Blog
Website Maintenance Contract Checklist for Canadian Agencies
A vague maintenance contract is how a five-minute plugin update turns into a Friday night argument about who was responsible.
If your agency sells WordPress care plans, the contract matters as much as the technical work. It sets client expectations, protects your margin, and gives you something concrete to point to when a client asks why a redesign, malware cleanup, or custom feature is not included in a basic maintenance fee.
This checklist is written for Canadian agencies managing WordPress sites for small business, professional services, WooCommerce, nonprofits, and local organizations. It is not legal advice, but it will help you spot the clauses your lawyer, ops person, or white-label maintenance partner should review before you send another monthly care agreement.
Start With the Basics
Before you get into backups, updates, or support times, make sure the contract clearly identifies who is involved.
- Client legal name: Use the business or organization name, not just the contact person.
- Agency legal name: Use your incorporated or registered business name if applicable.
- Website covered: List the exact domain or subdomain.
- Start date: State when the maintenance service begins.
- Billing cycle: Monthly, annual, or another agreed structure.
- Primary contact: Name the person authorized to request work and approve changes.
This sounds obvious, but it prevents scope creep later. If the client owns three sites and only one is covered, the contract should say that plainly.
Tip: If you manage multiple sites for one client, list each site separately with its own scope. One agreement can cover them all, but each site should have its own maintenance expectations.
Define What “Maintenance” Actually Means
Clients often hear “maintenance” and assume it means everything short of a full rebuild. Agencies know that is not realistic.
Your contract should define maintenance in plain language. Avoid fuzzy phrases like “ongoing website support” unless you explain exactly what that includes.
Common items to include
- WordPress core updates
- Theme updates
- Plugin updates
- Backup monitoring
- Security monitoring
- Uptime monitoring
- Basic performance checks
- Small content edits
- Broken link checks, if included
- Form testing, if included
- WooCommerce checkout testing, if included
- Monthly reporting, if included
Do not just list services. Define the frequency and limits. “Plugin updates” could mean daily, weekly, monthly, or only when requested. “Edits” could mean ten minutes of text changes or an entire landing page build.
If you are still shaping your agency plans, this related guide may help: White Label WordPress Maintenance for Agencies: What to Include in Client Plans.
Separate Maintenance From Development
This is one of the most important sections in the whole contract.
Maintenance keeps the existing site healthy. Development changes what the site does. If you blur those together, your monthly plan can quietly become unlimited web development at a discounted rate.
Usually maintenance
- Updating WordPress, plugins, and themes
- Replacing a staff photo
- Fixing a minor layout issue after an update
- Updating business hours
- Adding a short announcement
- Checking whether a contact form still sends properly
Usually not maintenance
- New page designs
- New custom post types
- New booking, membership, portal, or LMS features
- Major WooCommerce changes
- Copywriting
- SEO campaigns
- Accessibility remediation projects
- Full redesigns
- Custom plugin development
There is nothing wrong with doing development work for maintenance clients. Just quote it separately or bill it at an agreed hourly rate.
Ambrite handles this distinction in its own maintenance terms by including monthly edit time on care plans, then billing extra work at $50/hour when the included time is exceeded. Ambrite’s WordPress maintenance plans are month-to-month, with Care at $49/month per site, Growth at $99/month per site, and Complete at $199/month per site, all in CAD.
Spell Out Edit Time
Edit time is where many agency maintenance contracts get messy.
If you include edits, answer these questions in the contract:
- How many minutes or hours are included each month?
- What counts as an edit?
- Does unused time roll over?
- Who can request edits?
- What happens when the included time is used up?
- Are edits based on the request date or completion date?
- Are emergency edits treated differently?
Be specific. “Minor edits included” is not specific enough.
A better clause would say something like: “The plan includes up to 30 minutes per month for small edits such as text changes, image swaps, plugin settings, and minor layout fixes. Unused time does not roll over. Larger changes are quoted separately or billed at the agreed hourly rate.”
That language is clear enough for a client to understand and practical enough for your agency to enforce.
Set Update Rules Before Something Breaks
WordPress updates are routine, but they still carry risk. A plugin can conflict with another plugin. A theme can remove support for an older function. A WooCommerce extension can change checkout behaviour.
Your contract should explain how updates are handled.
