What Happens to Your Data If Your CS Vendor Shuts Down or Gets Acquired
By Navin Agrawal · Co-Founder & CTO, Statisfy
If your customer success platform is acquired, sunset, or shut down, what you get to keep is decided by your contract, not by the vendor’s goodwill at the time. The clause that matters is the return-and-deletion term in your data processing addendum, which should state how many days after termination the vendor will return or delete your data. The layer most teams lose is not their account list, which almost always exports cleanly, but the derived and generated data: health score history, QBRs, call summaries and drafted emails, which frequently live in formats that do not travel.
This page covers the three scenarios, what you can realistically export, the five contract terms that decide it, and how to run the migration.
Disclosure: Statisfy is a customer success platform, so we have an interest here. Where this page states what Statisfy commits to, it quotes our own published DPA and terms so you can check it. We are also a younger company than the incumbents, and we address what that means for you directly, near the bottom.
What actually happens to your data when a CS vendor shuts down or is acquired?
Three scenarios get discussed as one thing. They have very different mechanics.
| Scenario | What usually happens | Your real risk | What protects you |
|---|---|---|---|
| Acquisition | Product keeps running. Existing terms normally survive the change of control. | Not seizure. A roadmap freeze, then a sunset 12 to 24 months later. | Change-of-control and notice-period clauses |
| Sunset | Notice period, then a defined export window, then read-only, then off. | Export tooling and support quality degrade as the wind-down proceeds. | Notice period and a self-serve export you can run yourself |
| Insolvency | An administrator controls the assets, including the data infrastructure. | Nobody is answering support tickets, and goodwill is not a mechanism. | A contractual export right, and data you already hold elsewhere |
The pattern across all three: the protections that work are the ones written down before anything went wrong, plus any copy of the data that already sits somewhere you control.
My CS tool is being sunset. What are my options?
Four, and they are not mutually exclusive.
Migrate to a replacement platform and bring the history. The cleanest outcome and the most work. Budget more time for the derived data (score history, lifecycle stage) than for the account records, because that is where mapping gets genuinely difficult.
Fall back to your CRM. If the tool wrote back bidirectionally, a large part of the account record is already in Salesforce or HubSpot under your control, and the sunset is an inconvenience rather than a loss. If it only ever read from your CRM, this option does not exist, which is worth knowing before you need it.
Export to a warehouse and archive. Even if no tool reads it yet, getting the history into BigQuery, Snowflake or Redshift preserves the option. Cheap, and it decouples the deadline from the decision.
Negotiate an extension. Sunsetting vendors grant these more often than teams expect, because an orderly wind-down is cheaper for them than a loud one. Ask early, while there are still people to ask.
The one thing not to do is wait. Export tooling and support responsiveness both degrade as a sunset progresses, and the last month of a wind-down is the worst possible time to discover that your QBR archive only exports one document at a time.
What data can you actually get out, and in what format?
Export is three layers deep, and most vendor export features only cover the first.
Accounts, contacts, subscriptions, renewal dates. Almost always exportable, usually as CSV. This is the layer vendors mean when they say “you can export your data”.
Health scores, score history, risk flags, lifecycle stage, segment membership. Sometimes exportable, and often only as a current snapshot. A score without its history cannot be trended.
QBRs, drafted emails, meeting briefs, call summaries, account plans. The layer most often stranded, because it lives in a proprietary document format with no bulk export.
The practical test is simple and almost nobody runs it: ask for a sample export file of all three layers during the evaluation, not a description of one. A vendor who can send you a real CSV and a real artifact bundle in an afternoon has built export as a feature. A vendor who needs to open a ticket to produce one has built it as a favour, and favours are exactly what stops being available during a wind-down.
Ask specifically whether export is self-serve, whether it is bulk or record-by-record, whether it includes history or only current state, and whether there is an API you could run on a schedule.
Which contract terms decide what happens at shutdown?
Five clauses do most of the work. Read these before the commercial terms, because the commercial terms are negotiable at renewal and these often are not.
Return and deletion window
How many days after termination will the vendor return or delete your data? A stated number is the single most important term on this page. “Upon request” is not a number.
Export format and mechanism
Self-serve or request-based, bulk or per-record, with history or snapshot only. Get this in writing rather than inferring it from a UI you saw in a demo.
Notice period for sunset or material change
How long before the service changes materially or ends. This is what converts a sunset from an emergency into a project.
Survival through change of control
Does the DPA bind an acquirer to the same processing terms? A well-drafted one does, and this is the clause that makes an acquisition a roadmap question rather than a data question.
Retention rights after termination
Some retention is normal and lawful. It should be narrow, stated, and tied to a legal obligation rather than left open.
How do you migrate off a sunset CS platform?
Export everything now, before you choose a replacement
The export is time-boxed by the vendor’s calendar; the platform decision is not. Do not let the two share a deadline. Pull all three layers even if you are not sure what you will keep.
Land it in a warehouse, not a laptop
BigQuery, Snowflake or Redshift. This gives you a durable archive that survives the migration and can be queried later even if no CS tool ever reads it again.
Reconcile against your CRM
Whatever was written back is already yours. Diff the export against the CRM to find what only ever existed in the vendor, because that is your actual exposure and it is usually smaller or larger than people expect.
Decide what genuinely needs to move
Account records and renewal dates: yes. Score history: usually, for trending. Two years of drafted emails: often not. Migrating everything is how migrations overrun.
