Private equity and portfolios
Customer data rights after a home services acquisition
By SourceX Editorial · Reviewed by Noah Loul ·
Short answer
Customer data rights after a home services acquisition start with deal structure. In a stock purchase, the acquired company keeps its customer records and every promise it made about them. In an asset purchase, records move only if the agreement transfers them, and the seller's privacy notice and customer contracts may still limit how they are used.
Key takeaways
- In a stock deal the company, its customer records and its obligations stay together; only the owner above it changes.
- In an asset deal, customer records transfer only when the purchase agreement lists them, and excluded records stay with the seller.
- The privacy notice in force when data was collected is a core document, so collect every version the seller published.
- Permission to call, text or email customers is tracked separately from the customer list and may not carry the same scope.
- Licensing job records for AI generally means removing personal details first, and customer contracts can narrow the scope further.
Why does deal structure decide customer data rights?#
Deal structure decides customer data rights because it determines which legal entity holds the records after close and which obligations come with them. A stock purchase changes who owns the company; an asset purchase moves selected property from the seller's company to the buyer's.
Home services platforms use both structures, sometimes in the same year. Many add-ons are bought as assets, often to leave liabilities behind or for tax reasons, and that is the structure that calls for the most care with customer lists, service histories and membership agreements.
| Question | Stock purchase | Asset purchase |
|---|---|---|
| Who holds customer records after close? | The acquired company, unchanged | The buyer's entity, if the agreement lists them as purchased assets |
| What happens to commercial customer contracts? | The company remains the party; look for change-of-control terms | Each one is assigned to the buyer, and some require the customer's consent first |
| Does the seller's privacy notice still matter? | Yes, it remains the company's own promise | Generally yes, as a likely limit on how transferred data may be used |
| Can the seller keep some records? | The company keeps them; selling owners leave with only what was carved out | Yes, excluded assets and retained books stay with the seller |
| What about memberships and maintenance agreements? | They continue with the same company | They transfer if assigned, and customers may need notice |
What did the seller promise its customers?#
The seller's promises to customers live in its privacy notices, booking terms, membership agreements and commercial contracts, and they generally follow the data when ownership changes. Collect every version, not only the one on the website today, because records gathered years ago were collected under the notice in force at that time.
Look for three things in each notice: whether it described sharing with third parties, whether it mentioned transfers in a sale or merger, and whether it promised that information would be used only to provide service. A clause covering business transfers usually addresses who may hold the data, not new uses of it.
When old versions are missing, reconstruct them from the web agency's files, the website builder's page history or emails that announced changes. Record any period where the wording is unknown rather than assuming today's notice applied throughout; counsel can then decide how to treat records collected in that gap.
- Website privacy notices, including archived versions held by the seller or its web agency.
- Online booking, financing and customer portal terms.
- Membership and maintenance agreement templates, past and present.
- Commercial contracts with property managers, builders, home warranty companies and facilities clients.
- Call recording disclosures used in phone greetings.
- Marketing consent and opt-out records from the email and texting tools.
Which laws may apply to acquired customer records?#
Several areas of law may apply to acquired customer records, and which ones do depends on the company's size, the states it serves and what the records contain. Counsel assesses them deal by deal; the operating team's job is to bring the facts that make that assessment possible.
Marketing permission deserves its own check. A platform may hold a valid customer list but not the right to text every name on it, because consent to marketing messages is often tied to the business that collected it and the purpose it described.
| Area | What counsel typically reviews |
|---|---|
| State privacy laws such as the CCPA | Whether the company meets each law's thresholds, what notices said and how rights requests were handled |
| Calls and texts | Consent records for marketing calls and texts, which the TCPA and state rules may govern |
| Email marketing | Opt-out lists and whether they were honored, which CAN-SPAM may address |
| Call recordings | How callers were told about recording, since state consent rules differ |
| Data security | Safeguards for records with personal information and state breach notice laws |
| Card payment data | Whether full card numbers sit in notes, attachments or exports; PCI DSS is an industry standard that usually applies through card processing agreements |
The hard part: customer details inside job records#
Customer details inside job records are harder to manage than the customer list itself, because they sit in free text, photos and recordings rather than labeled fields. Technician notes mention gate and alarm codes, pets, who was home and sometimes health details, such as a resident on oxygen. Photos show house numbers, faces and the inside of homes.
