Wind-downs and transitions
Your software vendor is shutting down: how to get your records out in time
By SourceX Editorial · Reviewed by Noah Loul ·
Short answer
When a SaaS vendor is going out of business, treat its shutdown notice as the deadline for your data: secure admin access, start complete exports the same day and read your contract's data return terms. The rule: do not wait for a replacement system before exporting, because the vendor's window can close before any migration is ready.
Key takeaways
- A vendor's shutdown notice sets the real deadline for your records, whatever your own migration plan says.
- Complete exports with attachments, notes and history come before migration planning, not after it.
- Your contract's data ownership, transition, return and deletion clauses decide what you can require from the vendor.
- If the vendor enters bankruptcy, an assignment or a receivership, raise data return requests in writing with whoever controls its assets.
- A closing software company generally cannot license its customers' data; its own internal records are a separate question.
What should you do first when a vendor announces it is closing?#
The first thing to do when a software vendor announces it is closing is to confirm you still have admin access and start a complete export the same day. Everything else, including choosing a replacement, can follow once a verified copy of your records sits in storage you control.
Read the shutdown notice closely. It usually states when logins stop, whether exports remain available until then, and whether the vendor or a successor will offer transition help. Forward it to whoever owns the contract, finance and IT, and log the date you received it, because that date anchors every later request.
The 72-hour action list#
The 72-hour action list below assumes the notice arrived today and the service still works. Compress the order if the notice gives a very short window, but keep exports ahead of everything else, including vendor selection.
- Hours 0 to 24: confirm at least two working admin accounts, pause any auto-deletion or archiving rules, and start every built-in export the system offers.
- Hours 0 to 24: download attachments, photos and documents separately if the export only holds links to them.
- Hours 0 to 24: pull the contract, order form and any data processing agreement, and mark the data return and deletion terms.
- Hours 24 to 48: check each export against the live system for record counts, date range, notes and history.
- Hours 24 to 48: run API or report-based extractions for anything the built-in export missed.
- Hours 24 to 48: list integrations that copied data elsewhere, such as accounting or CRM syncs, and export from those too.
- Hours 48 to 72: move verified exports into encrypted, company-controlled storage and start an export log.
- Hours 48 to 72: write to the vendor requesting a complete data return in a documented format and its deletion timing.
- Hours 48 to 72: decide whether to pay for any extended access offered, and only then begin migration planning.
What to export from each kind of system#
What to export depends on the kind of system, and the items people miss are usually the ones that explain the work rather than bill for it. Use the table to brief whoever runs the export, and add the system's own custom objects to the list.
| Vendor type | Records to pull | Often missed |
|---|---|---|
| Bookkeeping or accounting service | Ledger, reconciliations, invoices, bills and tax filings | Receipt images, adviser notes and closing workpapers |
| Field service management | Customers, estimates, jobs, invoices, equipment and memberships | Technician notes, photos, call recordings and warranty history |
| Help desk or live chat | Tickets and conversations with every reply | Internal notes, audit history, macros and attachments |
| CRM | Accounts, contacts, deals and activities | Logged emails, notes, custom objects and field history |
| Project or issue tracking | Projects, issues, comments and attachments | Status history and links between issues and to code |
| Transportation or warehouse software | Orders, shipments, inventory movements and carriers | Exception records, appointment changes and dock notes |
| Payroll or HR | Pay registers, tax forms and personnel files | Year-end filings, benefit elections and policy acknowledgments |
What your contract says about getting your data back#
Your contract decides what you can require from the vendor, so read it before arguing about access. Look for who owns customer data, what export or transition help is promised, how long data is kept after termination and whether the vendor will confirm deletion.
Do not expect a closing vendor to be more generous than a healthy one, and published terms at healthy vendors are already short. Freshworks says Freshdesk permanently deletes an account and its data 14 days after the subscription end date and warns its export can take up to 10 business days. Help Scout says an account is inaccessible as soon as it is deleted, with data removed 60 days after cancellation. Smartsheet makes paid-plan items read-only on cancellation and deletes them 30 days after the effective date.
If the vendor has entered bankruptcy, an assignment for the benefit of creditors or a receivership, its contracts and the data it holds are handled inside that process. Ask counsel to identify the trustee, assignee or receiver and send your data return request to them in writing. This is general information, not legal advice.
| Clause | What it can give you | What to ask for |
|---|---|---|
| Data ownership | Confirmation that the records are yours, not the vendor's | A complete copy in a standard, documented format |
| Export or transition assistance | Help moving data, sometimes for a fee | Field definitions, attachments and history, not a summary file |
| Post-termination access | A window to retrieve data after service ends | Written confirmation of the date the window closes |
| Return and deletion | An obligation to return or delete your data | Deletion confirmation only after you have verified your copy |
| Escrow | Release of escrowed code or data on defined events | Whether the vendor's closing triggers a release |
When the built-in export falls short#
When the built-in export falls short, combine several routes rather than accepting an incomplete copy. Each route fills a different gap, and used together they close many of them before the service goes dark.
