News

“Trusted Prospecting” the day HubSpot tried to hand your hard-earned data to your competitors

Avatar photo
Damian

HubSpot called it “Trusted Prospecting.”

For four days, it meant one thing: the data your team bled for would feed a shared dataset and enrich other HubSpot customers’ records. Including your direct competitors.

The market revolted in four days. HubSpot reversed. The press called it a happy ending.

Too early. I’ve worked in GTM for a decade, and I see more than a controversy here: four questions that stay with anyone who builds pipeline. Let’s take them apart.

The “legal update” that broke the internet

On June 25, 2026, HubSpot sent an unassuming email: a legal-document update, effective July 1. The kind of terms-of-service change admins accept without reading.

This one they should have read.

The email said HubSpot was “expanding data discovery and intelligence features.” Buried underneath: enrichment data (business contact details, employer info, email deliverability signals) “may be shared with other customers.” The kicker? You had to actively opt out before August 4. And if you have to opt out, you’re opted in by default.

To be fair to HubSpot’s telling: the post pitched “better data, not bigger lists,” promised you’d “never pay for a contact already in your CRM,” insisted both enrichment and Contact Discovery were “opt-in” and admin-controlled, and stressed it only checks deliverability and “does not read or share emails.” The friction was in the word opt-in. For accounts already using enrichment, participation ran as a default: something you had to notice and switch off across three separate settings before August 4.

Section 6.3 of the new Product Specific Terms said it plainly: you agree HubSpot may add your Enrichment Data to its commercial dataset and use it to “enrich or otherwise supplement the data sets of other customers.” On August 4, that dataset would power a new feature, Contact Discovery, letting anyone find and add net-new contacts without leaving HubSpot.

Treść artykułu
HubSpot’s official July 1 post, now carrying a banner that the changes are no longer in effect.

 

Enrichment used to be a simple exchange: send a record, get missing fields back. The new mechanism meant the exchange no longer stopped at your instance. Your email engagement data (opens, clicks, bounces, delivery status) was about to become public goods for the rest of the market.

Treść artykułu
Enrichment was always an exchange: a record out, missing fields back. The withdrawn change would have sent your signals onward, to enrich other customers’ records too. Including your competitors’.

“WTF”: the market’s verdict

The GTM community did not hold back. LinkedIn lit up with exactly the crowd that keeps HubSpot alive: sales directors, CMOs, RevOps leaders.

Brent Leary (CRM Essentials) summed it up: “Damn… what was HubSpot even thinking.”

Caitlin Bigelow (CMO, Blazel), a customer of 15 years, laid out the raw injustice: you work to earn a subscriber, HubSpot drops that prospect into a shared pool your competitor gets by default. Her verdict: she switched CRMs that week, and she’s “never coming back.”

Saarika Chotai hit the operational core: “So we are now paying to build a database that also feeds their system and their revenue?”

That last line became the theme. MarTech.org asked it outright: why should customers foot the bill to improve a vendor’s AI products

Treść artykułu
The community reaction on r/hubspot.
Treść artykułu

One take: “a huge GDPR risk,” with EU companies threatening to cancel.

 

And the irony was brutal. HubSpot built its brand on inbound and permission-based marketing, on earning attention with consent. Ending up on the wrong side of a consent fight was almost impossible to defend.

Let’s step back: what a CRM actually is

Before we argue whose data this is, we have to agree on what we’re even talking about. This whole affair is about a layer most companies treat as plumbing, and it’s the foundation the entire go-to-market sits on.

I’m a Pipedrive Platinum Partner in Poland, and I’ve implemented CRMs for five years. So I’ll say it bluntly. A CRM is your company’s foundation: the system of record where the truth lives about who your customer is, what stage they’re at, what they’re worth, and what happened last. Your whole sales motion stands on it.

In the framework we build at Dealme, the CRM is the middle of three inseparable layers: the process layer, the IT layer with the CRM as your Single Source of Truth, and the operator layer. Pull out the middle and the whole engine collapses.

And here’s the part the affair made concrete: your data physically lives inside the vendor’s system. Modern CRMs are SaaS. They don’t sit in your basement, they run in the cloud. HubSpot and Pipedrive on AWS, Salesforce on its Hyperforce architecture. For EU customers, providers host in a European region (e.g. Frankfurt) for GDPR. Convenient, secure, yet your operational truth sits on someone else’s infrastructure. That’s exactly why one clause in the terms stops being a formality.

Treść artykułu
Data flows in from many channels. The CRM merges it into one record, a single source of truth. Only clean data drives sales. Garbage in, garbage out.

Salesforce: the heavy enterprise standard. Endless configurability, highest cost and implementation bar.

HubSpot: the marketing-heavy all-in-one that became the star of this controversy.

Pipedrive: built purely around the rep and the pipeline. Fast, intuitive, execution-driven.

