Standfast Commerce

Export before you are terminated

A one-afternoon checklist for Shopify stores selling glass, vaporizer hardware, cigars, kratom or CBD. 420.com worked through this exact list when it exported from Shopify in September 2026.

Why this exists. Shopify enforces its ENDS rule by private email to each store, with a short removal window. Section 14 of Shopify's Terms of Service lets Shopify terminate "for any reason, without notice and at any time", after which "you will no longer be able to access your Account" and "your Shopify Store will be taken offline." There is no export right in that section. The notice reads "regardless of nicotine content." What the notice says.

Part 1: Export today, in this order

  1. Products. Products, then Export, then All products, plain CSV, all columns. Open the header row and check whether your metafields are there. Keep the file.
  2. Customers. Customers, then Export, then All customers. No passwords are in it, ever; no platform can export them.
  3. Orders. Orders, then Export, then All orders. Large exports arrive by email; wait for the file.
  4. Discounts. Discounts, then Export. Check that your automatic discounts are in the file — automatic discounts are not always included and may need to be written down by hand.
  5. URL redirects. Online Store, then Navigation, then URL redirects, then Export.
  6. Gift cards. Products, then Gift cards, then Export. Note the outstanding balances; on any new platform they become codes, not cards.
  7. Theme. Online Store, then Themes, then Actions, then Download theme file. The theme itself will not run elsewhere; the images and copy inside it will.
  8. Pages and blog posts. There is no CSV. Copy each page's text, and each post's text and image, into a folder.
  9. Photographs. The product CSV holds cdn.shopify.com links only. Download every image now. The links die with the account.
  10. Reviews. Export from Yotpo, Judge.me, Stamped or whichever app you use. If the app prints reviews into the page, they can also be read from the public site while it is up.
  11. Subscriptions. Export the subscriber list from Loop, Recharge or Shopify Subscriptions. Stored cards do not move; every subscriber will re-enter a card once, on any platform.
  12. Flow. Screenshot every workflow, with its on/off state.
  13. Google Merchant Center. Note that the Shopify Google app generates your feed. It stops with Shopify.
  14. Your Shopify notice email. Save it, with the date.

Part 2: The merchant account. Start today; it takes weeks

  1. Find out which gateway you use now. Shopify Payments refuses tobacco and cannabis-related goods, so most stores in these categories already run a third-party gateway such as Authorize.net or NMI.
  2. Get a written quote from a high-risk processor. Ask for the rate, the reserve percentage and hold period, the contract length, the early-termination fee and the chargeback fee. Ask for month to month. A rolling reserve of 5% to 10% held 90 to 180 days is normal in these categories.
  3. Ask whether the account can run on Authorize.net. Most high-risk processors offer it, and it is what most hosted alternatives, including ours, connect to.
  4. Publish the policy pages underwriters look for on your current site: refund, shipping, terms, privacy and a contact page.

Part 3: Access you must hold yourself

  1. Domain registrar login. Who has it, and is two-step on.
  2. DNS. Which account holds the zone: Cloudflare, GoDaddy, or an agency.
  3. App logins. Klaviyo, ShipStation, AgeChecker, Authorize.net, your review app, your loyalty app, each with an owner you control.

Part 4: Do not do these

  1. Do not cancel Shopify until your last Shopify-paid order has shipped and every order has synced to the new store. Keep the plan read-only for 30 days for a final export.
  2. Do not generate a new Authorize.net Transaction Key early. Generating one can invalidate the key your live Shopify checkout is using. Authorize.net lets the old key run for 24 hours after a new one is made unless you tick "disable immediately"; use that overlap on switch day, not before.
  3. Do not email your customer list about a move until the new store's login and password reset are working.

Part 5: What a hosted move looks like, so you can compare offers

  1. Products load with their Shopify handles, so every indexed URL keeps working.
  2. Customers and orders load as history; nothing is re-charged or re-emailed.
  3. Discount codes, redirects, reviews, blog posts and policy pages load.
  4. Customers set a password once, or sign in by emailed code.
  5. Subscribers get one link to re-enter a card.
  6. Your Klaviyo flows come across as drafts under the same event names; you switch them on. Segments are rebuilt on the new event names.

If you would like us to read your export, the free dry run is here. Send the products CSV; within 48 hours you get a private preview and the importer's problem list. Nothing signed.

Sources

This checklist reflects 420.com's own September 2026 export, item by item. No newsletter is attached to this page.