- API extraction with a short script or an integration tool, which can reach comments, history and attachments the export skips.
- Saved reports and list views exported one module at a time.
- PDF copies of critical records, such as open warranties or service agreements, when no structured route exists.
- Copies held by connected systems, such as invoices synced to accounting or contacts synced to email marketing.
- Notification emails in your own mailboxes, which often record status changes the export leaves out.
- A written request to the vendor's support team for a database-level export.
If you are the vendor: what a closing software company may license#
A closing software company may be able to license some of its own records, but its customers' data is generally off limits. Customer agreements and data processing agreements usually treat the vendor as a processor of customer data, limit use to providing the service and require return or deletion at the end.
The vendor's own operating records are a different category. Engineering issues, code reviews, release notes, internal documentation and its own support conversations were created by the vendor, though they often contain customer names and details that must be removed first. Aggregated or de-identified usage data sits in between and depends on what the agreements actually permit.
| Record | Usual starting position | What decides it |
|---|---|---|
| Customer-entered data in the product | Not licensable by the vendor | Customer agreements, DPAs and privacy law |
| The vendor's own support conversations | Possible after review | Customer contracts, privacy notices and redaction |
| Engineering issues, code reviews and releases | Often the strongest candidate | IP ownership, open-source licenses and customer code terms |
| Aggregated or de-identified usage data | Depends on contract wording | Whether agreements permit aggregated or de-identified use |
| Internal documentation and playbooks | Possible after review | Confidentiality duties and third-party content |
Illustrative: a 3PL loses its dock scheduling vendor#
Illustrative: a fictional regional third-party logistics provider runs dock appointments and carrier check-ins on a small SaaS scheduling tool, alongside NetSuite and a WMS. One morning the vendor emails customers that the service will stop at the end of the following month.
The COO had the IT lead confirm two admin logins and start the built-in export that day. The export held appointments but not the exception notes dock supervisors typed when trucks arrived late or loads were refused, so the IT lead pulled those through the API and matched them to shipment numbers in NetSuite.
Counsel sent the vendor a written data return request citing the contract's ownership clause. The company later moved to a new scheduler from its own verified archive rather than the vendor's final file, and kept the exception history under its retention schedule as a record that could be assessed for licensing.
How SourceX approaches records from a retired vendor#
SourceX treats an archive recovered from a closing vendor like any other retired system. The fit check starts from metadata, such as the system, record families and years covered, and no files are shared at that stage. For closing vendors themselves, the Rights step of the SourceX five-step transaction separates customer-owned data from the vendor's own records before anything else happens.
If a package proceeds, the SourceX Evidence Packet records where the records came from, how they were exported, what rights support the license and who authorized release. SourceX does not host large archives; they remain in the company's own storage or travel on encrypted drives.
Frequently asked questions
Will the vendor delete our data as soon as it shuts down?
Not necessarily on the first day, but you cannot count on access after the stated shutdown date. Some vendors keep data for a short period, some transfer it to a successor and some delete quickly. Get the vendor's deletion timing in writing and finish verified exports before the earliest date mentioned.
Should we pay for extended access if the vendor offers it?
It is worth considering when exports are incomplete or a migration is underway, because lost history is hard to rebuild. Compare the price with the effort of recreating records, and do not let paid extended access delay your own verified export.
Can a bankrupt vendor transfer our data to someone else?
Transfers of data in a bankruptcy are shaped by the vendor's contracts, its privacy commitments and court oversight. In US cases, 11 U.S.C. §363(b)(1) may restrict selling personally identifiable information that a debtor's privacy policy promised not to transfer, unless the sale fits the policy or a court approves it after a consumer privacy ombudsman is appointed. Ask counsel whether to file a request about your data.
Is an exported archive still useful after we migrate?
Yes. Migrations often move only open records or recent history, while the archive keeps closed jobs, resolved tickets and notes. Keep it under your retention schedule for audits, disputes and warranty claims, and consider whether it holds operational history worth assessing for licensing.
Does the export format matter?
Format matters less than completeness and documentation. CSV, JSON or a database dump can all work if every field is present and defined. Ask the vendor for field definitions and attachment mappings, because an export full of unlabeled codes is hard to use once the vendor is gone.
Sources
- Freshdesk permanently deletes the account and its data 14 days after the subscription end date, and the export can take up to 10 business days. Source
- The Help Scout account becomes inaccessible as soon as Delete Account is clicked, and all data is permanently deleted 60 days after cancellation. Source
- When a paid Pro or Business plan is canceled, items become read-only immediately and data is permanently deleted 30 days after the cancellation's effective date. Source
- Under 11 U.S.C. §363(b)(1), a trustee may not sell or lease personally identifiable information covered by a no-transfer privacy policy unless consistent with the policy or approved by the court after appointment of a consumer privacy ombudsman. Source
Related resources
See if your company qualifies
A short company assessment. No data uploads are needed.