Marketing platforms have spent a decade telling customers that the data inside their CRM belongs to them. That promise just failed its first real stress test. HubSpot spent four days finding out what happens when a shared-data feature ships quietly, and the answer is that customers now read terms of service like auditors.
What HubSpot Tried to Do
On July 1, HubSpot rewrote the customer-facing description of two features, Contact Discovery and Trusted Prospecting, and set them to automatic opt-in. The mechanism: enrichment data one customer’s CRM had accumulated on a contact could flow into a shared pool that other HubSpot customers could then draw on to fill in their own records. The authorizing language in HubSpot’s Product Specific Terms had actually been added on September 18, 2024, nearly two years earlier, a gap of roughly 652 days between the policy change and the moment customers were told what it meant in practice.
Customers who used HubSpot’s enrichment tools found themselves opted in by default, and turning it off was not a single switch. Withdrawal was split across three separate settings, enrichment participation, AI-model training, and tracking-code intent signals, so switching off one left the other two running.
Why the Backlash Was Immediate
The objection was not that HubSpot had built a data-enrichment product. It was that customer-built CRM records were being converted into an input for a shared commercial product without a clear, upfront choice. Gabe Larsen, chief revenue officer at revenue operations firm Atonom, told MarTech.org the arrangement amounted to: thanks for spending years building your CRM, we might use your data to make our product better for everyone else. Channing Ferrer, CRO at competitor Brevo and a former HubSpot executive, was blunter, calling it crazy to use one company’s data to help a competitor. Marketing writer Melissa Rosenthal framed the underlying shift: the CRM customers had been told they owned was quietly becoming an input to a data product sold back to everyone else.
By July 5, the plan was dead. HubSpot’s chief product and technology officer, Duncan Lennox, posted “We Got This Wrong. And We Are Fixing It” to the company’s community forum: “We made a mistake. Nothing matters more to us than the trust of our customers, and with our recent terms of service update we let you down. We are sorry about that.” HubSpot said it would not move forward with the July 1 terms, restated that customers control their data, and committed that any future version of enrichment sharing “will be fully and transparently opt-in.”
The Bigger Pattern: Data as Shared Infrastructure
HubSpot’s four-day reversal is a symptom, not the disease. Marketing and sales platforms increasingly treat the customer data flowing through them as infrastructure to be pooled, not just records to be stored, the same instinct behind the broader move from siloed customer databases toward agentic data platforms built to feed AI systems across a customer base. The commercial logic is real: enrichment gets better with more contributors, and AI features need training signal from somewhere. But the more platforms lean on customer data as a shared resource, the more that data becomes a point of leverage and dispute, a dynamic already visible in the wider fight over who controls the data layer beneath AI agents.
Why This Lever Keeps Getting Pulled
The economic logic behind Contact Discovery is not unique to HubSpot. Any large CRM or marketing automation vendor sitting on troves of first-party customer records faces the same temptation: a single customer’s enrichment data is worth more when it is pooled across an entire customer base, and AI features that promise to auto-fill or auto-score contacts need training signal from somewhere. That is the same pressure driving the broader consolidation of customer data platforms into shared, AI-fed infrastructure. The difference is that HubSpot tried to make the pooling automatic and opt-out, buried in Product Specific Terms rather than surfaced as a product decision, and the market corrected it in four days instead of years.
That speed is itself a signal. Marketing operations teams and revenue leaders, the Atonom and Brevo executives quoted above among them, are now reading vendor terms of service the way security teams read a breach disclosure: assuming the worst until the vendor proves otherwise in plain language. A platform that wants to build a shared enrichment network going forward will need to earn that trust explicitly, not assume it by default.
What It Means for the Marketing Leader
Every marketing operations team running a CRM or CDP now has a homework assignment: read the Product Specific Terms, not just the marketing copy, on every platform holding first-party customer data, and check the date they were last changed. HubSpot’s gap between the terms change and the customer notice was 652 days, which means a data-sharing clause can sit live and unenforced-against for years before it is exercised.
Ask vendors directly whether contact enrichment, lookalike modeling, or AI training draws on a shared pool that includes other customers’ data, and whether opting out is one setting or three. A platform that cannot answer specifically, in writing, is a platform where the answer is probably yes to something you have not agreed to.
What to Do Next
Treat this as the moment to formalize a data-sharing clause review into the vendor renewal process, not a one-time reaction. Build a standing checklist: what enrichment features are enabled by default, what data leaves the account boundary, and what the opt-out actually covers. HubSpot says its next version of enrichment will be opt-in by design. Whether that holds, and whether competitors follow before their own version of July 1 forces the issue, is the test worth watching through the rest of 2026.
Source: HubSpot Community