Any use beyond running the business, including licensing records for AI, generally requires removing names, addresses, phone numbers, access codes and similar details first. Automated tools help but do not finish the job: the documentation for Presidio, an open-source toolkit for detecting personal information, warns that automated detection offers no guarantee of finding all sensitive information. Plan for human review of samples, especially free text and images.
Can a platform license acquired customer records for AI?#
A platform can sometimes license records that originated with acquired customers, but what is usually licensed is job history with personal details removed, not the customer list. AI developers want the work itself: the request, the diagnosis, the repair, the parts and the outcome. Who the homeowner was is rarely useful and only adds risk.
Rights still matter after redaction. Counsel looks at the acquisition chain, the notices and contracts above, and any commercial customer terms that restrict use of project information. Records tied to a commercial client with strict confidentiality terms are often carved out, while residential job histories may clear once preparation is complete. The decision is made brand by brand, and the entity that holds the records signs.
Illustrative: an electrical contractor bought as assets#
Illustrative: a fictional home services platform acquires the assets of an electrical contractor. The agreement lists customer lists, service histories and the FieldEdge account as purchased assets, but excludes accounts under the seller's contracts with two property management companies until those clients consent to assignment.
The records review finds that the seller's old website notice said customer information would be used to provide and improve services and would not be sold. Its texting tool kept opt-in records for only part of the list. The platform sends a change-of-ownership notice to residential customers by mail and email, collects new texting consent through its booking forms and at service visits instead of importing the old texting list, and keeps the property management records in a separate archive pending consent.
When the platform later explores licensing, counsel clears residential job records for scoping on two conditions: personal details are removed, and the license's permitted use stays consistent with what the old notice told customers. The property management records stay out.
How SourceX approaches acquired customer records#
SourceX handles acquired customer records as a rights question before anything else, inside the Rights step of the SourceX five-step transaction (Supply, Rights, Preparation, Approval, Delivery). Its fit check works from metadata, so no customer records are shared while counsel reviews the deal structure, notices and contracts.
When records proceed, Preparation removes personal and confidential details, and the SourceX Evidence Packet documents the acquisition chain, licensing rights, permitted use, the privacy record and release authorization. The supplier entity approves each step and can exclude any brand, client or record family.
Frequently asked questions
Does a privacy notice that mentions mergers cover licensing for AI?
Not necessarily. Business transfer language usually explains that customer information may pass to a new owner in a sale or merger. It does not by itself authorize new purposes. Counsel compares the notice's stated uses with the proposed license, and redaction often matters more than the transfer clause.
What happens to customers who asked to be deleted or opted out?
Their requests should follow the data. Carry suppression and deletion lists into the platform's systems before importing anything, honor them in marketing tools, and exclude those customers from any export prepared for analytics or licensing. Gaps here are among the easiest problems for later diligence to find.
Do we have to notify customers after an asset purchase?
It depends on the states involved, the seller's notices and the contracts being assigned. Many platforms send a change-of-ownership notice regardless, because it reduces confusion when a familiar truck arrives with a new logo. Counsel can advise whether specific notice language is needed.
Are commercial customers treated differently from homeowners?
Usually, because commercial relationships run on negotiated contracts. Property managers, builders and facilities clients often include confidentiality, data use and assignment clauses that go beyond a consumer privacy notice. Review those contracts one by one before their records are combined, migrated or offered for licensing.
What if the acquired business was a franchisee?
Read the franchise agreement before treating the customer list as acquired. Franchise agreements often give the franchisor ownership of, or control over, customer data and records, limit transfers of the franchised business and restrict use of customer information after the relationship ends. Those terms can matter as much as the purchase agreement and may require franchisor consent.
Who signs a license if the add-on was merged into the platform entity?
The entity that now holds the records signs. Merging the add-on does not erase obligations attached to its history, so the seller's notices and the customer contracts it assigned still shape the scope that the surviving entity can approve.
Sources
- Presidio's documentation warns that because it uses automated detection mechanisms, there is no guarantee that Presidio will find all sensitive information, and additional systems and protections should be employed. Source
Related resources
See if your company qualifies
A short company assessment. No data uploads are needed.