Skip to content

AI data market

What to export before you cancel SaaS subscriptions in a wind-down

By SourceX Editorial · Updated

Short answer

Before cancelling SaaS subscriptions in a wind-down, export every system that records how the business worked, in order of risk: chat, help desk, CRM, code and project tools, documents, operations and finance, with email and the identity provider last. Verify each export against the source before cancelling, because lapsed accounts may lose their data.

Key takeaways

  • Close the identity provider and email last, because single sign-on failures can lock you out of every other tool.
  • Export each system before its admin leaves or its renewal date passes, whichever comes first.
  • Capture user lists, field definitions and settings along with records, or the exports become hard to read.
  • Check every export against the source system's own counts and date range before the subscription ends.
  • Preserve originals securely and de-identify only the copies prepared for a specific use.

What should you export before cancelling SaaS subscriptions?#

Before cancelling SaaS subscriptions in a wind-down, export every system that holds records of how the business worked, plus the user lists and settings that explain those records. Work in order of risk: systems whose admins are leaving or whose renewals come first go first, and the identity provider and email go last.

Order matters because access collapses in a chain. If Okta, Google Workspace or Microsoft 365 is closed early, single sign-on fails and nobody can log into the other tools to export them. If the last Salesforce admin leaves before the export, recovering admin rights can take longer than the time left.

Treat each export as unfinished until someone has opened it, compared it with the source and recorded where it is stored.

Who should own the export plan?#

The export plan should have one named owner, usually the wind-down officer or COO, with an IT admin doing the work and counsel reviewing what may be kept. Without a single owner, each department cancels its own tools on its own schedule, and nobody notices what was lost until a lender, buyer or tax authority asks.

Pull the list of systems from what the company actually pays for, meaning vendor lines in the ledger and charges on every company card, rather than from anyone's recollection. Tools bought on a manager's card often hold records nobody else knew about, such as a survey tool full of customer feedback or a project tracker used by a single team. Keep at least one long-standing super admin account active to the end: Google, for example, requires its Data Export tool to be started by a super admin account that is at least 30 days old.

The ordered export checklist by system#

The ordered export checklist below covers the systems most companies with 50 or more employees run. Adjust the order to your own renewal dates and staff departures, but keep identity and email at the end.

The deadline column quotes limits that vendors documented as of 2026. They change over time, and a negotiated contract may override them, so check each vendor's current documentation and your order form before relying on a date.

The ordered export checklist by system
OrderSystemWhat to exportTypical formatDeadline trigger and documented limits
1Chat: Slack or Microsoft TeamsChannels, messages, files, member list, channel settingsSlack JSON export with file links, plus the files themselves; Teams through eDiscoveryBefore any downgrade or lapse. Slack exports of private channels and direct messages need Business+ or Enterprise and an application, and Slack may delete all data once subscriptions end
2Help desk: Zendesk, Intercom or FreshdeskTickets with comments, tags, macros, satisfaction ratings, attachmentsJSON, CSV or XML exports, or API pullsBefore the renewal date. Zendesk exports are off until support enables them, and Freshdesk deletes account data 14 days after the subscription ends
3CRM: Salesforce or HubSpotAccounts, contacts, deals, activities, notes, attachments, field historyCSV per object plus attachment filesBefore the last admin leaves. Salesforce provides data on request within 30 days after termination; HubSpot's Sales and Service Hubs give no access after termination
4Code and issues: GitHub, GitLab, Jira, LinearRepositories with full history, pull requests, reviews, issuesMirror clones, migration archives and CSV in batchesBefore any product is cancelled. Atlassian keeps a cancelled site 15 days, then paid-plan data 60 days, but unsubscribing from all Jira products deletes Jira data immediately
5Docs and wiki: Confluence, Notion, Google Drive, SharePointPages with version history, attachments, permissionsNative exports, HTML or original filesBefore storage plans are reduced. A Notion workspace export can take up to 30 hours and skips other users' private pages
6Operations: ServiceTitan, NetSuite, WMS, TMS or MESJobs, orders, exceptions, invoices, quality recordsReport exports to CSV, saved searches or a full backupBefore contract end. NetSuite's Full CSV Export does not cover all data, so add saved searches for transactions
7Finance and HR: accounting, payroll, HRISLedgers, tax filings, payroll registers, personnel filesNative backups and PDFsBefore books close. Federal rules require payroll records to be kept at least three years, and Intuit describes a one-year read-only period after QuickBooks Online is cancelled
8Email and identity: Google Workspace, Microsoft 365, OktaMailboxes, shared drives, admin audit logs, user listMBOX or PST for mail, CSV for logs and usersLast. A Google Data Export can take up to 14 days, and Microsoft deletes data no later than 180 days after cancellation

What to capture besides the records#

Records without context are hard to use, so capture the material that explains them along with the data itself. A ticket export without status definitions or a CRM export without field meanings can take longer to decode than it took to create.

  • User and role lists, so later readers know which account belonged to which role.
  • Custom field definitions, picklists and status meanings.
  • Activity records that sit outside the standard export, such as HubSpot calls and notes, which need a separate export method.
  • Integration settings and automation rules, which explain records created by bots.
  • Retention and auto-delete settings, which show what history may already be missing.
  • Vendor contracts and data processing terms, which govern how exported data can be used.
  • An export log recording who exported what, when, from which system, with file sizes and hashes.

How to verify an export before you cancel#

Verifying an export means proving it is complete and readable before the source disappears. Compare record counts with the system's own reports, check the first and last dates, open a sample of records with attachments, and confirm that threads and linked items still connect. Download promptly, because export files expire: Google Vault deletes export files 15 days after the export starts, Microsoft Purview eDiscovery exports expire after 14 days and Linear's emailed export link lasts 12 hours.

