AI data market
What to export before you cancel SaaS subscriptions in a wind-down
By SourceX Editorial · Updated
Short answer
Before cancelling SaaS subscriptions in a wind-down, export every system that records how the business worked, in order of risk: chat, help desk, CRM, code and project tools, documents, operations and finance, with email and the identity provider last. Verify each export against the source before cancelling, because lapsed accounts may lose their data.
Key takeaways
- Close the identity provider and email last, because single sign-on failures can lock you out of every other tool.
- Export each system before its admin leaves or its renewal date passes, whichever comes first.
- Capture user lists, field definitions and settings along with records, or the exports become hard to read.
- Check every export against the source system's own counts and date range before the subscription ends.
- Preserve originals securely and de-identify only the copies prepared for a specific use.
What should you export before cancelling SaaS subscriptions?#
Before cancelling SaaS subscriptions in a wind-down, export every system that holds records of how the business worked, plus the user lists and settings that explain those records. Work in order of risk: systems whose admins are leaving or whose renewals come first go first, and the identity provider and email go last.
Order matters because access collapses in a chain. If Okta, Google Workspace or Microsoft 365 is closed early, single sign-on fails and nobody can log into the other tools to export them. If the last Salesforce admin leaves before the export, recovering admin rights can take longer than the time left.
Treat each export as unfinished until someone has opened it, compared it with the source and recorded where it is stored.
Who should own the export plan?#
The export plan should have one named owner, usually the wind-down officer or COO, with an IT admin doing the work and counsel reviewing what may be kept. Without a single owner, each department cancels its own tools on its own schedule, and nobody notices what was lost until a lender, buyer or tax authority asks.
Pull the list of systems from what the company actually pays for, meaning vendor lines in the ledger and charges on every company card, rather than from anyone's recollection. Tools bought on a manager's card often hold records nobody else knew about, such as a survey tool full of customer feedback or a project tracker used by a single team. Keep at least one long-standing super admin account active to the end: Google, for example, requires its Data Export tool to be started by a super admin account that is at least 30 days old.
The ordered export checklist by system#
The ordered export checklist below covers the systems most companies with 50 or more employees run. Adjust the order to your own renewal dates and staff departures, but keep identity and email at the end.
The deadline column quotes limits that vendors documented as of 2026. They change over time, and a negotiated contract may override them, so check each vendor's current documentation and your order form before relying on a date.
| Order | System | What to export | Typical format | Deadline trigger and documented limits |
|---|---|---|---|---|
| 1 | Chat: Slack or Microsoft Teams | Channels, messages, files, member list, channel settings | Slack JSON export with file links, plus the files themselves; Teams through eDiscovery | Before any downgrade or lapse. Slack exports of private channels and direct messages need Business+ or Enterprise and an application, and Slack may delete all data once subscriptions end |
| 2 | Help desk: Zendesk, Intercom or Freshdesk | Tickets with comments, tags, macros, satisfaction ratings, attachments | JSON, CSV or XML exports, or API pulls | Before the renewal date. Zendesk exports are off until support enables them, and Freshdesk deletes account data 14 days after the subscription ends |
| 3 | CRM: Salesforce or HubSpot | Accounts, contacts, deals, activities, notes, attachments, field history | CSV per object plus attachment files | Before the last admin leaves. Salesforce provides data on request within 30 days after termination; HubSpot's Sales and Service Hubs give no access after termination |
| 4 | Code and issues: GitHub, GitLab, Jira, Linear | Repositories with full history, pull requests, reviews, issues | Mirror clones, migration archives and CSV in batches | Before any product is cancelled. Atlassian keeps a cancelled site 15 days, then paid-plan data 60 days, but unsubscribing from all Jira products deletes Jira data immediately |
| 5 | Docs and wiki: Confluence, Notion, Google Drive, SharePoint | Pages with version history, attachments, permissions | Native exports, HTML or original files | Before storage plans are reduced. A Notion workspace export can take up to 30 hours and skips other users' private pages |
| 6 | Operations: ServiceTitan, NetSuite, WMS, TMS or MES | Jobs, orders, exceptions, invoices, quality records | Report exports to CSV, saved searches or a full backup | Before contract end. NetSuite's Full CSV Export does not cover all data, so add saved searches for transactions |
| 7 | Finance and HR: accounting, payroll, HRIS | Ledgers, tax filings, payroll registers, personnel files | Native backups and PDFs | Before books close. Federal rules require payroll records to be kept at least three years, and Intuit describes a one-year read-only period after QuickBooks Online is cancelled |
| 8 | Email and identity: Google Workspace, Microsoft 365, Okta | Mailboxes, shared drives, admin audit logs, user list | MBOX or PST for mail, CSV for logs and users | Last. A Google Data Export can take up to 14 days, and Microsoft deletes data no later than 180 days after cancellation |
What to capture besides the records#
Records without context are hard to use, so capture the material that explains them along with the data itself. A ticket export without status definitions or a CRM export without field meanings can take longer to decode than it took to create.
- User and role lists, so later readers know which account belonged to which role.
- Custom field definitions, picklists and status meanings.
- Activity records that sit outside the standard export, such as HubSpot calls and notes, which need a separate export method.
- Integration settings and automation rules, which explain records created by bots.
- Retention and auto-delete settings, which show what history may already be missing.
- Vendor contracts and data processing terms, which govern how exported data can be used.
- An export log recording who exported what, when, from which system, with file sizes and hashes.
How to verify an export before you cancel#
Verifying an export means proving it is complete and readable before the source disappears. Compare record counts with the system's own reports, check the first and last dates, open a sample of records with attachments, and confirm that threads and linked items still connect. Download promptly, because export files expire: Google Vault deletes export files 15 days after the export starts, Microsoft Purview eDiscovery exports expire after 14 days and Linear's emailed export link lasts 12 hours.