- How often updates are applied
- Whether updates are automatic, manual, or reviewed first
- Whether a backup is taken before updates
- Whether updates are tested on staging
- Which sites qualify for staging-tested updates
- What happens if an update causes a visible issue
- Whether abandoned plugins may be replaced
For lower-cost plans, it may be reasonable to apply routine updates directly after a backup. For higher-risk sites, especially WooCommerce, membership, learning, booking, or high-traffic sites, staging is safer.
For agencies managing many sites, this guide is worth reading alongside your contract language: How to Manage WordPress Updates Across Multiple Client Websites.
Define Backup Frequency and Retention
Backups are only useful if everyone knows what they cover and how far back they go.
Your contract should include:
- Backup frequency, such as daily or weekly
- Backup retention period
- Whether backups include files, database, uploads, or email
- Where backups are stored, in general terms
- Who can request a restore
- Whether restore work is included or billable
- Any limits around restoring old versions
Be careful with promises. Do not say “we can restore anything at any time” unless your actual systems support that. A safer promise is to state the retention period and the restore process.
Ambrite’s WordPress maintenance plans include daily backups kept for 90 days. Ambrite hosting backups vary by plan, with weekly backups on Starter hosting and daily backups on Business and Pro hosting.
Be Honest About Security
Security language should be strong, but not magical.
No maintenance contract should promise that a site will never be hacked, never go down, or never have a plugin conflict. That is not how WordPress, hosting, DNS, third-party APIs, or the internet work.
Instead, your contract should say what you actively do to reduce risk:
- Keep WordPress, themes, and plugins updated
- Monitor for malware or suspicious changes
- Monitor uptime
- Use strong administrator access practices
- Recommend two-factor authentication
- Remove unused plugins and themes where appropriate
- Use firewall or CDN protection where included
- Keep reliable backups
You should also say what happens if malware is found. Is cleanup included? Is it billed separately? Are third-party security review costs excluded? Does the client need to approve emergency work?
At Ambrite, hack and malware cleanup is included with the Complete Plan. On Care and Growth, one-off cleanup starts at $499 CAD, depending on severity, and is usually finished within 24 to 48 hours. That kind of distinction belongs in a maintenance contract because it avoids panic pricing discussions during a stressful incident.
Include Canadian Privacy and Compliance Responsibilities
Canadian agencies should not ignore privacy language. Most client websites collect at least some personal information through contact forms, intake forms, quote requests, newsletter signups, analytics, appointment forms, or checkout pages.
Your contract should explain who is responsible for:
- Website privacy policy content
- Cookie and analytics disclosures
- Consent language on forms
- CASL compliance for email signups and commercial messages
- PIPEDA-related privacy obligations
- Data processing by third-party plugins and services
- Responding to access or deletion requests from users
- Legal review of policies and compliance language
Most agencies should not pretend to be privacy lawyers. A practical contract says you can implement forms, checkboxes, cookie tools, and technical settings, but the client is responsible for obtaining legal advice and approving compliance wording.
For Canadian privacy basics, see How to Comply with PIPEDA: Essential Privacy Policy Requirements for Canadian Websites.
Clarify Hosting Responsibilities
Maintenance and hosting are related, but they are not the same thing.
If your agency also hosts the client site, your contract should cover uptime, backups, storage, bandwidth, email, SSL, DNS, server security, and migration procedures.
If the client uses third-party hosting, your maintenance contract should say that some problems are outside your direct control. Slow server response, host outages, DNS issues, email account problems, and server-level restrictions may require cooperation from the hosting provider.
Include language for:
- Who owns the hosting account
- Who pays hosting invoices
- Who controls DNS
- Who manages SSL certificates
- Who creates email accounts
- Who handles host-level downtime
- Whether migration support is included
For clients that care about Canadian data residency, mention whether hosting is in Canada. Ambrite’s cloud web hosting runs on Canadian infrastructure and includes LiteSpeed, NVMe SSD storage, free SSL, and Canadian support. Pricing starts at $7.99/month CAD for Starter hosting, with Business at $14.99/month CAD and Pro at $29.99/month CAD.
Set Support Channels and Response Targets
Clients need to know how to ask for help. Agencies need to avoid support requests scattered across texts, social media messages, personal inboxes, and hallway conversations.