Rebuild the scoring model rather than porting it
A health score is a formula tuned to one platform’s data shape. Porting the numbers without the model gives you a column nobody trusts. Either rebuild it deliberately or pick a platform where scoring does not need rebuilding.
Step 5 is the one that catches teams out. A configured health score is not portable in any meaningful sense, and moving from one rules-based platform to another means rebuilding it regardless. We cover the mechanics of that in customer health score metrics, and the platform options in the best AI customer success platforms in 2026.
What does Statisfy commit to?
Fair question to turn back on us, and there is a specific reason to ask it: Statisfy is a younger company than Gainsight or ChurnZero, so vendor-continuity risk is a legitimate thing to weigh when buying from us. Here is what is written down, all of it checkable.
- Return and deletion within 30 days. Our Data Processing Addendum states that upon termination, Statisfy will delete or return all personal data within thirty days, unless retention is required by law.
- Certifications. SOC 2 Type II and ISO 27001 certified, GDPR and CCPA compliant. The detail is on security and compliance.
- Portability rights. Our privacy policy recognises rights of access, correction, deletion and portability where applicable law provides them.
- Notice terms. Paid subscriptions auto-renew unless 30-day non-renewal notice is given, and either party may terminate for uncured material breach within 30 days of notice, per our terms of service.
The structural point matters more than any of those clauses, though. Statisfy writes account updates back to your CRM bidirectionally, with Salesforce and HubSpot supported equally deeply. The account record, the activity and the updates land in a system you own and would still own if we disappeared tomorrow. A platform that only reads from your CRM concentrates the risk inside the vendor; one that writes back distributes it to a system you control. That is worth more than a promise, because it does not depend on us being around to keep it.
If you want the specific export formats and mechanism for your own use case, ask us on the call and we will put it in writing. We would rather answer that during an evaluation than have it become a question at renewal.
Ask us the hard version of this question
Bring your data-portability checklist to a 20 minute call. We will answer on export formats, retention and what happens at termination, in writing.
The questions to ask any vendor before you sign
Copy this into your evaluation. It works on us too.
- What is the stated number of days for return or deletion of our data after termination?
- Can we run a full export ourselves, without filing a request?
- Does the export include score history, or only the current score?
- Can you send a sample export of generated artifacts (a QBR, a drafted email) today?
- Is there an API we could run on a schedule to keep our own copy?
- What is the notice period for a sunset or a material change to the service?
- Does the DPA bind an acquirer to the same terms?
- What data do you retain after termination, and under what legal obligation?
A vendor that answers all eight in writing within a week is telling you something real about how they operate. A vendor that answers in adjectives is telling you something too.
Frequently asked questions
What happens to my data if my customer success vendor shuts down or gets acquired?
It depends entirely on your contract, not on the vendor's intentions. In an acquisition the product usually keeps running while the acquirer decides whether to merge or sunset it, and your existing terms normally survive the change of control. In a sunset you typically get a notice period and a defined export window. In an insolvency the company's assets, including its data infrastructure, are controlled by an administrator, and a contractual export right is worth far more than a support ticket. The clause that decides all three is the return-and-deletion term in your DPA: it should say the vendor will return or delete your data within a stated number of days of termination.
My CS tool is being sunset. What are my options?
You have four. Migrate to a replacement platform and move the history with you. Fall back to your CRM if the tool wrote data back bidirectionally, in which case most of the account record is already yours. Export to a warehouse and keep the history as an archive even if no tool reads it. Or negotiate an extension, which sunsetting vendors often grant because a quiet wind-down is cheaper for them than a loud one. Decide early, because export tooling and support responsiveness both degrade as a sunset progresses.
What data should I be able to export from a customer success platform?
Three layers, and most export tools only cover the first. Records you supplied (accounts, contacts, subscriptions) are almost always exportable. Derived data the platform computed (health scores, score history, risk flags, lifecycle stage) is sometimes exportable and often only as a current snapshot rather than history. Generated artifacts (QBRs, drafted emails, meeting briefs, call summaries) are the layer most commonly stranded, because they live in a proprietary document format. Ask for a sample export file of all three before you sign, not a description of one.
Which contract terms matter most for data portability?
Five. The return-and-deletion window (how many days after termination the vendor will return or delete your data). The export format and whether self-serve export exists or you must file a request. The notice period for a sunset or material change to the service. Whether the DPA survives a change of control. And whether any retention right lets the vendor keep data after termination, which is normal for legal obligations but should be narrow and stated.
Does an acquisition change my data rights?
Usually not immediately. A change of control does not by itself void your agreement, and a well-drafted DPA binds the acquirer to the same processing terms. What changes in practice is the roadmap, the support model and the pricing at renewal. The risk is less that the acquirer seizes your data and more that the product is folded into another line and sunset in 12 to 24 months, which is why the notice period and export window in your contract matter more than the acquisition announcement.
What does Statisfy commit to on data return and deletion?
Statisfy's Data Processing Addendum commits to delete or return all personal data within thirty days of termination, unless retention is required by law. Statisfy is SOC 2 Type II and ISO 27001 certified and GDPR and CCPA compliant. Statisfy also writes account updates back to your CRM bidirectionally, so a large part of the account record lives in Salesforce or HubSpot under your control rather than only inside Statisfy.
For the platform comparison itself, see the best AI customer success platforms in 2026 and the customer success platform comparison. If you are migrating because the tool is being sunset rather than because you chose to, the best Gainsight alternatives in 2026 covers the replacement shortlist.