Skip to content

Wind-downs and transitions

Your software vendor is shutting down: how to get your records out in time

By SourceX Editorial · Reviewed by Noah Loul ·

Short answer

When a SaaS vendor is going out of business, treat its shutdown notice as the deadline for your data: secure admin access, start complete exports the same day and read your contract's data return terms. The rule: do not wait for a replacement system before exporting, because the vendor's window can close before any migration is ready.

Key takeaways

  • A vendor's shutdown notice sets the real deadline for your records, whatever your own migration plan says.
  • Complete exports with attachments, notes and history come before migration planning, not after it.
  • Your contract's data ownership, transition, return and deletion clauses decide what you can require from the vendor.
  • If the vendor enters bankruptcy, an assignment or a receivership, raise data return requests in writing with whoever controls its assets.
  • A closing software company generally cannot license its customers' data; its own internal records are a separate question.

What should you do first when a vendor announces it is closing?#

The first thing to do when a software vendor announces it is closing is to confirm you still have admin access and start a complete export the same day. Everything else, including choosing a replacement, can follow once a verified copy of your records sits in storage you control.

Read the shutdown notice closely. It usually states when logins stop, whether exports remain available until then, and whether the vendor or a successor will offer transition help. Forward it to whoever owns the contract, finance and IT, and log the date you received it, because that date anchors every later request.

The 72-hour action list#

The 72-hour action list below assumes the notice arrived today and the service still works. Compress the order if the notice gives a very short window, but keep exports ahead of everything else, including vendor selection.

  • Hours 0 to 24: confirm at least two working admin accounts, pause any auto-deletion or archiving rules, and start every built-in export the system offers.
  • Hours 0 to 24: download attachments, photos and documents separately if the export only holds links to them.
  • Hours 0 to 24: pull the contract, order form and any data processing agreement, and mark the data return and deletion terms.
  • Hours 24 to 48: check each export against the live system for record counts, date range, notes and history.
  • Hours 24 to 48: run API or report-based extractions for anything the built-in export missed.
  • Hours 24 to 48: list integrations that copied data elsewhere, such as accounting or CRM syncs, and export from those too.
  • Hours 48 to 72: move verified exports into encrypted, company-controlled storage and start an export log.
  • Hours 48 to 72: write to the vendor requesting a complete data return in a documented format and its deletion timing.
  • Hours 48 to 72: decide whether to pay for any extended access offered, and only then begin migration planning.

What to export from each kind of system#

What to export depends on the kind of system, and the items people miss are usually the ones that explain the work rather than bill for it. Use the table to brief whoever runs the export, and add the system's own custom objects to the list.

What to export from each kind of system
Vendor typeRecords to pullOften missed
Bookkeeping or accounting serviceLedger, reconciliations, invoices, bills and tax filingsReceipt images, adviser notes and closing workpapers
Field service managementCustomers, estimates, jobs, invoices, equipment and membershipsTechnician notes, photos, call recordings and warranty history
Help desk or live chatTickets and conversations with every replyInternal notes, audit history, macros and attachments
CRMAccounts, contacts, deals and activitiesLogged emails, notes, custom objects and field history
Project or issue trackingProjects, issues, comments and attachmentsStatus history and links between issues and to code
Transportation or warehouse softwareOrders, shipments, inventory movements and carriersException records, appointment changes and dock notes
Payroll or HRPay registers, tax forms and personnel filesYear-end filings, benefit elections and policy acknowledgments

What your contract says about getting your data back#

Your contract decides what you can require from the vendor, so read it before arguing about access. Look for who owns customer data, what export or transition help is promised, how long data is kept after termination and whether the vendor will confirm deletion.

Do not expect a closing vendor to be more generous than a healthy one, and published terms at healthy vendors are already short. Freshworks says Freshdesk permanently deletes an account and its data 14 days after the subscription end date and warns its export can take up to 10 business days. Help Scout says an account is inaccessible as soon as it is deleted, with data removed 60 days after cancellation. Smartsheet makes paid-plan items read-only on cancellation and deletes them 30 days after the effective date.

If the vendor has entered bankruptcy, an assignment for the benefit of creditors or a receivership, its contracts and the data it holds are handled inside that process. Ask counsel to identify the trustee, assignee or receiver and send your data return request to them in writing. This is general information, not legal advice.

What your contract says about getting your data back
ClauseWhat it can give youWhat to ask for
Data ownershipConfirmation that the records are yours, not the vendor'sA complete copy in a standard, documented format
Export or transition assistanceHelp moving data, sometimes for a feeField definitions, attachments and history, not a summary file
Post-termination accessA window to retrieve data after service endsWritten confirmation of the date the window closes
Return and deletionAn obligation to return or delete your dataDeletion confirmation only after you have verified your copy
EscrowRelease of escrowed code or data on defined eventsWhether the vendor's closing triggers a release

When the built-in export falls short#

When the built-in export falls short, combine several routes rather than accepting an incomplete copy. Each route fills a different gap, and used together they close many of them before the service goes dark.