Your contract should list the approved support channels. For many agencies, that means ticket and email support only.
Define:
- Where requests must be sent
- Who may submit requests
- What information the client should include
- Expected response targets
- Emergency request handling
- After-hours limits
- What counts as urgent
Be careful with “24/7 support” wording. Monitoring can run around the clock, but that is not the same as promising a human reply at any hour.
Ambrite support is provided by email and through the client area. Care aims for replies within 24 hours, Growth has faster replies, and Complete requests come first. Those are response targets, not guarantees.
Define What Counts as an Emergency
Not every urgent-feeling request is a real emergency.
Your contract should define emergency categories, such as:
- The site is completely down
- Checkout is not working
- Forms are not delivering on a lead-critical site
- Visitors see malware or browser warnings
- A payment or booking flow is broken
- A public page is showing sensitive information
Then define what is not usually an emergency:
- A typo on a low-traffic page
- A requested design tweak
- A new landing page needed quickly
- A third-party platform outage
- A marketing campaign that was planned late
This does not mean you cannot help quickly when you want to. It means the contract protects you from every client request becoming a crisis.
Handle WooCommerce Separately
WooCommerce sites need stronger contract language than brochure sites.
A store has orders, payment gateways, tax settings, shipping rules, inventory, transactional emails, subscriptions, refunds, customer accounts, and sometimes fraud tools. A plugin update that barely matters on a simple brochure site can affect revenue on a store.
Your WooCommerce maintenance contract should cover:
- Checkout testing frequency
- Payment gateway monitoring limits
- Shipping plugin update handling
- Tax plugin and configuration responsibility
- Subscription renewal monitoring, if applicable
- Order email deliverability checks
- Staging requirements for major updates
- Who handles refunds, disputes, and gateway account issues
Do not promise that every order issue is a website issue. Sometimes the problem is a payment processor setting, card issuer decline, shipping API outage, expired account credential, tax configuration change, or customer error.
For stores, Ambrite’s Growth and Complete maintenance plans are the better fit. Growth includes a WooCommerce health check covering plugins and payments, while Complete adds form, cart, and checkout testing after major updates.
Include Reporting Without Creating Busywork
Clients like reports when reports explain what changed and why it matters. They do not need a wall of plugin names with no context.
If reporting is included, define the frequency and contents:
- Updates applied
- Backups confirmed
- Security scan summary
- Uptime notes
- Performance observations
- Completed edit requests
- Recommended follow-up work
Keep the language human. “Three plugins updated, no visible issues found, contact form tested successfully” is more useful than a technical export the client will never read.
If you white-label maintenance, decide whether reports come from your agency brand, the maintenance partner, or not at all. Put that in your internal process, even if it does not appear in the client-facing contract.
Cover Access and Credentials
You cannot maintain a site you cannot access.
Your contract should require the client to provide and maintain the access needed to deliver the service. That may include WordPress administrator access, hosting access, DNS access, domain registrar access, analytics access, search console access, plugin licence access, or payment gateway access.
Also include security expectations:
- No shared administrator passwords
- Use named accounts where possible
- Use strong passwords
- Use two-factor authentication where practical
- Remove old staff accounts promptly
- Notify the agency before changing DNS, hosting, or admin access
If the client changes passwords or removes access, your contract should say that affected services may be paused until access is restored.
List Client Responsibilities
A good maintenance contract does not put every responsibility on the agency.
The client should be responsible for:
- Providing accurate content
- Approving legal and compliance wording
- Keeping billing information current
- Maintaining third-party accounts they own
- Not installing random plugins without notice
- Not giving admin access to untrusted users
- Reviewing completed work in a reasonable time
- Renewing paid plugin licences if licences are owned by the client
- Notifying the agency about business-critical pages or integrations
That last point matters. If a client has a custom integration, fragile plugin, or business-critical form, you need to know before routine updates happen.
Put Pricing, Taxes, and Payment Terms in Writing
Your contract should be clear about money.
For Canadian agencies, pricing should state the currency, usually CAD, and mention applicable taxes such as GST, HST, or PST depending on your situation and the client’s location.
