TrustExits

What Documents Do You Need to Sell an Online Business?

Etienne Hurpin, Founder of TrustExits · · 12 min read

Sellers ask for a document checklist. Buyers ask for access. Those are not the same request — and conflating them is why LOIs die in week three when someone discovers the Meta billing export does not match the P&L PDF.

This guide is the document stack for selling an ecommerce business in 2026: what to prepare, what to grant read-only, what to keep legal until LOI, and why connected verification beats a folder of screenshots. I wrote it for Shopify and DTC operators exiting between $50k and $2M. Same structure applies to WooCommerce and hybrid wholesale — adjust labels, not logic.

What Documents Do You Need to Sell an Online Business?

Two tiers: marketing packet vs diligence room

Split your materials into two tiers before you list. Mixing them creates either oversharing (competitors scrape your ad creative) or undersharing (buyers bounce because the listing feels opaque).

Tier 1 — Listing packet (public or NDA-light)

Enough for a buyer to decide if they want a call. No raw customer PII. No full ad account exports.

  • One-page business summary: niche, geo, SKU count, fulfillment model, owner hours/week.
  • Trailing twelve-month summary P&L — high level, reconciled to verified connections if on TrustExits.
  • Channel mix chart: % revenue Meta, Google, email, organic, other.
  • Verification status: profit verified badge, channel flags disclosed upfront.
  • Asking price logic: SDE multiple band, not revenue fantasy (SDE vs EBITDA vs Revenue Multiple).

Tier 2 — Diligence data room (post-LOI or serious buyer)

Everything a buyer needs to confirm Tier 1. Prefer read-only platform access over static exports where possible. PDFs supplement connections; they do not replace them.

The sections below map Tier 2 in detail.

Financial documents

Buyers rebuild SDE from primary sources. Your job is to make reconstruction boring — no surprises.

Required

  • 12-month P&L (monthly granularity): revenue, COGS, gross margin, ad spend, shipping, payment fees, software, contractor, owner comp line.
  • Balance sheet snapshot if inventory or liabilities material: stock value, AP, loans, processor reserves.
  • Tax returns or accountant letter (last 1–2 years) for deals above $250k — aligns declared vs operational SDE.
  • SDE add-back schedule with receipts for every item over $2k.
  • Read-only payment processor access: Stripe, PayPal, Shopify Payments — viewer role, not admin.
  • Shopify (or platform) reports access: sales, refunds, discounts, payout reconciliation.

Read-only beats PDF here

A P&L PDF is declarative — you chose the export date and categories. Read-only Stripe + Shopify lets the buyer match deposits to orders without trusting your Excel skills. TrustExits listings pre-connect this chain for profit verification. Sellers who open with connections close faster because buyers skip the "prove it" phase.

If you only send PDFs, expect a 10%–20% SDE variance challenge. That is not buyer aggression; it is standard.

Advertising and channel documents

Channel dependency is half the value story for most DTC exits. Documents here are access grants plus disclosure memos.

Required

  • Meta Business Manager: partner access read-only; disclose personal vs business ad account history.
  • Google Ads + Merchant Center: MCC link read-only; GMC disapproval history screenshot or export.
  • TikTok/Pinterest/other if >10% revenue: same pattern.
  • Monthly ad spend summary TTM matched to P&L line — not dashboard ROAS screenshots alone.
  • Creative ownership note: who shot UGC, licensed music, influencer contracts with usage rights.
  • Channel concentration memo: honest percentages, CPM/ROAS trend narrative, known policy flags.

Why exports fail

Ad platform CSV exports miss billing profile splits, account credit memos, and paused campaign spend that still hit the card. Buyers run due diligence point 4 against billing, not Ads Manager totals. Give billing access or accept retrades.

Operations and supply chain documents

  • Supplier list with lead times, MOQ, payment terms, exclusivity flags.
  • Purchase orders or invoices for top 5 SKUs (redact unrelated SKUs if needed).
  • 3PL or warehouse agreement and inventory count as of last month-end.
  • Shipping rate table vs actual blended cost TTM.
  • Return policy and return rate by SKU band (hero SKU separate).
  • SOP index: fulfillment, CS macros, VA handoff — not every SOP day one, but a table of contents.

Inventory mismatches are post-close escrow fights. A current 3PL portal screenshot plus Shopify inventory export beats a PDF "estimated stock value."

  • Entity formation docs and cap table if multiple owners.
  • Trademark registrations or pending applications; domain WHOIS alignment.
  • Supplier and contractor contracts with assignability / change-of-control language highlighted.
  • Influencer and UGC agreements with content usage rights transferable to buyer.
  • Privacy policy, terms of service URLs and last-updated dates.
  • GDPR/CAN-SPAM evidence for email list source (Klaviyo export of consent metadata if challenged).
  • Platform compliance history: Shopify, Amazon, Meta ad account warnings — disclose, do not hide.

Legal docs stay PDF — that is appropriate. Financial and ads should not be PDF-only.

Customer and brand assets (controlled release)

  • Email/SMS platform: Klaviyo read-only; subscriber counts, flow list, deliverability metrics — not full export pre-LOI.
  • Brand kit: logos, fonts, style guide, Figma links.
  • Social account list with follower counts and whether accounts transfer (personal IG is a problem).
  • Review aggregator stats (Judge.me, Yotpo) — platform access preferred.

Never attach full customer CSV to a public listing. GDPR and deal hygiene both say no.

