Alex is Sprintlaw’s co-founder and principal lawyer. Alex previously worked at a top-tier firm as a lawyer specialising in technology and media contracts, and founded a digital agency which he sold in 2015.
Many New Zealand businesses sign e commerce service agreements too quickly, especially when a provider says the terms are “standard” or the deal needs to be done this week.
The usual problems are predictable: founders rely on sales promises that never make it into the contract, they accept vague service levels with no real remedy, or they miss clauses that let the provider change pricing, suspend the account, or use subcontractors without much warning.
That matters because an e commerce provider often sits right in the middle of your sales process. If the platform goes down, if payments are delayed, if customer data is mishandled, or if the integration does not do what you expected, the commercial damage can be immediate. A short contract review before you sign can save a long argument later.
This guide explains what e commerce service agreements usually cover, the main legal issues New Zealand businesses should check before accepting a provider’s standard terms, and the mistakes that most often cause trouble once trading is underway.
Overview
E commerce service agreements set the rules for how a provider will deliver online selling, payment, fulfilment, software, marketing, hosting, support, or marketplace services to your business. A good agreement should match how your business actually operates, not just how the provider markets its product.
Before you sign, the contract should clearly deal with scope, service standards, fees, data, intellectual property, liability, and exit rights. If any of those areas are vague, the risk usually falls back on your business.
- Define the exact services, features, integrations, and deliverables.
- Check pricing, renewals, minimum terms, and any right to increase fees.
- Set service levels, support times, outage processes, and remedies.
- Confirm who owns data, content, custom development, and intellectual property.
- Review privacy, security, and subcontracting obligations.
- Check termination rights, transition support, and data return on exit.
- Limit reliance on verbal promises by recording key commitments in written terms.
- Make sure liability caps, indemnities, and exclusions are commercially fair.
What Service Agreements Cover
An e commerce service agreement should say exactly what the provider is doing, what your business must do, and what happens if either side falls short.
That sounds basic, but this is where founders often get caught. A provider may sell an all-in-one solution, but the contract might only promise access to a platform, not setup, migration, optimisation, or custom integration work. If the signed terms do not reflect the sales pitch, your leverage drops fast.
Scope of services
The scope clause should describe the services in practical detail. Before you sign a contract, check whether the provider is supplying software only, ongoing managed services, implementation support, payment processing, marketplace access, fulfilment tools, or some mix of those things.
Useful detail often includes:
- which modules or features are included
- which integrations are part of the deal
- whether setup, migration, testing, or training is included
- who is responsible for third party systems
- what assumptions the provider has made about your systems and data
If a service description is broad and promotional, ask for a schedule that spells out the deliverables. This is especially important before you spend money on setup or commit internal staff to a migration timetable.
Service levels and support
If the service is business critical, uptime and support terms should be concrete, not aspirational.
For many online retailers and digital businesses, even a few hours of downtime during a promotion or peak trading period can have a real cost. Your agreement should deal with:
- target uptime or availability
- planned maintenance windows
- incident response times
- support hours and channels
- escalation steps for major outages
- service credits or other remedies if standards are missed
A contract that promises “reasonable efforts” with no response times or remedies often gives you little practical protection when things go wrong.
Fees and payment terms
Fee clauses need more than a headline monthly price. The real question is what triggers extra charges.
Check for:
- setup or onboarding fees
- implementation charges
- transaction or usage based fees
- gateway or payment processing deductions
- annual uplift clauses
- currency conversion issues
- charges for additional users, support, or storage
- automatic renewal terms
Many disputes start because a business assumes the quoted fee covers all ordinary use, then finds out key features or support levels sit outside the base package.
Data, privacy, and security
If the provider handles personal information, customer behaviour data, payment data, or order history, the contract should clearly allocate privacy and security responsibilities.
In New Zealand, privacy compliance is not just a technical issue. Businesses need to understand who is collecting information, who is storing it, where it is hosted, who can access it, and what happens if there is a privacy incident. The agreement should cover:
- what data the provider can access and use
- whether the provider acts only on your instructions or may use data for its own purposes
- security measures and incident notification obligations
- cross border storage or processing
- subcontractors or cloud providers used by the provider
- data return, deletion, or export rights at the end of the term
If the contract is silent on these issues, your business may still carry customer-facing responsibility under the Privacy Act 2020, even if the provider caused the problem.
Intellectual property and content
Ownership should be clear before you rely on a platform, invest in content, or pay for custom work.
