Skip to content

Software companies

Shutting down a SaaS startup: what to do with Slack, Jira, GitHub and email

By SourceX Editorial · Reviewed by Noah Loul ·

Short answer

When shutting down a SaaS startup, handle Slack, Jira, GitHub and email in a fixed order: freeze deletion, export what the company controls before subscriptions lapse, confirm who can act for the company, review privacy and customer obligations, and only then decide to license, archive or delete each record set. Reversing that order destroys options.

Key takeaways

  • Freeze automated deletion and keep admin access before cancelling any subscription.
  • Customer production data usually must be returned or deleted under customer agreements, not licensed.
  • Internal engineering history in Jira and GitHub is often the most licensable record a closing startup holds.
  • Someone with documented authority must approve any license, and lenders or investors may need to consent.
  • Decide record set by record set, because one answer for the whole company is almost always wrong.

Why does the order of shutdown steps matter?#

The order of shutdown steps matters because each SaaS system deletes or locks data on its own schedule once billing stops, and some of those losses cannot be undone. A cancelled workspace may take its history with it, and a deleted GitHub organization takes its pull requests and review threads.

Founders under cost pressure tend to cancel tools first and decide later, then discover that records needed for tax filings, a dispute or a possible license are gone. The five steps below put preservation first and decisions last.

Step 1: freeze deletion and secure admin access#

Freezing deletion means pausing every automated process that removes records and making sure at least two trusted people keep admin rights to each system. Departing employees often hold the only owner role on a tool, and that access disappears with their accounts.

Budget for a short paid overlap. One more billing cycle is usually cheaper than recovering lost history, and some vendors cannot recover it at all once an account closes. Post-termination windows, where they exist, are short and conditional: HubSpot's Product Specific Terms, for example, say that for Marketing Hub Professional and Enterprise a customer must make a written request within 30 days after termination to retrieve its data. Check the terms tied to each order form before cancelling anything.

  • Pause Slack retention rules that delete messages on a schedule.
  • Stop Google Workspace or Microsoft 365 from removing departed employees' mailboxes and drives.
  • Keep the GitHub organization and its repositories intact; archive rather than delete.
  • Disable automatic cleanup of inactive Jira or Linear projects.
  • Keep support desk and CRM subscriptions active until exports are verified.
  • Record which accounts hold owner or admin roles, and move roles held only by departing staff.
  • Apply legal holds where disputes, investigations or tax questions are open.

Step 2: export each system the company controls#

Exporting each system means producing complete, verified copies with their links intact, using the export tools your plans provide. Open every export and spot-check that comments, attachments and cross-references came through, because a silent gap found after cancellation is permanent.

Store exports in encrypted storage the company controls, with a written access list. Multi-terabyte archives can stay on that storage or move to encrypted drives; they do not need to be uploaded anywhere.

Step 2: export each system the company controls
SystemWhat to exportWatch for
SlackOwner-level workspace export for the channels your plan allowsAPI terms that restrict third-party tools; direct messages and shared channels
Jira or LinearIssues, comments, attachments, workflows and issue linksExports that drop attachments or links to commits
GitHub or GitLabRepositories with full history, plus pull requests, reviews and issuesReview threads live outside git, so a clone alone misses them
EmailMailboxes for founders, executives and key functionsDeparted employees' mailboxes and shared inboxes
Zendesk or IntercomTickets with comments, tags and macrosPlan limits on how far back exports go
Confluence or NotionSpaces and pages with version historyEmbedded files stored in other systems
HubSpot or SalesforceAccounts, deals and activity historyContact personal data subject to marketing consent

Step 3: confirm who can act for the company#

Confirming who can act for the company means identifying the person or body with documented authority to sign, which shifts as a company winds down. Directors, an appointed wind-down officer, an assignee in an assignment for the benefit of creditors, or a trustee may each hold that power in different situations.

Check the board resolutions authorizing the wind-down, any security agreement with a venture lender that covers intellectual property or records, and investor rights that require consent for asset dispositions. A license signed by someone without authority creates problems for the licensee and for the person who signed.

If the company has already dissolved, authority may sit with former directors acting only to wind up its affairs, or with no one until a court or assignee is involved. Counsel should confirm the position before any licensee is approached, and before anyone promises a timeline.

