Logistics and distribution
Your TMS or visibility vendor was acquired: how to protect access to your data
By SourceX Editorial · Reviewed by Noah Loul ·
Short answer
When a TMS or visibility vendor is acquired, protect access to your data in five steps: read the assignment and change-of-control clauses, export your history now, confirm retention and deletion in writing, review new terms before accepting them, and document what you hold. The contract usually survives the deal; your practical access may not.
Key takeaways
- An acquisition rarely ends your contract, but it often leads to platform consolidation, new terms and retired features.
- Export load, rate, tracking and exception history before any migration notice, while the old platform still works.
- Get written confirmation of how long the vendor will keep your data after termination and how deletion is certified.
- Read updated terms for new data-use rights, especially aggregated benchmarking and model training.
- Keep an export manifest that records source system, date range, row counts and who can access each file.
What changes when your TMS or visibility vendor is acquired?#
When a TMS or visibility vendor is acquired, your contract usually carries over to the new owner, but the product roadmap, hosting and data-use terms can change. Acquirers commonly consolidate overlapping platforms, retire features, move hosting and update terms of service, sometimes through a click-through notice rather than a negotiated amendment.
Visibility platforms raise the stakes because they often hold records you keep nowhere else: tracking events from carrier integrations, predicted arrival times against actual arrivals, exception alerts and the notes your team added. A TMS holds the loads, rates, carrier details and invoices that drive daily work. Losing reliable access to either is both an operational and a legal problem.
This is general information, not legal advice. Contract terms differ, so review your own agreements with counsel.
Step 1: read the assignment and change-of-control clauses#
The assignment and change-of-control clauses tell you whether the vendor could transfer your contract without your consent and whether the deal gives you any right to exit. Read them alongside the data clauses, because together they decide what you can ask for now.
If the contract is silent on data ownership or return, that silence is itself a finding. It is the clause to negotiate first, and change-of-control rights, where you have them, are the leverage to do it.
| Clause | What to look for | Why it matters |
|---|---|---|
| Assignment | Whether the vendor may assign to a successor without consent | Decides whether the acquirer simply steps in |
| Change of control | Termination or renegotiation rights for you | May give leverage to secure exports and terms |
| Data ownership | Who owns inputs, outputs, tracking events and derived data | Determines what you can demand back |
| Vendor license to your data | Rights to aggregate, benchmark or train on your data | May be used more broadly under new ownership |
| Return and deletion | Format, timing and cost of returning data at termination | Your exit path if the platform is retired |
| Transition assistance | Help moving to another system | Reduces cutover risk |
Step 2: export your history now#
Export your history now, while the current platform works and the people who know it are still at the vendor. Waiting for a migration notice risks shorter export windows, changed formats and support teams focused on moving customers to the new platform.
Test each export by opening it outside the platform and comparing it with what users see on screen. Exports that look complete often leave out notes, attachments or event history beyond a default window, and those gaps are far easier to fix while the platform still runs.
- TMS: loads, stops, rates, accessorials, carrier records, invoices, claims and internal notes.
- Visibility: tracking events, predicted and actual arrival times, exception alerts and comments.
- Carrier connectivity records showing which carriers sent which data, and how.
- Documents: bills of lading, proof of delivery and rate confirmations.
- User and permission lists showing who had access to what.
- Field definitions and code lists for every export.
Step 3: confirm retention and deletion in writing#
Retention and deletion should be confirmed in writing: ask the vendor how long it will keep your data after termination, where it is stored, whether it will move to the acquirer's systems and how deletion is certified. A support chat answer is not enough; ask for a letter or email from someone authorized to commit the company.
Ask the same questions about backups and subprocessors. If the acquirer plans to merge hosting, find out whether your data will sit in a new region or with new subprocessors, and whether your existing privacy terms and security commitments carry over unchanged.
