Export before you cancel: a SaaS checklist for closing companies
Export data before cancelling SaaS by working in a fixed order: keep identity and email until last, export chat, CRM, help desk, finance and code repositories with full history while admin access still works, verify each export, and only then cancel. Archives with years of operational history should be held for a SourceX licensing review.
Why the order of cancellation matters
Export data before cancelling SaaS, and cancel in a deliberate order: business tools first, each only after its export is verified, then email, and the identity provider last. Cancelling a single sign-on provider, letting the domain lapse or closing the company card too early can lock you out of every other system before its history is saved.
Closure is the most common way small businesses exit. Fortune, reporting McKinsey's findings, says 92% of small-business market exits happen through closure, with 5% through sale and 3% through transfer to new owners (Fortune). Every closure ends with subscriptions being cancelled, and what happens to the data afterwards depends on each vendor's terms, not on the company's intentions. Read the termination and data-return terms for every tool before giving notice; what happens to company data when a business closes covers the wider picture.
The archives that deserve the most care hold years of operating history: email, chat, CRM, help desk, finance and code. If the company had 50+ full-time employees at peak (contractors excluded), those archives could interest AI labs and data buyers that license records through SourceX, which is a reason to keep them intact after the business stops.
Order of operations
- Freeze. Stop auto-deletion and retention purges in every tool, and pause any user deprovisioning scripts.
- Secure access. Make sure at least two people still at the company hold admin rights on each tool, and document credentials and recovery codes.
- Keep the plumbing alive. Keep the company domain, DNS and one payment method active, so failed renewals or lapsed verification do not suspend accounts mid-export.
- Export business systems. Chat, CRM, help desk, finance and engineering tools, each verified before moving on.
- Export email. All mailboxes, including departed staff and shared mailboxes.
- Cancel in reverse dependency order. Business tools after their exports are verified, then email, then the identity provider.
- Document. Log each export, its storage location, record counts and the cancellation confirmation.
The checklist, system by system
Before cancelling anything
- Build the subscription list from card statements, AP records and the single sign-on app catalog, not from memory.
- Confirm who controls the assets and must approve cancellations: the owner, the board, an assignee, a trustee or a receiver.
- Read each vendor's termination, notice and data-retention terms.
- Ask counsel about litigation holds and record retention duties.
Chat (Slack, Microsoft Teams)
- Export public channels with files and threads.
- Export private channels and direct messages only where the plan, the company's policy and employee notices allow it.
- Keep channel membership and user lists so conversations can be read in context.
CRM
- Export all objects, including closed-lost opportunities with loss reasons, activity history, logged email, notes and attachments.
- Include field history and audit trails where the plan offers them.
Help desk
- Export every ticket together with its customer replies, private agent notes, tags, SLA timestamps and CSAT ratings.
- Export the knowledge base and macros, which document how the team actually worked.
Finance and ERP
- Export general ledger detail, AP and AR, purchase orders, approval workflows and audit logs.
- Confirm tax and payroll record retention with the company's accountant before closing finance tools; the interim CFO turnaround checklist lists the finance records to secure first.
Code and engineering
- Mirror-clone every repository with full history and branches.
- Export pull requests, review comments and issues separately; they do not live inside the Git history.
- Export wikis and project boards.
Calls and recordings
- Find any call-recording or conversation tools and export recordings and transcripts together with records of the notices given.
- Flag them for review: federal law generally allows recording with one party's consent (18 U.S.C. 2511), but California requires all parties' consent for confidential communications (Cal. Penal Code 632), so whether recordings can be licensed depends on how calls were recorded and what notices were given.
Email and identity (last)
- Export every mailbox, including departed employees, shared mailboxes and archive mailboxes.
- Keep the identity provider until every other export is verified, then cancel it.
