Sales Automation

    Pipedrive Backup: What the Vendor Keeps, and What You Have to Export Yourself

    Pipedrive runs nightly encrypted backups of every customer database, and none of them is a restore button. What the export tool covers, and what it leaves behind.

    Editorial illustration for Pipedrive Backup
    August 18, 2026Updated August 16, 20268 min read
    Share:
    The short answer

    Pipedrive keeps real-time replicas and nightly encrypted off-site backups of its customer databases, but publishes no customer-facing restore. The backup you control is a manual export from Tools and apps, run per item type in XLSX or CSV, limited to data your visibility settings allow, and held in the Generated exports list for 28 days.

    Key takeaways

    • Pipedrive's documented backups cover platform failure and data corruption. Restores are described as available on request rather than as a self-serve feature.
    • The customer-facing backup is the export tool, and it runs per item type: activities, notes and files must be exported separately from deals and contacts.
    • Export output is scoped by your visibility group, so an export run by a non-admin is a partial copy that looks complete.
    • Generated export files are available for 28 days, and closed paid accounts are scheduled for permanent deletion within 180 days of closure.

    Reviewed and updated August 16, 2026

    Pipedrive runs nightly backups of every customer database, encrypts them and stores them off-site. None of that is a restore button you can press. The two facts sit side by side in Pipedrive's own knowledge base, and the gap between them is the whole subject: the vendor's backups exist to keep Pipedrive running, and the backup you can actually hold is a spreadsheet you generate yourself.

    Teams find this out at the worst possible moment, usually after somebody bulk-edited four thousand deals or deleted a pipeline that turned out to matter. So it is worth reading what the vendor commits to, what the export tool gives you, and where the export quietly leaves things behind.

    What Pipedrive backs up, in the vendor's own words

    Pipedrive's knowledge base article on data backup, last updated 10 March 2026, describes three separate mechanisms and they do different jobs.

    Database replicas kept in sync in real time. If one of the main database machines fails, Pipedrive can switch to the backup quickly, which the article frames as ensuring continuity of service and preventing data loss. This is failover, and it protects against hardware rather than against you.

    Nightly complete backups of all the database machines. The article says these can be used to recover data in the event of data corruption, and describes the case precisely: the machines are intact but the data has been corrupted on both the main machines and the replicas.

    Nightly backup files of all the customer databases, encrypted and stored securely off-site. Pipedrive's separate security article adds that all backups, wherever you are, are done through Amazon Web Services, and lists the hosting regions: Sydney, Montreal, Frankfurt, Dublin, London, US East and US West. New sign-ups are primarily routed to a region by origin, with Asia and Pacific to Sydney, Canada to Montreal, EU clients to the EU regions, non-EU European and EMEA clients to London, and the rest of the world to the US. The same note says accounts can end up in a different data centre for external reasons, and points anyone who needs to know exactly where their data sits at support.

    Read those three together and the scope is clear. Every mechanism listed protects the platform against platform-level failure. The security article's phrasing on restores is worth quoting for what it does not promise: backups are stored so Pipedrive can restore data upon request. That is a support conversation, not a feature, and nothing in the documentation describes a customer-facing point-in-time restore.

    What the vendor's backups protectPlatform-level failure
    • A database machine failing, handled by real-time replicas
    • Data corruption reaching both main machines and replicas
    • Off-site loss, via nightly encrypted files held on AWS
    • Restores are described as available upon request
    What they do not protectEverything you did on purpose
    • A bulk edit that overwrote a field across thousands of records
    • A deleted pipeline, filter or custom field
    • An integration that wrote the wrong value into every deal
    • A departing admin's cleanup, done with full permissions
    What Pipedrive's published backup mechanisms cover, and what they do not, per its own knowledge base articles on data backup and data security.

    The backup you can actually create is an export

    Section illustration: The backup you can actually create is an export

    Pipedrive answers the question directly under the heading "How can I create a data backup?", and the answer is the export tool: go to Tools and apps, then Export data, generate a spreadsheet of the information you want, and download it. The article adds that this is only available to users with export permissions enabled.

    The export documentation, last updated 9 April 2026, fills in what that means in practice, and four details change how you should run it.

    You can only export what you can see. The article states that even with export permissions, you can only export the data visible to you based on your visibility group or item visibility. An admin's export and a rep's export of the same account are different files, and only one of them is a backup.

    It is nine exports, not one. The Export data section works per item type: leads, deals, organizations, people, products, activities, projects, notes and files each come out separately, in XLSX or CSV. Most item exports include default, custom and system fields plus ownership information and linked records. Pipedrive states outright that activities, notes and files linked to deals and contacts must be exported separately, so a person who exports deals and stops has exported roughly half of what a deal record means.