A provider will usually keep ownership of its pre-existing software and systems. That is normal. The more important question is who owns:
- your store content, branding, and product data
- custom templates or workflows built for your business
- new integrations or modifications funded by you
- reports, analytics, or derivative data generated from your use
If your business is paying for development, the agreement should say whether you receive ownership, a licence, or only access while the subscription continues. This also matters if you want to switch providers later.
Term, termination, and exit
The best time to negotiate an exit is before you sign.
Founders often focus on getting started and overlook what happens if the provider underperforms, changes pricing, or no longer suits the business. Your contract should cover:
- the initial term and any renewal process
- termination for breach and for convenience
- cure periods
- suspension rights
- what assistance the provider must give on exit
- how quickly data will be returned or made available for transfer
- whether there are termination fees or notice requirements
If the agreement locks you in but gives the provider wide discretion to change features or pricing, that imbalance is worth addressing before you accept the provider’s standard terms.
Legal Issues To Check Before You Sign
The main legal issue is not whether the agreement looks professional. It is whether the legal risk matches the value of the deal.
Many e commerce contracts are drafted to favour the supplier. That is expected. What matters is whether the clauses are still workable for your business in a real founder moment, such as a failed integration, a cyber incident, a delayed launch, or a payment hold.
Contract formation and authority
Make sure the right entity is signing and that the order form, statement of work, and standard terms actually line up.
This sounds administrative, but mistakes here are common. A quote may be issued to one company, the online acceptance may be made by another entity, and the attached terms may refer to a different package. If you trade through a New Zealand company, check the contract uses the correct legal name and Companies Office details. If your group has more than one trading entity, confirm which one is taking on the risk.
Fair Trading Act risk
Marketing claims made by a provider can matter legally, but it is far safer to record the key promises in the contract.
Under the Fair Trading Act 1986, misleading or deceptive conduct in trade can create problems. Still, no business wants to rely on a legal argument about pre-contract statements if it can be avoided. Before you rely on a verbal promise about migration timing, SEO performance, conversion uplift, fraud controls, or integration compatibility, ask for the commitment to be written into the agreement or a statement of work.
Consumer and customer obligations
Your provider agreement does not remove your obligations to your own customers.
If you sell goods or services online, your business may still need to comply with consumer law, including obligations under the Consumer Guarantees Act 1993 and the Fair Trading Act. That means you should check whether the provider’s processes help or hinder your compliance. For example:
- can you issue refunds efficiently
- can you update pricing and product information quickly
- does the checkout process create inaccurate impressions
- can you access order records if a customer complaint arises
If the provider’s system limits what you can do, the commercial fallout usually lands with your business first.
Privacy Act compliance
If personal information is involved, the agreement should support your privacy obligations in practice, not just mention security in general terms.
New Zealand businesses that collect customer details, shipping information, account credentials, or marketing preferences need to think carefully about privacy allocation. Before you sign, clarify:
- what personal information will be processed
- whether any information will be stored offshore
- what happens if there is an eligible data breach or other privacy incident
- how quickly the provider must notify you
- whether you can audit, request information, or require remedial steps
This is particularly important if your e commerce setup involves multiple providers, such as a storefront platform, payment processor, CRM, logistics software, and email marketing tool, and your own privacy notice needs to reflect those arrangements.
Liability caps and exclusions
The most expensive clause in the agreement is often the one you barely notice.
Many providers cap their liability at a very low amount, sometimes just the fees paid in the previous month or quarter. They may also exclude indirect loss, loss of profit, data loss, and service interruption. Some exclusion wording is standard, but the question is whether the overall allocation is reasonable in light of the risk.
Before you sign, consider:
- what losses your business could realistically suffer if the service fails
- whether there should be separate treatment for confidentiality, privacy breaches, or IP infringement
- whether credits alone are an adequate remedy
- whether the liability cap should be higher for implementation work or custom development
A low-value plugin may justify a light-touch approach. A central commerce platform usually deserves more care.
Intellectual property infringement and licensing
You should know what rights you receive and what happens if someone alleges the service infringes their intellectual property.
Look for licence restrictions, limits on users or territories, and clauses that let the provider suspend access if it believes there is misuse. Also check whether the provider gives an indemnity if its software infringes another party’s IP rights, and whether that indemnity has carve-outs that make it hard to use.
If your business name, logo, or brand assets appear in the service, confirm you are only granting the provider the narrow rights it needs to perform the contract. Your broader trade mark and branding rights should remain yours.
Subcontracting and offshore supply chains
Many e commerce services are delivered through layers of subcontractors. That is not necessarily a problem, but it should not be invisible.