Who pays to keep access while exports run
| Option | Who usually bears the cost | When it makes sense |
|---|---|---|
| Keep one or two admin seats on the lowest paid plan | The company or the fiduciary in control | Exports need several weeks or a paid feature |
| Move to a read-only or archive tier, where the vendor offers one | The company | History is large and export tools are slow |
| Pay for the vendor's export or data-return service | The company | Self-serve exports are incomplete |
| Extend the identity provider by a month or two | The company | Several tools depend on single sign-on |
| Let the subscription lapse | No one | Only after the export is verified and stored |
Reading the export results
| Export result | Meaning | What to do next |
|---|---|---|
| Core systems exported and verified, several years of history | Strong candidate for a licensing review | Run the company fit checker and list the systems in the data inventory builder |
| Exports exist but key metadata is missing | Threads and outcomes may be lost | Re-export with full history before cancelling |
| Admin access already lost | Data may be unrecoverable | Start the vendor's account recovery process now |
| Customer content dominates the help desk or CRM | Rights and privacy need review | Check customer contracts and privacy commitments with counsel |
| Little history in any system | Limited licensing value | Keep exports for retention; do not expect a license |
On customer content, FTC staff have said that companies' promises not to use customer data for undisclosed purposes, such as training models, are enforceable whether made in privacy policies, terms of service or marketing materials (FTC staff post, January 2024). Check what the company promised before customer records go anywhere. This is general information, not legal, tax or financial advice. Confirm with your own counsel, tax adviser or professional body before acting.
Red flags
- The help desk or CRM mostly holds the company's clients' data under contracts that bar reuse.
- The records are mainly consumer personal data or protected health information.
- Exports were never taken and the vendor has deleted the account.
- A trustee, assignee or receiver controls the company and has not been involved.
For a software business in an assignment for the benefit of creditors, the page on a SaaS company in an ABC covers contracts, code and customer data, and the checklist before wiping company servers covers on-premises hardware.
Next step
Hand this list to whoever runs IT during the shutdown and agree the cancellation order before the first notice goes out. Once exports are verified, register as a partner to introduce the company; you share fit information only and never handle the exports. Partners earn 25% of the eligible platform fees SourceX actually collects from the referred company's licensing deals, capped at $100,000 per referred company, and the reward becomes payable only after the buyer pays and SourceX receives its fee.
- Step 1Share your linkSend your personal link to a company you know.
- Step 2Company appliesThe company applies itself at /apply.
- Step 3Buyer selects and paysThe buyer selects and pays for the data and SourceX receives its fee.
- Step 4You get your rewardYour share of SourceX fees becomes payable.
Common questions
What happens to SaaS data after a subscription is cancelled?
It depends on the vendor and the contract. Some vendors keep account data for a period after cancellation or downgrade, others delete it after a short window, and some limit access to history on free tiers. Read the termination and data-return terms for each tool before giving notice, and assume nothing can be recovered once the account is deleted.
Which subscription should a closing company cancel last?
The identity provider, with email just before it. Single sign-on often controls access to every other tool, and email is needed for vendor verification, password resets and final correspondence. Cancel business tools one by one after their exports are verified, then email, and the identity provider at the very end, once nothing else depends on it.
Is a CSV export good enough for a licensing review?
Usually not on its own. Summary CSV files often drop conversation threads, internal notes, attachments and timestamps, which is where the operating history lives. Where a tool offers a full export in JSON or a native format with metadata, take that as well. Keep both, record the counts, and note any data the export could not include.
Do we need customer consent to license help desk tickets?
It depends on the customer contracts, the privacy commitments the company made and the laws that apply. Many tickets can be licensed with names and contact details removed under redaction rules agreed before work begins, but commitments not to use customer data for model training must be honored. Counsel should review the contracts, and SourceX reviews rights before anything goes to buyers.
What if admin access was lost when an employee left?
Contact the vendor's support team about its process for recovering an organization's account, and start immediately, because recovery can outlast the remaining subscription period. Verification often relies on proving control of the company's domain, so keep the domain registration and DNS active until recovery is complete. Document every step in case the fiduciary or counsel needs to show who authorized access.
Related pages
- What happens to company data when a business closes?
- Interim CFO turnaround checklist: records, covenants and data value in the first weeks
- Check Company Fit for Data Licensing
- Build a metadata-only business data inventory
- What happens to a SaaS company's contracts, code and data in an ABC
- Before you wipe the servers: a records checklist for closing companies
Free resources
- Client opportunity brief generator — An editable intro email, summary and checklist.
- Days sales outstanding calculator — How many days customers take to pay.
- Business succession planning assessment — Ten questions on successor, transition and documentation.
- All free tools · MCP resource center
By SourceX Partnerships Team · Published 2026-10-09 · Updated 2026-10-09
Know a US company with valuable proprietary data?
Become a referral partner from anywhere we support, get your link and introduce an owner or authorized decision-maker.
Refer a company →I own a business
Explore licensing your company's data to AI developers worldwide. Start a short assessment; no uploads needed.
Start an assessment