Store two copies in separate locations controlled by the entity or its successor, encrypt both and limit access to named people. Write down where they are, because in a wind-down the person who knows is often the first to leave.
What not to keep, and what you may need to delete#
Not every record should survive a wind-down. Customer data you processed on a customer's behalf may have to be returned or deleted under your contracts, and privacy laws may require deletion of personal information the business no longer needs.
Payment card data, stored passwords and API keys should not sit in an archive at all. Set a retention schedule that says what is kept, why, for how long and who deletes it, and have counsel confirm it fits the contracts and laws that apply.
Illustrative: an HVAC contractor exports before the lights go off#
Illustrative: a fictional HVAC and plumbing contractor sells its service agreements to a competitor and winds down the remaining entity. Its COO holds admin rights to ServiceTitan, QuickBooks Online, Google Workspace and a call-tracking tool, and the buyer of the service agreements does not take the job history.
The COO exports ServiceTitan first, including jobs, estimates, invoices, equipment records and technician notes, because its contract ends before anything else. Call recordings are set aside for counsel to review before any further use, because they capture customers' voices and details. QuickBooks and payroll records go to the outside accountant under the retention schedule, and Google Workspace stays open until every export has been checked against source counts.
Outcome: when the owner later asks whether the job histories could be licensed, the records exist, their date range is known and a rights review can start from a complete inventory.
How SourceX fits into a wind-down#
SourceX enters a wind-down at Supply, the first step of the SourceX five-step transaction, where preserved records are listed and described. That list is all SourceX needs to judge whether a package is worth pursuing, so exports can stay wherever the wind-down team stored them.
If a package proceeds, Rights, Preparation, Approval and Delivery follow, with the entity or its successor approving every step. Very large exports are never uploaded to SourceX; they stay in the owner's storage or travel on encrypted drives.
Frequently asked questions
How long do vendors keep data after cancellation?
It varies by vendor, plan and contract. As documented in 2026, Freshdesk deletes account data 14 days after the subscription ends, Atlassian holds paid-plan site data 60 days after deactivation, and Microsoft deletes data no later than 180 days after cancellation. Plan as though data could become unreachable on the cancellation date.
Can we reactivate an account to export after it lapses?
Sometimes, if the vendor still holds the data and allows reactivation, but it is not something to rely on. Reactivation may require paying for a full plan, recovering admin access or working through support, all of which take time a wind-down rarely has.
Should we pay for read-only access instead of exporting?
A low-cost archive or read-only tier can buy time, but it still depends on someone paying the bill and keeping credentials. A verified export in storage the entity controls is the more durable choice, and a read-only tier can bridge the gap until exports are checked.
Where should exports be stored after the company closes?
In encrypted storage controlled by the entity, its successor or a named custodian, with two copies in separate locations and a short access list. Record the location, who holds the encryption keys and the retention period in the wind-down file.
Do exports need to be de-identified before storage?
No. Preserve originals securely so nothing is lost, and de-identify only the copies prepared for a specific use such as a license. De-identifying the only copy too early can destroy context you may later need for legal, tax or licensing purposes.
Sources
- Slack's export help article says exports of private channels and direct messages are available only on Business+ and Enterprise plans and owners must apply to use them, and that workspace exports include links to files rather than the files. Source
- Slack's Customer Terms of Service say that after a workspace's subscriptions end, Slack may, unless legally prohibited, delete all Customer Data in its possession or control. Source
- Zendesk data exports are not turned on by default; the account owner must contact Zendesk Customer Support to enable them, and exports are delivered as JSON, CSV or XML. Source
- Freshworks partner support says Freshdesk permanently deletes the account and its data 14 days after the subscription end date. Source
- Under the Salesforce Main Services Agreement, if the customer asks within 30 days after termination or expiration, SFDC makes Customer Data available for export or download, and after that period has no obligation to maintain or provide it. Source
- HubSpot's Product Specific Terms strongly recommend retrieving Customer Data before the Subscription Term ends, and say that for Hub subscriptions such as Sales and Service Hub, HubSpot will not provide any access to Customer Data after termination or expiration. Source
- HubSpot's export-records article says activities such as calls and notes must be exported with a separate method, not the standard record export. Source
- Atlassian states that after a cancelled subscription period ends, the site stays accessible for 15 more days and is then deactivated, and data is retained for 60 days for Free, Standard, Premium or Enterprise plans before permanent deletion. Source
- Atlassian states that unsubscribing from all Jira products on a site deletes the Jira data immediately. Source
- Notion says workspace exports can take up to 30 hours and that pages the exporting user cannot access, such as other users' private pages, are not included. Source
- Oracle's NetSuite help says the Full CSV Export does not currently export all data. Source
- DOL Fact Sheet #21 states each employer shall preserve payroll records for at least three years. Source
- Intuit support content says you can still export QuickBooks Online data while a cancelled account is within its one-year read-only period. Source
- Google says the Workspace Data Export tool must be started by a super admin account that is at least 30 days old, unless the organization's account is newer than 30 days. Source
- Google states that a Data Export typically takes 72 hours but can take up to 14 days. Source
- Microsoft's business subscription lifecycle says data left behind might be deleted after 90 days and will be deleted no later than 180 days after cancellation. Source
- Google Vault export files are available for 15 days after the export starts and are then deleted. Source
- Microsoft states that Purview eDiscovery search exports expire 14 days after creation. Source
- Linear's emailed export download link expires after 12 hours. Source
Related resources
See if your company qualifies
A short company assessment. No data uploads are needed.