Store two copies in separate locations controlled by the entity or its successor, encrypt both and limit access to named people. Write down where they are, because in a wind-down the person who knows is often the first to leave.

What not to keep, and what you may need to delete#

Not every record should survive a wind-down. Customer data you processed on a customer's behalf may have to be returned or deleted under your contracts, and privacy laws may require deletion of personal information the business no longer needs.

Payment card data, stored passwords and API keys should not sit in an archive at all. Set a retention schedule that says what is kept, why, for how long and who deletes it, and have counsel confirm it fits the contracts and laws that apply.

Illustrative: an HVAC contractor exports before the lights go off#

Illustrative: a fictional HVAC and plumbing contractor sells its service agreements to a competitor and winds down the remaining entity. Its COO holds admin rights to ServiceTitan, QuickBooks Online, Google Workspace and a call-tracking tool, and the buyer of the service agreements does not take the job history.

The COO exports ServiceTitan first, including jobs, estimates, invoices, equipment records and technician notes, because its contract ends before anything else. Call recordings are set aside for counsel to review before any further use, because they capture customers' voices and details. QuickBooks and payroll records go to the outside accountant under the retention schedule, and Google Workspace stays open until every export has been checked against source counts.

Outcome: when the owner later asks whether the job histories could be licensed, the records exist, their date range is known and a rights review can start from a complete inventory.

How SourceX fits into a wind-down#

SourceX enters a wind-down at Supply, the first step of the SourceX five-step transaction, where preserved records are listed and described. That list is all SourceX needs to judge whether a package is worth pursuing, so exports can stay wherever the wind-down team stored them.

If a package proceeds, Rights, Preparation, Approval and Delivery follow, with the entity or its successor approving every step. Very large exports are never uploaded to SourceX; they stay in the owner's storage or travel on encrypted drives.

Frequently asked questions

How long do vendors keep data after cancellation?

It varies by vendor, plan and contract. As documented in 2026, Freshdesk deletes account data 14 days after the subscription ends, Atlassian holds paid-plan site data 60 days after deactivation, and Microsoft deletes data no later than 180 days after cancellation. Plan as though data could become unreachable on the cancellation date.

Can we reactivate an account to export after it lapses?

Sometimes, if the vendor still holds the data and allows reactivation, but it is not something to rely on. Reactivation may require paying for a full plan, recovering admin access or working through support, all of which take time a wind-down rarely has.

Should we pay for read-only access instead of exporting?

A low-cost archive or read-only tier can buy time, but it still depends on someone paying the bill and keeping credentials. A verified export in storage the entity controls is the more durable choice, and a read-only tier can bridge the gap until exports are checked.

Where should exports be stored after the company closes?

In encrypted storage controlled by the entity, its successor or a named custodian, with two copies in separate locations and a short access list. Record the location, who holds the encryption keys and the retention period in the wind-down file.

Do exports need to be de-identified before storage?

No. Preserve originals securely so nothing is lost, and de-identify only the copies prepared for a specific use such as a license. De-identifying the only copy too early can destroy context you may later need for legal, tax or licensing purposes.

Sources

  • Slack's export help article says exports of private channels and direct messages are available only on Business+ and Enterprise plans and owners must apply to use them, and that workspace exports include links to files rather than the files. Source
  • Slack's Customer Terms of Service say that after a workspace's subscriptions end, Slack may, unless legally prohibited, delete all Customer Data in its possession or control. Source
  • Zendesk data exports are not turned on by default; the account owner must contact Zendesk Customer Support to enable them, and exports are delivered as JSON, CSV or XML. Source
  • Freshworks partner support says Freshdesk permanently deletes the account and its data 14 days after the subscription end date. Source
  • Under the Salesforce Main Services Agreement, if the customer asks within 30 days after termination or expiration, SFDC makes Customer Data available for export or download, and after that period has no obligation to maintain or provide it. Source
  • HubSpot's Product Specific Terms strongly recommend retrieving Customer Data before the Subscription Term ends, and say that for Hub subscriptions such as Sales and Service Hub, HubSpot will not provide any access to Customer Data after termination or expiration. Source
  • HubSpot's export-records article says activities such as calls and notes must be exported with a separate method, not the standard record export. Source
  • Atlassian states that after a cancelled subscription period ends, the site stays accessible for 15 more days and is then deactivated, and data is retained for 60 days for Free, Standard, Premium or Enterprise plans before permanent deletion. Source
  • Atlassian states that unsubscribing from all Jira products on a site deletes the Jira data immediately. Source
  • Notion says workspace exports can take up to 30 hours and that pages the exporting user cannot access, such as other users' private pages, are not included. Source
  • Oracle's NetSuite help says the Full CSV Export does not currently export all data. Source
  • DOL Fact Sheet #21 states each employer shall preserve payroll records for at least three years. Source
  • Intuit support content says you can still export QuickBooks Online data while a cancelled account is within its one-year read-only period. Source
  • Google says the Workspace Data Export tool must be started by a super admin account that is at least 30 days old, unless the organization's account is newer than 30 days. Source
  • Google states that a Data Export typically takes 72 hours but can take up to 14 days. Source
  • Microsoft's business subscription lifecycle says data left behind might be deleted after 90 days and will be deleted no later than 180 days after cancellation. Source
  • Google Vault export files are available for 15 days after the export starts and are then deleted. Source
  • Microsoft states that Purview eDiscovery search exports expire 14 days after creation. Source
  • Linear's emailed export download link expires after 12 hours. Source

Related resources

See if your company qualifies

A short company assessment. No data uploads are needed.

See if you qualify