If core services are outsourced, ask whether the provider remains fully responsible for subcontractor performance, security, and confidentiality. You should also understand whether support, hosting, or data processing occurs outside New Zealand, because that may affect privacy disclosures and operational risk.
Common Service Agreement Mistakes
Most problems with e commerce service agreements do not come from exotic legal issues. They come from ordinary commercial assumptions that were never properly documented.
Accepting standard terms without matching them to the deal
A provider’s standard terms are a starting point, not proof that the contract suits your business.
This is a common issue where the sales process was customised but the legal terms were generic. If you negotiated a tailored implementation plan, migration support, priority service desk access, or a phased rollout, those points need to appear in the signed documents.
Relying on verbal promises
If a promise matters to the decision, it should be written down.
Founders often rely on calls or demos where the provider says the system “can definitely do” something. Later, the written contract may include an entire agreement clause that says the business cannot rely on earlier discussions.
The fix is simple: record key assumptions, milestones, and functionality in the contract, order form, or statement of work.
Ignoring exit mechanics
Switching providers is usually harder than businesses expect.
If your data export rights are unclear, or the provider has no obligation to assist with transition, you may face delay, extra cost, or operational disruption. Before you sign, ask what format data will be returned in, how long access continues after termination, and whether any transition services are available.
Overlooking internal obligations
Your team may need to do more under the contract than you realise.
Many agreements make service levels conditional on the customer meeting its own obligations, such as timely approvals, providing clean data, maintaining third party licences, or using supported browsers and plugins. If your team cannot meet those assumptions, the provider may have an easy answer when deadlines slip.
Missing automatic renewals and price changes
Renewal and variation clauses can quietly reshape the deal.
Some agreements renew automatically unless notice is given in a short window. Others allow fee increases on renewal or even during the term. Put those dates into your contract management process so the business can review pricing and performance before it is locked in again.
Not checking consistency across documents
Order forms, online terms, service descriptions, and policies often conflict.
Where there are multiple documents, the contract should say which one prevails if they are inconsistent. Without that, a useful commercial commitment in one document may be undercut by a broad disclaimer elsewhere.
Treating legal review as optional for critical systems
The more central the service is to your revenue, customer experience, or data, the less sensible it is to skip review.
You may not need heavy negotiation for every small SaaS tool. But if the agreement covers your core storefront, payment flow, marketplace operations, fulfilment software, or customer data stack, a targeted legal review before you sign is usually worth it.
FAQs
Do all New Zealand businesses need a written e commerce service agreement?
No, but a written agreement is strongly recommended whenever a provider is handling core online sales functions, customer data, payments, integrations, or custom implementation work. Without clear written terms, disputes about scope, fees, delays, and responsibility are much harder to resolve.
Can I just accept the provider’s online terms?
Sometimes, but you should review them first if the service is important to your operations. Online terms often contain strict liability limits, automatic renewals, broad suspension rights, and weak exit support.
Who owns customer data under an e commerce agreement?
The contract should say. Many providers acknowledge that the customer owns or controls its business data, but they may still claim rights to use aggregated, anonymised, or service-generated data. Check the wording carefully before you sign.
What if the provider stores data outside New Zealand?
That can be workable, but you should understand where the data goes, which subcontractors are involved, and what privacy and security protections apply. Your business may still need to address offshore handling in its own privacy disclosures and internal compliance steps.
When should I get legal help reviewing the agreement?
Get advice if the provider is central to revenue, customer experience, or personal information handling, if there is custom development or implementation work, or if the contract has long minimum terms, high spend, or one-sided risk allocation. The earlier you review it, the easier it is to negotiate sensible changes.
Key Takeaways
- E commerce service agreements should clearly define scope, service levels, fees, data handling, IP rights, liability, and exit arrangements.
- The main risk is assuming the provider’s sales promises will protect you if the signed contract says something else.
- New Zealand businesses should check how the agreement interacts with privacy obligations, customer-facing consumer law responsibilities, and Fair Trading Act risk.
- Low liability caps, vague support terms, automatic renewals, and poor data export rights are common pressure points.
- Before you accept the provider’s standard terms, make sure the contract reflects how your business actually uses the service and what would happen if it failed.
If you want help with contract terms, privacy obligations, liability clauses, exit rights, you can reach us on 0800 002 184 or team@sprintlaw.co.nz for a free, no-obligations chat.
Lock in the contract
Turning the information into a usable contract
Once money, deliverables or customer obligations are involved, the next step is usually a clear contract that matches how the business actually works.