The minimum viable stack to list on TrustExits

You do not need a 400-file data room to go live. You need verifiable truth:

  1. Shopify + payment processor read-only connected.
  2. Meta and/or Google read-only connected (whichever drives >20% revenue).
  3. COGS inputs for top SKUs — invoice upload or supplier confirmation.
  4. 12-month P&L aligned to connected data (variance explained).
  5. Channel mix disclosure with concentration flags.
  6. Entity proof and domain ownership.

We run profit verification and channel audit on that stack. The listing shows buyers verified SDE, not seller marketing. Deep diligence docs (full SOPs, every contract) come after buyer seriousness — same as any curated marketplace.

PDF theater: what sellers send that hurts them

Common patterns that kill credibility:

  • Shopify revenue screenshot without refund and discount context.
  • Meta Ads Manager ROAS screenshot without billing reconciliation.
  • QuickBooks P&L PDF with ad spend booked quarterly while cards hit monthly.
  • "Estimated" COGS margin without supplier backup on hero SKU.
  • Traffic pie chart from GA without cross-check to Shopify channel report.

Each item is not fraud — often sloppiness. Buyers treat sloppiness as risk premium. Read-only connections are adversarial verification: the platforms disagree with your PDF, and the buyer sees it immediately.

I cover the buyer-side mirror in Ecommerce Due Diligence Checklist. Sellers who pre-empt those 15 checks with connections rank as serious.

Timeline: when to prepare each document

30 days before listing

  • Rebuild monthly P&L from source exports.
  • Connect read-only accounts internally; fix mismatches >5%.
  • Draft channel concentration memo with honest ad dependency.
  • Collect supplier invoices for top SKUs.

Listing week

  • Publish Tier 1 packet on marketplace profile.
  • Pre-stage Tier 2 folder structure (Google Drive or data room tool) with permissions ready — not shared publicly.
  • Write transition SOP outline: ad account transfer, DNS, CS, VA.

Post-LOI

  • Grant Tier 2 access in staged waves (financial first, legal last).
  • Respond to diligence requests in 48-hour SLA — slow sellers get retrades.
  • Keep platforms live; do not restructure ad accounts mid-diligence without disclosure.

Organizing the data room

Folder structure buyers expect:

  • 01_Financials — P&L, balance sheet, tax, SDE schedule, processor access notes
  • 02_Revenue_Platforms — Shopify reports, connection guides
  • 03_Advertising — channel memo, BM access, GMC history
  • 04_Operations — suppliers, 3PL, inventory, shipping
  • 05_Legal — entity, IP, contracts
  • 06_Marketing — email platform, brand assets, social list
  • 07_Transition — SOP index, post-close checklist draft

Name files with dates: PandL_TTM_2025-08.pdf not final_v3_REAL.pdf. Buyers diligence humans, not archaeologists.

What you can withhold until LOI

Reasonable withholds protect you without looking evasive:

  • Full supplier identities (use SKU codes until LOI).
  • Complete contractor agreements with rate tables.
  • Customer-level exports.
  • Unreleased product roadmap.

Unreasonable withholds that kill deals:

  • Ad account any access post-LOI.
  • Payment processor viewer role after price agreement.
  • GMC policy history when Google is >25% revenue.

If you refuse read-only after LOI, buyers assume the worst — often correctly.

Transition documents buyers expect at close

Separate from diligence — close-week materials prevent escrow disputes:

  • Asset transfer checklist signed: Shopify ownership, domain registrar, email DNS, ad BM admin, Klaviyo owner, 3PL contact swap.
  • Training log: dates and topics covered in handoff calls (pixel, catalog, CS queue, supplier intro).
  • Non-compete and consulting agreement if negotiated — executed copies in data room 07_Transition.
  • Inventory count certificate at wire timestamp if stock is material.
  • Processor reserve release timeline from Stripe/PayPal — buyers model cash trapped post-close.

Sellers who pre-draft these in listing prep signal operational maturity. Buyers pay for fewer surprises — sometimes in multiple, always in speed.

How TrustExits reduces document friction

Traditional listing: seller builds data room, buyer distrusts PDFs, both repeat work. TrustExits front-loads profit verification and channel flags via connections at listing time. Your document job shifts from "convince" to "confirm."

Sellers still need Tier 2 for close — contracts, inventory, transition. But Tier 1 is live verification, not theater. That is the moat: profit verified plus channel dependency disclosed before the first buyer email.

Start the seller flow on /sell — connect accounts first, generate the packet second.

FAQ

Do I need audited financials to sell a $100k store?

No. You need reconciled monthly P&L, read-only payment access, and honest SDE add-backs. Audits help above $1M or with institutional buyers.

Can I sell without giving ad account access?

You can list. You will struggle to close with serious buyers. Ad dependency stores require billing-level verification.

PDF P&L enough for Flippa?

Often for initial interest. Not enough for LOI on profitable DTC without retrades. Connections differentiate.

How long to assemble the full stack?

1–3 weeks if books are clean; 4–8 if ad spend was never matched to accounting.

Does TrustExits store my documents?

Verification uses read-only connections and staged uploads. You control Tier 2 release timing post-LOI.

Stop shipping PDF theater. Connect your stack on TrustExits — then list with proof buyers already trust.


Keep going with the cluster - or jump straight into a TrustExits tool.

More on this topic

TrustExits pages worth opening

Ready for numbers, not screenshots?

Run a free estimate or see how we verify profit before a listing goes live.