Step 4: review new terms before you accept them#
New terms deserve review before acceptance because updated agreements are where data-use rights quietly expand. Route any click-through update to counsel rather than letting a dispatcher accept it at login.
| New term | Question to ask |
|---|---|
| Aggregated or de-identified data use | Can the vendor build benchmarks or products from our records, and can we opt out? |
| AI or model training | Will our data train models used by other customers or by the acquirer's other products? |
| Data location | Where will data be stored and processed after integration? |
| Export fees and limits | Will exporting our own data cost more or be restricted? |
| Product sunset | What notice will we get before the platform is retired? |
Step 5: document what you hold and who can reach it#
Documenting what you hold means keeping an export manifest: for each file, the source system, export date, date range, row count, field definitions and the people who can access it. The manifest proves completeness if a dispute arises and keeps the archive usable long after the platform is gone.
Published provenance standards offer a useful model. The Data & Trust Alliance's Data Provenance Standards group dataset metadata into Source, Provenance and Use, and a manifest built along those lines answers most of the questions a future acquirer, auditor or data licensee will ask.
Illustrative: a distributor's counsel after a visibility deal#
Illustrative: a fictional food and beverage distributor runs a TMS for its private fleet and a visibility platform for common-carrier loads. The visibility vendor announces it has been acquired by a larger logistics software company with an overlapping product.
The general counsel works through the five steps. The contract allows assignment to a successor, but data return is promised only in the vendor's standard format. IT exports tracking events, arrival history and exception notes with a manifest. Counsel obtains written confirmation of retention after termination and declines an updated clause allowing model training on customer data until it is narrowed.
The outcome: when the acquirer later announces a platform migration, the distributor already holds a complete archive under its own control, and its operations team moves on its own timetable rather than the vendor's.
How SourceX treats vendor-held history#
SourceX treats vendor-held history as licensable only when the supplier can show it controls the records and the vendor terms allow the use. In the Rights step of the SourceX five-step transaction, vendor agreements are reviewed alongside customer contracts, and the export manifest becomes part of the provenance record in the SourceX Evidence Packet. The supplier approves every step, and large archives stay in its own storage.
Vendor terms matter here because a visibility vendor that has already used your tracking events in pooled benchmarks or models may hold rights that overlap with what a buyer wants. The rights review identifies that overlap before any sample is discussed, so the supplier is not surprised late in a transaction.
Frequently asked questions
Can the vendor refuse to let us export our data?
That depends on your contract. Many agreements give customers the right to export their data during the term and at termination, sometimes only in set formats or for a fee. If the terms are vague, ask in writing now, while both sides are focused on keeping customers through the transition.
Does the acquirer automatically get our data?
Not automatically in the sense of new rights, but it does gain control of the systems that hold your records. In a stock purchase the vendor entity, its contracts and the data it hosts usually stay together under new ownership; in an asset purchase, contracts are typically assigned to the buyer, which is where the assignment clause matters. Either way, the existing terms generally govern use until they are amended, which is why updated terms deserve careful review.
Should we keep a read-only license if the platform is retired?
If your archive export is complete and readable without the platform, you may not need one. If key history only makes sense inside the application, such as linked documents or event timelines, a read-only arrangement for a defined period can be worth negotiating.
Do our carrier integrations move with the platform?
Not necessarily. Carrier connections often rely on separate agreements and technical setups that must be rebuilt on a new platform. List which carriers feed which data so you can check coverage after any migration and spot gaps quickly.
What if the acquirer plans to shut the product down?
Treat a sunset announcement as the start of your exit plan. Confirm the shutdown date and export deadline in writing, complete and test your archive well before it, and ask whether the acquirer will offer migration tools or transition help. Avoid signing new terms for the replacement product until counsel has compared them with your current agreement.
Sources
- The Data & Trust Alliance's Data Provenance Standards (version 1.0.0 specification) define dataset metadata in three groups: Source, Provenance and Use. Source
Related resources
See if your company qualifies
A short company assessment. No data uploads are needed.