Include:
- Monthly or annual fee
- Currency
- Applicable taxes
- Invoice due date
- Accepted payment methods
- Late payment consequences
- Hourly rate for out-of-scope work
- Minimum billing increments, if any
- Price change notice period
Avoid hiding the out-of-scope rate. If a client knows in advance that extra work is billable, the conversation is much easier later.
Cancellation and Refund Terms
Maintenance plans should explain how cancellation works before anyone wants to cancel.
Cover:
- Whether the plan is month-to-month or fixed term
- How cancellation must be requested
- Whether unused time is refundable
- What happens to backups after cancellation
- What happens to premium licences provided by the agency
- How DNS, CDN, or email routing is handed back
- Whether migration help is included or billable
Ambrite’s maintenance plans are month-to-month with no long-term contract and no cancellation fee. Cancelling stops future billing, and the plan stays active until the end of the paid period. Plan fees are non-refundable.
White-Label and Subcontractor Language
If your agency uses a white-label WordPress partner, do not leave that relationship to assumptions.
Internally, decide:
- Whether the client knows a subcontractor is involved
- Who communicates with the client
- Whose branding appears on reports
- Who owns support documentation
- Who is responsible for mistakes
- Who carries insurance, if applicable
- How access is granted and revoked
- Whether the partner can contact the client directly
Client-facing contracts often say the agency may use qualified subcontractors to deliver services while remaining responsible for the client relationship. Ask your lawyer how that should be worded for your province and business structure.
Ambrite provides white-label WordPress builds, hosting, and maintenance for agencies, with one point of contact and support handled by ticket and email. If that fits your agency model, you can ask about partner work through the contact page.
When Not to Offer a Maintenance Contract
Not every site is a good fit for a care plan.
Be cautious if:
- The site is already badly infected and the client only wants cheap updates
- The theme is abandoned and breaking apart
- The client refuses backups or security changes
- The site depends on outdated custom code nobody understands
- The client wants unlimited edits for a low monthly fee
- The client will not provide access
- The client expects guaranteed rankings from maintenance
- The hosting environment is too poor to support the site reliably
Sometimes the honest recommendation is a cleanup, rebuild, migration, or paid audit before a maintenance plan begins. That may cost more upfront, but it is better than selling a monthly plan you cannot deliver properly.
A Practical Contract Checklist
Use this as a final review before sending your next maintenance agreement.
- Client name, agency name, and covered website are listed correctly.
- The maintenance scope is specific, not vague.
- Update frequency and process are defined.
- Backup frequency and retention are stated.
- Security monitoring is described honestly, without impossible guarantees.
- Malware cleanup is clearly included or excluded.
- Edit time is defined with limits.
- Out-of-scope work has an hourly rate or quote process.
- Support channels are listed.
- Response targets are realistic and not absolute guarantees.
- Emergency situations are defined.
- WooCommerce responsibilities are separate if the site sells online.
- Hosting responsibilities are clear.
- DNS, CDN, SSL, and email responsibilities are clear.
- Client responsibilities are included.
- Privacy, PIPEDA, CASL, and legal content responsibilities are addressed.
- Third-party plugin and service limitations are covered.
- Billing, taxes, late payment, and cancellation terms are written plainly.
- White-label or subcontractor arrangements are handled properly.
- The client knows what happens when the plan ends.
A good maintenance contract does not need to be scary or full of legal fog. It should answer the questions that cause arguments later: what is included, what is not, who is responsible, how fast help arrives, and what happens when something falls outside the plan.
If your agency wants to keep the client relationship but outsource the WordPress maintenance work behind the scenes, Ambrite can help with Canadian white-label maintenance, hosting, and WordPress support. Keep the contract clear, keep the scope honest, and your monthly care plans will be much easier to sell and much easier to deliver.
This article was written with the help of AI and reviewed by Ambrite. Pricing, features, and technical details may change, so always verify with official sources before making decisions.
Was this article useful?
Related Articles
Your WordPress site loads in 8 seconds on mobile. Meanwhile, your competitor's site loads in 2...
Running a restaurant in 2026 means juggling a thousand things at once. Your WordPress site...
Your WordPress site has 47 active plugins and takes 8 seconds to load. Sound familiar? Plugin...
Your real estate website is more than just a digital business card: it's a 24/7 sales machine...
Your staff page hasn't been updated since Jessica left in 2022, and your services page still...
