner's Office calls for specific, granular consent records, including evidence of who consented, when and how consent is managed. Its guidance says consent requests must identify the organisation and purposes, and that people have a right to withdraw consent. This is UK guidance, and the page is marked as under review following legislative changes. Check the rules that apply where you operate.

Ask for the permission state and its supporting evidence: collection source, timestamp, relevant notice or form version, purpose and withdrawal history. Your privacy lead should determine what your situation requires and whether the planned use stays within the original scope.

Moving providers doesn't give you permission to add old buyers to a new marketing list. Have your privacy lead review the proposed activity and its lawful basis. Not every purpose relies on consent, but the ICO guidance is explicit that you cannot simply swap lawful basis to continue the same consent-based processing after someone withdraws.

Permission review showing contact records alongside purpose, evidence and withdrawal statusView full-size image

Keep permission evidence connected to the contact. An exported address does not answer whether a proposed use is allowed.

Agree on the exit work before signing

Ask who can request an export, how long it takes to prepare, what help costs and how long access lasts after termination. Confirm whether custom fields and records from connected services are included. Where a connected service needs a separate request, give someone responsibility for making it.

Discuss backups and retained records too. Getting your records into the destination is separate from the old provider's retention obligations. Have the terms reviewed rather than asking for a promise of immediate deletion everywhere that the provider can't support.

Keep the acceptance sheet with the contract. Record the gaps you've agreed to live with and who will pay to close them. Apply appropriate access and retention controls to sensitive test files. A future colleague should be able to repeat the test from those records, without trying to reconstruct what someone promised on a sales call.