  • API extraction with a short script or an integration tool, which can reach comments, history and attachments the export skips.
  • Saved reports and list views exported one module at a time.
  • PDF copies of critical records, such as open warranties or service agreements, when no structured route exists.
  • Copies held by connected systems, such as invoices synced to accounting or contacts synced to email marketing.
  • Notification emails in your own mailboxes, which often record status changes the export leaves out.
  • A written request to the vendor's support team for a database-level export.

If you are the vendor: what a closing software company may license#

A closing software company may be able to license some of its own records, but its customers' data is generally off limits. Customer agreements and data processing agreements usually treat the vendor as a processor of customer data, limit use to providing the service and require return or deletion at the end.

The vendor's own operating records are a different category. Engineering issues, code reviews, release notes, internal documentation and its own support conversations were created by the vendor, though they often contain customer names and details that must be removed first. Aggregated or de-identified usage data sits in between and depends on what the agreements actually permit.

If you are the vendor: what a closing software company may license
RecordUsual starting positionWhat decides it
Customer-entered data in the productNot licensable by the vendorCustomer agreements, DPAs and privacy law
The vendor's own support conversationsPossible after reviewCustomer contracts, privacy notices and redaction
Engineering issues, code reviews and releasesOften the strongest candidateIP ownership, open-source licenses and customer code terms
Aggregated or de-identified usage dataDepends on contract wordingWhether agreements permit aggregated or de-identified use
Internal documentation and playbooksPossible after reviewConfidentiality duties and third-party content

Illustrative: a 3PL loses its dock scheduling vendor#

Illustrative: a fictional regional third-party logistics provider runs dock appointments and carrier check-ins on a small SaaS scheduling tool, alongside NetSuite and a WMS. One morning the vendor emails customers that the service will stop at the end of the following month.

The COO had the IT lead confirm two admin logins and start the built-in export that day. The export held appointments but not the exception notes dock supervisors typed when trucks arrived late or loads were refused, so the IT lead pulled those through the API and matched them to shipment numbers in NetSuite.

Counsel sent the vendor a written data return request citing the contract's ownership clause. The company later moved to a new scheduler from its own verified archive rather than the vendor's final file, and kept the exception history under its retention schedule as a record that could be assessed for licensing.

How SourceX approaches records from a retired vendor#

SourceX treats an archive recovered from a closing vendor like any other retired system. The fit check starts from metadata, such as the system, record families and years covered, and no files are shared at that stage. For closing vendors themselves, the Rights step of the SourceX five-step transaction separates customer-owned data from the vendor's own records before anything else happens.

If a package proceeds, the SourceX Evidence Packet records where the records came from, how they were exported, what rights support the license and who authorized release. SourceX does not host large archives; they remain in the company's own storage or travel on encrypted drives.

Frequently asked questions

Will the vendor delete our data as soon as it shuts down?

Not necessarily on the first day, but you cannot count on access after the stated shutdown date. Some vendors keep data for a short period, some transfer it to a successor and some delete quickly. Get the vendor's deletion timing in writing and finish verified exports before the earliest date mentioned.

Should we pay for extended access if the vendor offers it?

It is worth considering when exports are incomplete or a migration is underway, because lost history is hard to rebuild. Compare the price with the effort of recreating records, and do not let paid extended access delay your own verified export.

Can a bankrupt vendor transfer our data to someone else?

Transfers of data in a bankruptcy are shaped by the vendor's contracts, its privacy commitments and court oversight. In US cases, 11 U.S.C. §363(b)(1) may restrict selling personally identifiable information that a debtor's privacy policy promised not to transfer, unless the sale fits the policy or a court approves it after a consumer privacy ombudsman is appointed. Ask counsel whether to file a request about your data.

Is an exported archive still useful after we migrate?

Yes. Migrations often move only open records or recent history, while the archive keeps closed jobs, resolved tickets and notes. Keep it under your retention schedule for audits, disputes and warranty claims, and consider whether it holds operational history worth assessing for licensing.

Does the export format matter?

Format matters less than completeness and documentation. CSV, JSON or a database dump can all work if every field is present and defined. Ask the vendor for field definitions and attachment mappings, because an export full of unlabeled codes is hard to use once the vendor is gone.

Sources

  • Freshdesk permanently deletes the account and its data 14 days after the subscription end date, and the export can take up to 10 business days. Source
  • The Help Scout account becomes inaccessible as soon as Delete Account is clicked, and all data is permanently deleted 60 days after cancellation. Source
  • When a paid Pro or Business plan is canceled, items become read-only immediately and data is permanently deleted 30 days after the cancellation's effective date. Source
  • Under 11 U.S.C. §363(b)(1), a trustee may not sell or lease personally identifiable information covered by a no-transfer privacy policy unless consistent with the policy or approved by the court after appointment of a consumer privacy ombudsman. Source

Related resources

See if your company qualifies

A short company assessment. No data uploads are needed.

See if you qualify