Ownware
Guide · Aug 12, 2026

What Happens to Your Data When You Cancel — Nine Vendors' Own Policies, Read

We read nine tracked vendors' privacy policies looking for one answer: how long is your data kept after you leave? Three gave a number. The three numbers were 7 days, 9 months and 6 years.

Everyone compares prices before signing up. Almost nobody reads the paragraph that says what happens to their records when they leave.

So we read it — nine vendors from our price ledger, their own published privacy policies, on 1 August 2026. One question: after you cancel, how long is your data kept, and how do you get a copy of it?

Three of the nine gave a number. The three numbers were seven days, nine months, and six years.

What each one says

VendorOn retention after you leaveStated timeframe
Zoho"Once you terminate your Zoho user account, your data will eventually get deleted from active database during the next clean-up that occurs once in 6 months" — and "data deleted from active database will be deleted from backups after 3 months"up to 6 months, plus 3 months of backups
Timetastic"After your account is closed the only personal data we retain is for accounting and legal purposes, which we're required to keep for 6 years"6 years (accounting only)
Calendly"Calendly will process the deletion within 7 days of the request" — and "Once data has been deleted, it cannot be recovered"7 days, irreversible
Setmore"After you deactivate your account, Setmore will continue to retain copies of information to comply with our legal obligations" — deletion and export requests are "fulfilled within 30 days of the receipt of request"⚠️ request fulfilled in 30 days; retention period not stated
Harvest"We retain the Personal Data that we process on your behalf as long as your account is active"none — the policy stops at "active"
FreshBooks"After the completion of the purpose for which it was collected… for a reasonable period of time thereafter, we will either delete the Personal Information or… anonymize it"none — "a reasonable period"
SafetyCulture"We may need to retain certain personal information after we cease providing you with products or services to enforce our terms, for fraud prevention… and/or for proper record keeping"none
Square"we preserve your information after you delete your account" where there is a legal obligation, such as a preservation ordernone
SmartwaiverThe published privacy policy contains no clause on retention after cancellation, deletion timeframes, or data exportthe question is not addressed

(All read 1 August 2026 from each vendor's own published policy. Deputy was a tenth target: its /privacy-policy page is an index of documents rather than the policy text, and the linked privacy portal returned nothing readable, so we have recorded no finding for Deputy rather than guessing at one.)

The three numbers disagree by a factor of three hundred

Calendly: seven days, and explicitly irreversible. Zoho: up to six months in the live database, plus three more in backups. Timetastic: six years, for the accounting subset.

Read carelessly, that looks like one of them is wrong. It is not. They are answering two completely different risks, and the difference matters more than the numbers do.

Short retention is the risk that your records vanish. You cancel in March; in April your accountant asks for the invoice history; it is gone and "cannot be recovered."

Long retention is the risk that your records persist. Customer details, staff data and signed documents sitting on a former supplier's servers for years, under a contract you are no longer paying for and no longer reading.

Neither is a scandal. Both are legitimate, and long retention is frequently a legal requirement rather than a choice — tax records genuinely must be kept. The problem is not the policy. It is that you cannot plan around a number you were never given, and five of the nine did not give one.

Getting a copy out is a separate question, and it is the harder one

A retention policy tells you when your data disappears. It does not tell you whether you can get it back before then. Two mechanics show up in the policies:

Self-serve. Timetastic's policy states the right to "get a copy of your personal data in a structured, commonly used machine readable format", and points to a backup you take yourself from inside the account.

Request-and-wait. Setmore's route is an email to a privacy address, "fulfilled within 30 days." Square's is a request through a portal or a phone number. These are real rights and they work — but thirty days is not the same product as a download button, and the difference is invisible until the day you need it.

What this means in practice

The single most useful thing on this page: export before you cancel, not after. In several of these policies the export right is tied to being a customer, and in at least one the deletion is explicitly irreversible once triggered.

A five-minute check for any tool you currently pay for:

  1. Find the export. If you cannot find it in under two minutes, that is your answer about how easy leaving will be.
  2. Export once, now, while you are calm. Open the file. A CSV you have never opened is not a backup — it is a file.
  3. Search the vendor's privacy policy for the word "retain." If there is no number attached to it, assume you have no guarantee in either direction.
  4. Ask what the export does not include. Attachments, settings, historical versions and signed documents are the usual omissions.
  5. Do this before you decide to leave. The worst time to discover your export is a support ticket is the week you have already signed with somebody else.

The honest counterweight, and it applies to us

Self-hosting does not solve this problem. It relocates it.

When the database is on your server, the retention policy is whatever you do, and the export is a file you already have. But so is the loss: nobody else is keeping a copy, no support team can restore last Tuesday, and "we are required to keep it for 6 years" becomes your legal problem to solve rather than your vendor's.

The honest framing is not "owned data is safe and rented data is not." It is that owning converts a disclosure problem into an operations problem — and an operations problem is one you can actually see. You know exactly where your data is. You are also the only one who does.

If you own anything, the retention question becomes a backup question, which we have written out in full: your backup is not a backup until you have restored it.

How this was done

Nine vendors, their own published privacy policies, read on 1 August 2026, quoted above without paraphrase. Where a policy did not address the question, we recorded that it did not — rather than inferring an answer from a general clause.

Policies change. Every quotation here carries the date it was read, and that is the honest limit of the claim: this is what these nine documents said on one day, not a permanent characterisation of any vendor.


Next steps

Every quotation is taken from the named vendor's own published policy on the date stated. Nothing on this page describes a vendor's conduct — only what its published document does and does not say.

Series · What things cost — part 7 of 11
← What Currency Are You Actually Billed In — And Why the Same Price Is Three Different Prices What a Six-Person Café Pays for Software Every Year — Line by Line →
Own your tools

Stop renting your own business.

Every tool in this store is a one-time purchase: install it on your own server, keep your own data, and never see a renewal invoice.

Affiliate program
Recommend tools people own — earn 35% on every sale. 90-day tracking, instant delivery, payouts by Lemon Squeezy.
Become an affiliate →
Ownware Business tools you own.  ·  [email protected]
No spam — product launches and guides only.
Catalog · Categories · Alternatives · Guides · Price Observatory · State of Self-Hosted 2026 · Ownware Cloud · Changelog · Search · Your purchases · FAQ · Legal · Support · Press kit · Affiliates — earn 35% Powered by Deliora (self-hosted)