---
title: "Technology and data diligence, Due Diligence Deep Dive"
url: https://poolroutemarketplace.com/learn/due-diligence/technology-and-data-diligence
description: "The software stack the route runs on is a real asset (or liability). Diligence here saves you from a painful migration later.\n\n**Inventory the stack.**\n\n- Routi"
lang: en
---

# Technology and data diligence

Lesson 11 of 12 · 7 min read

The software stack the route runs on is a real asset (or liability). Diligence here saves you from a painful migration later.

**Inventory the stack.**

\- Routing software (Skimmer, Pooltrac, Pool Office, Jobber, custom)
\- Billing & payments (the software's built-in module, QuickBooks, Stripe, etc.)
\- Customer communication (built-in SMS, separate platform, manual)
\- Accounting (QuickBooks, Wave, Xero, shoebox)
\- Payroll if applicable (Gusto, ADP, manual)

**Confirm seller-owned, not personal.** Many small operators run accounts in their personal email or login. Make sure logins, billing accounts, and merchant accounts can transfer or be cleanly recreated. A seller's personal Stripe account doesn't transfer, you'll create your own and migrate customers (with their re-authorization).

**Data export.** Before close, confirm you can export full customer history, payment history, and service notes from every system. Some platforms make this very hard; learn now.

**PCI / payment data.** Never accept a transfer of raw card numbers. Customers must re-authorize on your account. This is both a PCI compliance requirement and a fraud-prevention norm.

**Customer PII handling.** What does the seller's privacy posture look like? Are customer addresses, phone numbers, gate codes, and dog notes stored in software with access controls, or in a shared Google Sheet anyone can edit? Inheriting weak data hygiene means inheriting breach risk.

**Customer contact authorization.** Confirm the seller has consent (or a basis under their state's law) to share customer contact info with you for transition. Most do; some don't. A short re-permissioning email at close protects everyone.

## Quick check

\1. Why never accept a transfer of raw card numbers?

\2. Big risk of accounts in the seller's personal logins?

\3. Customer address and gate-code list in a shared Google Sheet means…?

\4. Why never accept a transfer of raw card data?

\5. Risk of seller running on personal logins?

\6. Confirm the seller can export the full customer database to ____ before close.

\7. Software vendor account ownership transfers automatically with a route sale.

Earn 42 points

Mark this lesson complete

← Previous lesson: https://poolroutemarketplace.com/learn/due-diligence/environmental-and-regulatory
Next lesson →: https://poolroutemarketplace.com/learn/due-diligence/diligence-report-writeup

## Structured data

```json
[
  {
    "@context": "https://schema.org",
    "@type": "Organization",
    "name": "Pool Route Marketplace",
    "url": "https://poolroutemarketplace.com",
    "logo": "https://poolroutemarketplace.com/favicon.png"
  },
  {
    "@context": "https://schema.org",
    "@type": "WebSite",
    "name": "Pool Route Marketplace",
    "url": "https://poolroutemarketplace.com",
    "potentialAction": {
      "@type": "SearchAction",
      "target": "https://poolroutemarketplace.com/browse?q={search_term_string}",
      "query-input": "required name=search_term_string"
    }
  }
]
```