But the golden rule outlasts the tool: a CRM is only as good as the data inside it. If your team lives in spreadsheets and inboxes, all you own is an expensive illusion of control. So when HubSpot reached for this data, it reached for the foundation of every customer’s GTM engine.

Treść artykułu
Scattered data (spreadsheets, email threads, sticky notes, business cards) flows into the CRM merge layer, where it gets deduped, matched and merged, and comes out as one record that drives pipeline, dashboards, reports and automations.

Is your CRM data actually yours?

Yes and no.

Your core records (contacts, notes, deals, call recordings) are your property. HubSpot later reaffirmed that emphatically.

The gray zone is enrichment data: business-card details (name, work email, title, company, seniority) and behavioral signals (opens, clicks, bounces, tracking-code data). Whose is that? Yours? The person’s? The market’s, where the same contacts circulate across dozens of CRMs?

HubSpot’s legal workaround was a Controller-to-Controller DPA: wherever you used enrichment, you and HubSpot both became independent controllers of the shared data. Clever. And exactly what made “whose data is this” stop being obvious.

Opting out was a mechanical nightmare, too. You had to kill both enrichment toggles (automatic plus continuous refresh), stop manually enriching, and opt out of AI model training, because those models power enrichment. And it worked forward only: data already contributed was not pulled back.

The uncomfortable truth every operator needs to hear: operational data in your system of record can quietly become a vendor’s commercial asset. The reason is simple. That’s how the terms were written.

The “mother database” strategy

Let’s be objective. A continuously refreshed, shared dataset is genuinely more accurate than any static list you buy off the shelf. Prospecting data rots fast, and pooled signals from thousands of live instances fix that. ZoomInfo has run this exact contributory model for years.

But there’s one fundamental difference between them. ZoomInfo is a data vendor. HubSpot is your system of record. When the system that holds your operational truth starts acting like a data broker, the governance question changes character. The ZoomInfo comparisons landed instantly and, fair or not, they stuck.

HubSpot’s own paperwork pointed the same way. The update added new sub-processors to power the dataset, including Bright Data, a company known for large-scale web data collection. When your system of record starts wiring in data brokers, “system of record” quietly turns into “data network.”

Legal? It depends, and that’s no dodge. HubSpot emailed EU contacts and leaned on GDPR’s Controller-to-Controller mechanism. But the timing was terrible: they moved to commercialize email signals exactly as France’s CNIL (practical deadline July 14) and Italy’s Garante (window to October 28) were tightening the rules around that same raw material. The DPO question isn’t “is this illegal.” It’s: do I know which signals I collect, why, whether they’re shared, and whether my legal basis holds?

The mother database is a strategic move. And you answer strategic moves strategically, not by frantically clicking opt-out toggles the day before a deadline.

The retreat

On July 5, four days after the change took effect, Duncan Lennox (HubSpot’s CPTO) published “We Got This Wrong. And We Are Fixing It.” He echoed it on LinkedIn: “we made a mistake, and we’re reverting those changes completely.”

No corporate fluff:

“We made a mistake… We will not move forward with the terms of service changes we communicated on July 1, 2026.”

“You control your data. This has always been our policy and will not change.”

Treść artykułu
Duncan Lennox’s July 5 apology post: “We Got This Wrong. And We Are Fixing It.”

 

Co-founder Dharmesh Shah also owned it publicly. Apology analyst Josh Bernoff rated it highly, but flagged the one thing it missed: acknowledging the sheer labor customers pour into cleaning their databases, labor that can’t just be shared “willy-nilly.” He’s right. There’s also an unexplained gap: the July 1 email said opt-out; the apology promises a future opt-in. Two different things.

Even so, credit where it’s due. Reversing a major rollout in four days, publicly, on the channel where it was boiling over, is not the default behavior for a SaaS giant.

The real takeaway: paused, not dead

Here’s the catch most coverage missed.

Lennox withdrew the terms. He left the vision intact. In the very post that put out the fire, he defended it: “We still believe there is a better, more effective way to prospect than the status quo.”

Trusted Prospecting landed on the shelf, ready to return.

And that’s the real lesson. The market is moving toward networked data. It will happen, at this vendor or the next. The only question is who designs the model so you stay the owner rather than the raw material.

So with every new AI or data feature, from any vendor, run this governance test:

Does this feature use my data only to improve my account, or does it also build a shared model, a commercial dataset, or other customers’ results?

The answer tells you whether you’re looking at a product improvement or a quiet transfer of value.

And here the loop closes. A CRM is only as good as the data inside it. If that data was valuable enough that HubSpot tried to build a separate product on top of it, that’s proof of how critical the foundation is that so many treat as an afterthought.

HubSpot backed off. Fast, and with a better apology than most. But the question it raised hasn’t gone away. And when “Trusted Prospecting” returns, it’ll be worth reading that email line by line.

Found this useful?
Subscribe GTM Club
EN Nie odkładaj na jutro. EN Zoptymalizuj sprzedaż z Dealme dzisiaj!