Skip to content

Wind-downs and transitions

Preserve records before you cancel SaaS subscriptions: a shutdown order of operations

By SourceX Editorial · Updated

Short answer

To preserve records before cancelling SaaS subscriptions, follow a fixed order: freeze deletions, secure admin access before layoffs, export and verify each system, assess what to keep, delete or license, and only then cancel, with identity, email and the domain last. Cancelling in the wrong order is how most shutdown records are lost.

Key takeaways

  • Sequence matters more than speed: freeze, secure access, export, assess, then cancel.
  • Secure admin accounts and recovery codes before the people who hold them leave the company.
  • Deleting a user in a productivity suite can remove that user's mailbox and files unless ownership is transferred first.
  • Cancel in reverse dependency order, keeping single sign-on, email and the domain until every other export is verified.

The order of operations at a glance#

The order of operations runs in five phases, and each system passes through all of them before its cancel date. The table works as a register: one row per system, one owner per row, and a retention window confirmed from the vendor's own terms rather than memory.

Build the register from the accounts payable ledger and the company card statements, not from memory. Tools bought on individual cards, free plans that still hold records and integrations installed by former employees rarely appear on an IT list, and they are where unexpected records surface.

The order of operations at a glance
SystemOwnerExport methodRetention windowCancel when
Help desk (Zendesk, Intercom)Support leadNative export or API, with attachmentsConfirm in vendor terms for your planAfter export is verified and the assessment is decided
CRM (Salesforce, HubSpot)Sales operationsFull data export plus files and activity historyConfirm in vendor termsAfter export is verified and customer obligations are met
Issue tracker and code (Jira, GitHub)Engineering leadProject export and repository clones with full historyConfirm in vendor termsAfter linked issues and reviews are verified
Chat (Slack, Teams)IT or operationsWorkspace export at the highest level the plan allowsConfirm in vendor termsAfter export and channel review
Docs and files (Confluence, Notion, Google Drive)IT or operationsSpace exports, ownership transfer, bulk downloadConfirm in vendor termsAfter all user files are transferred
Finance and payrollControllerReports and ledgers on the accountant's listConfirm in vendor terms and retention lawAfter the custodian holds required records
Identity, email and domainIT leadMailbox exports and directory exportConfirm in vendor termsLast, after every other row is closed

Phase one: freeze deletions and map dependencies#

Phase one stops anything that deletes records automatically while the plan is built. Retention policies in email and chat, auto-archive rules in help desks and offboarding scripts that remove accounts can all destroy records quietly during a wind-down.

Map dependencies at the same time. Single sign-on controls access to most tools, integrations break when their source system closes, and password resets for every vendor arrive at company email addresses. Any system that other systems depend on gets cancelled late.

Phase two: secure admin access before layoffs#

Phase two secures admin access before the people who hold it leave, because a lost login is harder to recover than a cancelled subscription. In many companies a single engineer or office manager is the only admin for several systems.

  • Add a second company-controlled admin to every system that holds records.
  • Move multi-factor authentication off personal phones to company-held devices or a shared vault.
  • Record billing owners and the card or invoice each subscription runs on.
  • Check auto-renewal dates so no plan renews into a long term or lapses unnoticed.
  • Transfer file ownership before deleting any user account in Google Workspace or Microsoft 365.

Phase three: export and verify#

Phase three exports each system and verifies the export against the live system before anything else happens. Verification is the step most often skipped, and it is the one that catches missing attachments, truncated history and broken links between records.

Check record counts by year, open a sample of exported records next to the originals, confirm that attachments and comments came through, and make sure the identifiers that link systems survive, such as ticket numbers referenced in Jira issues or CRM account IDs on invoices. Store exports in company-controlled storage with access limited to named people.

Prefer each vendor's own export features over third-party tools that pull data through APIs. According to a Hunton Andrews Kurth client alert, Slack's API terms were changed effective May 29, 2025 to prohibit bulk exporting of data through its APIs and creating persistent copies or archives, so an archiving app that worked in the past may no longer be a permitted route.

Phase four: assess before you decide#

Phase four assesses each export before the cancel decision, because three different obligations meet here: records the law requires you to keep, records contracts require you to delete or return, and records that may be worth licensing.

Apply the rules in the order shown. A legal or contractual obligation always outranks a licensing opportunity.

Phase four: assess before you decide
FindingDecision
Required by tax, employment or corporate lawKeep with a named custodian
Customer data under a return or deletion clauseReturn or delete, and confirm in writing
Records under a litigation holdKeep unchanged until counsel releases the hold
Company-controlled operational history with outcomesHold for a licensing assessment
Personal files and duplicates with no purposeDelete under the retention schedule

What vendors say happens to data after cancellation#

Vendor terms on data after cancellation range from immediate loss of access to a long read-only window, which is why the register needs each vendor's own wording rather than an assumed grace period. The examples below come from vendor terms and help pages as published; policies change, so re-check them before setting a cancel date.

Two patterns matter most. Some vendors cut off access at termination even if the data sits on their servers for a while longer, and some charge or require a written request from the account owner for a full backup. Both are easy to handle before cancellation and hard to handle after.