    Files held in Google Drive are excluded. The article notes that files stored in Google Drive are not exported during global export. That one catches document-heavy accounts, because Smart Docs stores its output in your connected Google Drive, OneDrive or SharePoint rather than in Pipedrive. If your quotes and contracts are Smart Docs, they are not in the Pipedrive export and never were.

    The generated file expires. Exports appear in a Generated exports list under Tools and apps, and the article states exported files are available for 28 days. A backup that lives only in that list is on a four-week timer.

    Two adjacent jobs run through the same door, and it is worth naming them because they get confused with backup. Getting Pipedrive data into Excel is this export: the Export data section offers Excel or CSV per item type, and the list view exports whatever columns you have filtered to. Getting it into Power BI or another BI tool is a different job with a different shape, because a report needs a refreshing connection rather than a dated file, which means either the API or one of the connector services built on it. A spreadsheet dropped into a BI tool once is a snapshot, and a snapshot is a backup rather than a dashboard. Deciding which of the two you actually want, before wiring anything, saves rebuilding it. Pipedrive's own reporting layer answers a good many of the questions people reach for a BI tool to answer, and it is worth exhausting that before adding a pipeline.

    There are smaller exports worth knowing about because they carry configuration rather than records. The data fields export, from Personal preferences, gives item type, field name, field type, whether the field is custom, and the API key for each field. The users and access export gives user name, email, last login time, permission sets and visibility groups. Neither holds a single deal, and both are the part you will miss most when rebuilding, because they describe the shape the records go back into.

    A Pipedrive export that is actually a backup
    • Yes: Leads, deals, organizations, people and products exported per item type
    • Yes: Activities, notes and files exported separately, since they are not carried by the deal export
    • Yes: Run by a global admin, so visibility rules do not silently truncate the file
    • Yes: Data fields setup exported, since it carries field names, types and API keys
    • Yes: Users and access exported, since it carries permission sets and visibility groups
    • Yes: Documents held in the connected Google Drive or OneDrive backed up on that side
    • Yes: Files downloaded off the Generated exports list, which holds them for 28 days
    • No: Treating a single deal export as a copy of the CRM
    What a complete manual Pipedrive export covers, drawn from the item-type table in Pipedrive's export documentation.

    Automating it, and what the API costs

    The manual route is fine as a quarterly ritual and poor as a habit, because the thing you need is a recent copy rather than an accurate memory of making one. Pipedrive's export article names the API as the alternative, listing endpoints for all major data types including deals, contacts, organizations, activities and custom fields, and framing it as the route for scheduled exports, real-time access, selective retrieval and integration with other systems.

    That path has a published price, and it is the reason to design the job rather than write the obvious one. Pipedrive meters API traffic in tokens against a daily budget, and reading a list of entities is one of the more expensive calls in its published cost table. A nightly job that walks every object type is buying the same rows again every night. A job that reads what changed, and only reads everything on a schedule you chose deliberately, does the same work against a much smaller line item. Where that budget sits against the rest of the connection design, including which system owns each field, is worked through in Pipedrive integrations.

    The other choice to make consciously is where the copy lands. Third-party backup services for Pipedrive exist and several rank for this query, and each one is another processor holding your entire customer database. That is a data protection decision as much as an operational one. If your list includes people in the EU or the UK, the same lawful-basis and processor questions covered in GDPR for B2B outbound apply to the backup copy exactly as they apply to the working one.

    Deletion, and the two clocks that run after you leave

    Section illustration: Deletion, and the two clocks that run after you leave

    Two figures in the backup article are worth writing down somewhere a future person will find them, because they are deadlines rather than settings.

    When a paid Pipedrive account is closed, the account and its data are scheduled for permanent deletion within 180 days of the closure date. For free trial accounts, the window is 60 days from closure.

    Neither of those is generous when a team is mid-migration and the reason the account was closed is that everyone moved on. The practical version is to run the full export before the account closes rather than after, while permissions, visibility and the file links all still work, and to check the export against the record counts in the interface rather than assuming the file is complete. A summary count in a confirmation message is not the same evidence as opening the file and reading it.

    1. Step 1Decide the unit

      Records, configuration and documents are three different backups with three different homes. Name who owns each.

    2. Step 2Export as an admin

      Run every item type from Tools and apps, plus the data fields and users exports, so visibility rules do not truncate the file.

    3. Step 3Move it off the list

      Download from Generated exports and store it somewhere durable, since Pipedrive holds the generated file for 28 days.

    4. Step 4Verify by reading

      Open the files and check counts and a sample of linked records against the interface, rather than trusting the export confirmation.

    A Pipedrive backup routine that survives the person who set it up, built from the export options Pipedrive documents.

    What a backup does not fix

    Restoring a CRM restores a record of work. It does not restore the position that work was in, and the difference matters when someone is deciding how much to spend on this.

