All Posts

Enterprise SaaS

HubSpot's Contact Discovery Reversal Shows Who Really Controls Your CRM Data

HubSpot's Contact Discovery Reversal Shows Who Really Controls Your CRM Data

TechShorts Newsroom

Editorial Team

HubSpot spent four days in July as a case study in how little contractual control most SaaS customers actually have over their own data, and it did not take a breach or a lawsuit to prove it. The interesting part is not that HubSpot tried the change or that it reversed course. It is how ordinary the mechanism was: a routine terms of service update, the kind every enterprise SaaS buyer clicks past, that could have moved a customer's CRM data into a shared commercial pool from a standing start.

What HubSpot tried to do

On July 1, 2026, HubSpot updated its Customer Terms of Service, Privacy Policy and Data Processing Agreement to support a new feature called Contact Discovery, built on a shared enrichment layer the company referred to as Trusted Prospecting. Business contact data, company data, email engagement signals and tracking-code data from customers using HubSpot's enrichment tools would flow into a shared dataset. Other customers could then draw on that pooled dataset to find, verify and add new contacts to their own CRM, according to HubSpot's own community post announcing the change.

The default was opt-out, not opt-in. Unless a customer actively turned participation off, their enrichment data was already contributing to the shared pool.

Four days

The reaction was immediate. Criticism built across LinkedIn and HubSpot's own community forum, from solutions partners, independent consultants, RevOps professionals and competing vendors. MarTech.org captured the plainest version of the objection, from Caitlin Bigelow, CMO of Blazel: the prospect her team spent months earning could land in a shared pool that a competitor accessed by default. Bigelow said she switched CRM platforms that week.

By July 5, four days after the original notice, HubSpot reversed itself. Chief product and technology officer Duncan Lennox posted in the community forum that the company had gotten it wrong and would not move forward with the terms it had communicated on July 1. Co-founder Dharmesh Shah made a similar public acknowledgment. HubSpot committed that any future version of enrichment sharing would be fully and transparently opt-in, with clear, upfront control over participation.

It walked back the terms, not the underlying product ambition. HubSpot said Contact Discovery would still ship, redesigned around explicit consent rather than default participation.

The clause that made this possible

None of this required a breach, a lawsuit or a regulator. HubSpot did something entirely routine: it updated its terms of service and gave customers standard notice. That update alone would have moved the definition of what a customer's CRM data could be used for, and moved it toward pooling with unrelated third parties, including direct competitors.

Nearly every enterprise SaaS agreement contains a version of the clause that made this possible: the vendor's right to amend terms of service unilaterally, with notice delivered by email or in-app banner, and continued use treated as acceptance. Data-use and data-processing language usually lives inside that same amendable document, not inside the negotiated commercial contract. For a self-serve or low-touch enterprise customer, clicking past a routine legal update is not a meaningfully informed decision. That is what let HubSpot describe a default-on data-pooling program as a "legal update" in the subject line of its July 1 notice, rather than the material change in data rights that it actually was.

Why this is not just a HubSpot story

HubSpot reversed course because the backlash was loud, fast and public, not because customers held contractual leverage to stop it. That distinction matters more than the specific feature. The mechanism that produced this episode, a vendor's standing right to redefine data use through a routine terms update, sits underneath most SaaS relationships across the mid-market and enterprise long tail, regardless of vendor.

Any vendor sitting on a large multi-tenant dataset, whether the category is CRM, HR, finance or collaboration software, has the same structural incentive to enrich its product with pooled customer data, and most hold similar contractual latitude to do it through a terms update rather than a renegotiated contract. HubSpot happened to be the company that tested how customers would react in public. It is unlikely to be the last.

What buyers should actually check

Enterprise SaaS buyers renewing or negotiating an agreement this year should treat the amendment clause with the same scrutiny as pricing, not less.

Three questions are worth asking directly. First, can the vendor change data-use terms unilaterally with notice only, or does a material change to data rights require affirmative customer agreement. Second, is any enrichment, model-training or benchmarking use of account data opt-in by default, and can that default be verified in the actual contract language rather than in a blog post or community response. Third, does the agreement distinguish between using a customer's data to serve that customer and using it to build a product or dataset sold to others.

HubSpot's four-day reversal was a good outcome for its customers this time. It was driven by the visibility and volume of complaint, not by a contractual right most of those customers actually held. The lesson for any enterprise buyer is not really about HubSpot's judgment. It is about what is sitting, unexamined, in the amendment clause of every SaaS agreement already signed.