Step 4: review privacy and customer obligations#

The privacy and customer review decides what must be returned, deleted or retained before anything can be licensed. Customer agreements and data processing agreements commonly require the vendor to return or delete customer data when the relationship ends, and a shutdown ends every relationship at once.

Employee records raise separate questions. Slack and email hold personal messages, family and health details, and compensation discussions. Whether any of it can be licensed depends on notices, policies and the privacy laws that may apply, assessed with counsel.

Financial, tax and HR records usually must be kept for periods set by the rules that apply to the company. Ask the company's accountant and counsel which ones, and keep them out of any licensing scope.

Step 5: license, archive or delete each record set#

Deciding to license, archive or delete works record set by record set, because each one carries different rights and obligations. The table shows the usual starting position; counsel and the authorized signer make the final call for each row.

Write the decision for each record set into the wind-down file, with the reason. A licensee, an auditor or a former customer may ask later, and a dated record answers faster than anyone's memory.

Step 5: license, archive or delete each record set
Record setUsual decisionWhy
Customer production dataReturn or deleteCustomer agreements and DPAs usually require it
Jira issues and GitHub pull requestsCandidate to licenseCompany work product with linked outcomes
Incident postmortems and runbooksCandidate to licenseInternal operational knowledge
Slack work channelsCandidate after reviewNeeds employee notice review and redaction
Direct messages and personal channelsArchive or deleteHigh privacy expectations
EmailArchive for legal and tax needsMixed content, rarely licensable as a whole
Financial, tax and HR filesRetainRetention duties, never part of a license

Illustrative: a closed freight visibility startup works the checklist#

Illustrative: a fictional freight visibility startup decides to close after a failed fundraise. The CEO's first instinct is to cancel every tool at month end. The wind-down officer instead pauses Slack retention, keeps GitHub and Jira active, and moves admin roles off departing engineers.

Exports follow, checked one by one. Counsel confirms that customer shipment data must be deleted under the customer agreements, and deletion is certified to each customer. The board passes a resolution naming the wind-down officer as signer for any record licenses.

What remains for licensing is engineering history: Jira issues linked to pull requests, carrier integration code reviews, and postmortems from missed tracking events. Slack work channels are held back pending an employee notice review, and email is archived for the accountants.

How SourceX fits into a wind-down#

SourceX fits after preservation, not before it. The fit check collects metadata about systems, years of history and record families, and nothing is shared during that assessment, so it can run while exports are still being verified.

For records that proceed through the SourceX five-step transaction, the SourceX Evidence Packet records release authorization alongside provenance, licensing rights, permitted use and the privacy record. In a wind-down, that authorization record is often the item licensees examine most closely.

Frequently asked questions

Can we delete the GitHub organization once the code is cloned?

Not yet. Pull requests, review comments and issues are not part of a git clone, and they are often the most useful records. Export them separately, verify the export, and archive the organization rather than deleting it until decisions about every record set are final.

Who should pay for subscriptions during the wind-down?

The company, from its wind-down budget, for systems that hold records still under review. Prioritize systems that would delete history when billing stops, and cancel tools that hold no unique records first to reduce cost without losing anything.

Can the buyer of our code also get the Jira and Slack history?

Possibly, but treat them as separate decisions. Code can be sold outright, while records usually carry privacy and customer obligations that travel with them. Make sure any sale agreement does not promise the buyer exclusive rights that conflict with a separate license of the records.

What if co-founders disagree about licensing internal records?

Follow the governance documents: the board, or the person it authorizes, decides. Record the decision and the reasons in a resolution. Disagreement is another reason to preserve first, so the choice stays open while it is resolved.

How long should we keep the exports after the company closes?

As long as retention duties and open matters require, which the company's accountant and counsel set. Keep a dated inventory of what each export contains and where it is stored, and delete on schedule once obligations end and no license, audit or dispute depends on the data.

Sources

  • For Marketing Hub Professional and Enterprise, if the customer makes a written request within 30 days after termination or expiration, HubSpot will give temporary access to retrieve, or provide copies of, Customer Data; after that it has no obligation to maintain or provide the data. Source

Related resources

See if your company qualifies

A short company assessment. No data uploads are needed.

See if you qualify