What vendors say happens to data after cancellation
VendorWhat its terms or help pages sayWhat to do before cancelling
HubSpotFor Sales, Service, CMS and Operations Hub subscriptions, no access to customer data after termination or expiration; retrieval before the term ends is strongly recommendedTake the full CRM export, including activity history, before the term ends
SlackAfter subscriptions end, Slack may delete all customer data; no fixed number of days is statedRun the workspace export while the plan is active
PipedriveNo access after cancelling; a closed paid account is scheduled for permanent deletion within 180 daysExport deals, activities and notes before closing the account
BQE COREData stays for 60 days after cancellation but cannot be accessed, then is deleted unless an extraction or backup was arranged; a CSV backup is available for a fee on the owner's written request, typically in 1 to 3 working daysRequest the backup in writing well before the cancel date
JobberCancelling preserves the account and allows re-subscribing to retrieve information; permanently closing is finalCancel rather than permanently close until exports are verified
monday.comData is kept by default after cancellation, but deletion of inactive accounts is reserved at any timeTreat the window as unreliable and export first

Phase five: cancel in reverse dependency order#

Phase five cancels systems in reverse dependency order, with the most connected systems last. Standalone tools go first once their rows are closed; help desks, CRMs and trackers follow; chat and file storage come next; single sign-on, email and the domain go last.

Keep the domain registered and email forwarding active for a period after everything else is gone. Vendors send deletion confirmations, final invoices and account notices to company addresses, and a lapsed domain can let someone else receive them.

Cancel payment methods after the subscriptions they fund, not before. A card closed early turns a planned cancellation into a failed payment, and some vendors suspend or delete accounts on non-payment faster than on a normal cancellation.

Illustrative: an engineering firm sequences its shutdown#

Illustrative: a fictional structural engineering firm is closing after its principals retire. Its records span Deltek Vantagepoint for projects and billing, Procore for RFIs and submittals, Bluebeam sessions for markups, and Microsoft 365 for email and files.

The original plan cancels everything at month end and deletes staff accounts as people leave. The operations manager instead freezes deletions, adds a second admin to each system, and exports Procore and Bluebeam history with attachments first. The assessment separates client deliverables, which stay with the firm's records custodian under its professional obligations, from internal review comments and RFI resolution histories, which are held for a licensing assessment.

Microsoft 365 and the domain stay active until the final exports are verified and the custodian confirms receipt.

Where SourceX fits in the sequence#

SourceX fits into phase four. A metadata-only fit check covering systems, years of history and record families tells the company whether any exports are worth holding for licensing, and nothing leaves the company at that stage.

If a package proceeds, the SourceX five-step transaction (Supply, Rights, Preparation, Approval, Delivery) works from the verified exports rather than the live systems, so subscriptions can close on the planned schedule.

Frequently asked questions

What if a subscription renews in the middle of the wind-down?

Decide before the renewal date whether the system is still needed. If its export is not yet verified, a short renewal or a cheaper plan may cost less than losing the records. If the export is complete, cancel before renewal and keep proof of the cancellation.

Can we downgrade instead of cancelling?

Sometimes, and it can buy time. Check what a downgrade does to data access first, because some lower plans restrict exports, history or attachments, which defeats the purpose. Downgrade only after the full export is taken, or confirm the lower plan keeps what you need.

Who should own the subscription register?

One person with authority, usually the COO, head of operations or IT lead, should own it, with each row assigned to a system owner. The register owner signs off each cancellation, which stops well-meant cost cutting from closing a system early.

What about work done in personal accounts?

Ask staff before they leave which personal tools held company work, such as personal Dropbox folders, notes apps or personal email. Have them move company files to company storage and confirm deletion of their copies. These records are often missed and cannot be recovered later.

How long do vendors keep data after cancellation?

It varies by vendor and plan, and some delete quickly. Read each vendor's terms and help documentation, record the window in the register, and treat any unconfirmed window as already closed when you plan the export.

Should we tell vendors we are closing?

Usually yes, once exports are verified. Some vendors offer extended read-only access or help with bulk exports when a customer is winding down, and telling them can prevent surprise renewals. Ask in writing and keep the response with the register.

Sources

  • HubSpot's Product Specific Terms strongly recommend retrieving Customer Data before the Subscription Term ends; for Sales, Service, CMS and Operations Hub subscriptions, HubSpot will not provide any access to Customer Data after termination or expiration. Source
  • Slack's Customer Terms of Service say that after a workspace's subscriptions end, Slack may, unless legally prohibited, delete all Customer Data; no fixed number of days is stated. Source
  • Pipedrive says a closed paid account and its data are scheduled for permanent deletion within 180 days of closure, and the customer has no access after cancelling. Source
  • BQE says data stays in CORE for 60 days after cancellation without access, then is deleted unless an extraction or backup was arranged; a CSV backup is available for a fee on the owner's written request, typically in 1 to 3 working days. Source
  • Jobber says cancelling preserves the account and lets you re-subscribe to retrieve information, while permanently closing an account is final. Source
  • monday.com keeps data available by default after cancellation but cannot guarantee this indefinitely and reserves the right to delete data from an inactive account at any time. Source
  • According to Hunton Andrews Kurth, Slack API Terms effective May 29, 2025 prohibit bulk exporting of data accessible through Slack's APIs, creating persistent copies or archives, and using such data in large language models. Source

Related resources

See if your company qualifies

A short company assessment. No data uploads are needed.

See if you qualify