    A recovered deal comes back with its stage, its value and its owner, and without the context that made the stage credible. Whoever inherits it has to re-establish that by talking to the account, which is the expensive half. The same is true of a contact record: the address and the title come back, and the reason this person answered comes back only if somebody wrote it down.

    The wider version is that a CRM is a ledger of conversations that already happened. Protecting it well is basic hygiene and does nothing about the number of conversations happening next month, which is the constraint most teams actually have. The suppression side is the exception worth naming, because it is the one part of the CRM whose loss directly damages outbound: the record of who has already been contacted, who replied, and who asked not to be. That belongs in a suppression list that outlives any single tool, for the same reason list hygiene belongs outside the sending platform.

    If you are still choosing where the records live rather than protecting what is in them, the CRM options for SDR teams and the Pipedrive alternatives roundup are the earlier decision, and Pipedrive against Salesforce is the comparison most buyers are running.

    Where we sit

    Section illustration: Where we sit

    RevenueFlow does not sell Pipedrive, resell it, or take a fee for backing it up. We run cold email and LinkedIn outbound on Email Bison and HeyReach, and the account above is a documentation-grounded read of a vendor we do not operate as our own CRM.

    The half we do run is the one that fills the pipeline a backup then protects. Our campaigns send one message per prospect with nothing scheduled behind it, priced per qualified meeting against criteria agreed in writing before launch. You can see what that produces on your own market with a free campaign.

    Backup mechanisms, hosting regions, export permissions, the per-item export table, the 28-day availability of generated exports and the 180-day and 60-day deletion windows are per Pipedrive's own knowledge base, fetched 16 August 2026. Verify current terms with the vendor before relying on them.

    Questions

    Frequently asked questions.

    Frequently asked questions
    Does Pipedrive let me restore my own data?
    Pipedrive's documentation describes replicas, nightly machine backups and encrypted off-site files, and says backups are stored so data can be restored on request. It does not document a self-serve point-in-time restore. Practically, recovering from your own bulk edit means a support conversation or your own export, so keep an export you control.
    What does a full Pipedrive export actually include?
    Nine item types, each exported separately in XLSX or CSV: leads, deals, organizations, people, products, activities, projects, notes and files. Most include default, custom and system fields plus ownership and linked records. Pipedrive states that activities, notes and files linked to deals and contacts have to be exported on their own.
    Are my Smart Docs documents in the Pipedrive export?
    No. Pipedrive's export article states that files stored in Google Drive are not exported during global export, and Smart Docs saves documents to your connected Google Drive, OneDrive or SharePoint. Quotes and contracts created that way are backed up on the storage provider's side, which is a separate job with a separate owner.
    How long do I have to export after closing the account?
    Pipedrive schedules a closed paid account and its data for permanent deletion within 180 days of the closure date, and a closed free trial account within 60 days. Run the export before closure rather than after, while permissions, visibility settings and file links still work as expected.
    PipedriveCRMData ExportRevOpsVendor Evaluation
    Byline

    About the author.

    RevenueFlow Team

    B2B cold email experts helping companies generate qualified leads through done-for-you outreach campaigns.

    RevenueFlow Team

    Your next move

    Ready to scale your outreach?

    We build GTM engines that book real meetings. See the receipts.

    Further reading

    Related articles.

    Sales Automation

    Pipedrive Integrations: Deciding Which System Owns Each Field

    Every Pipedrive integration failure that costs money comes from two systems writing one field with no rule about who wins. How to settle that first.

    8 min readRead →
    Sales Automation

    Pipedrive Pricing: Why Half the Numbers Online Describe Retired Plans

    Pipedrive renamed every plan in 2025, so most pricing write-ups quote a retired rate card. The five inputs that actually decide your bill, from the vendor's own docs.

    8 min readRead →
    Sales Automation

    Pipedrive vs Salesmate: Where the Outreach Engine Sits in the Price

    Both run a good deal board. The purchase turns on where each vendor puts sequences, quotes and a team inbox in its ladder, and how many line items you end up holding.

    7 min readRead →
    Sales Automation

    The Pipedrive Gmail Add-On: What the Side Panel Does, and Where Gmail's Limits Start

    What the Pipedrive Gmail side panel shows and creates, how it differs from email sync, and the published Google sending limits that decide what Gmail cannot be.

    7 min readRead →
    Sales Automation

    Pipedrive MCP: Giving an AI Assistant Write Access to Your Pipeline

    Pipedrive's native MCP server lets an assistant create and update CRM records. The permission model, the setup, and where it belongs against the API and the rules engine.

    7 min readRead →
    Sales Automation

    The Attio API: Two Rate Limits, and Only One Behaves Like a Rate Limit

    Attio caps its API at 100 reads and 25 writes per second, then prices list queries by complexity score. That second limit grows as your workspace does.

    8 min readRead →