BTIBTI-2026-0001
CRITICALPUBLISHEDBTI-X02BTI-X04BTI-X11
9.0BTSS

HubSpot

The 652-Day Gap: HubSpot Enrichment Contributory Sharing

Version
2
First Detected
2026-07-01
0
THE TAKE

On August 4, 2026, enrichment data contributed by HubSpot customers may be shared with other customers. The contractual authorization to copy customer-transmitted enrichment data into HubSpot's commercial dataset is dated September 18, 2024, which is 652 days before the plain-language notice of July 2, 2026. For part of that window HubSpot's own help center stated the opposite: "HubSpot won't share the data listed above with other accounts." Documented entirely from HubSpot's own pages. Every claim is a quote, a date, and a Wayback-pinned link.

This advisory exists to warn companies running HubSpot on their sites. We do not notify vendors. We do not provide remediation windows. If you're using this vendor, this is your evidence.

0
Revenue impact

What It Costs You

CAC Subsidization

Visitor data captured on a site can flow into data broker networks and identity graphs, eventually surfacing in competitor prospecting tools. The original company paid to acquire the traffic; competitors pay pennies to intercept the lead.

Signal Corruption

Overlapping tracking mechanisms corrupt attribution data. Multiple sources claim credit for single conversions. Pipeline metrics diverge from reality. Marketing decisions get made on numbers that can’t be trusted.

Legal Tail Risk

Pre-consent data collection, undisclosed data sharing, and consent signal violations create regulatory exposure. Class actions and regulatory fines can exceed entire annual marketing budgets. Liability sits with the site owner, not the vendor.

GTM Attack Surface

Third-party scripts execute with full privileges on every page load. Dangerous code patterns, external dependencies, and data interception turn marketing infrastructure into attack vectors. One compromised dependency compromises the entire site.

BTSS breakdown

BTSS Score Breakdown

Vector
BTSS:1.0/TR:A/CT:N/DS:I/FL:C/PR:W/DD:C/RC:Confirmed
Confidence: ConfirmedRevenue channels: Legal Tail Risk · CAC Subsidization
Exploitability
10/ 10
weight 24%
Data Sensitivity
7.5/ 10
weight 20%
Flow
10/ 10
weight 20%
Prevalence
7/ 10
weight 18%
Detection Difficulty
10/ 10
weight 18%
Regulatory touchpoints

Regulatory Touchpoints

GDPR Art. 5(1)(a)European Union

Personal data must be processed lawfully, fairly, and in a transparent manner. This behavior pattern (a documented reversal of a prior public statement about sharing) is addressed under the transparency principle. Determinations belong to your own advisors.

GDPR Art. 6European Union

Processing requires a lawful basis. The pattern of contributing customer-transmitted data to a commercial dataset shared with other customers is addressed under Art. 6. Determinations belong to your own advisors.

CCPA §1798.100(b)California, United States

Notice at or before the point of collection of the categories of personal information and the purposes for which it is used. The 652-day gap between authorization and plain-language notice is addressed under the notice-at-collection provision. Determinations belong to your own advisors.

Citation templates

Citation Templates

For Contracts / DPAs
“Vendor shall not engage in behaviors classified under BTI-2026-0001 (HubSpot), including BTI-X02 (Undisclosed Sharing).”
For Compliance Reports
“BTI Advisory BTI-2026-0001 documents HubSpot engaging in Undisclosed Sharing (BTSS 9.0, CRITICAL).”
For Email / Communication
“We have identified HubSpot as exhibiting Undisclosed Sharing behavior per BTI Advisory BTI-2026-0001. Full details: deployblackout.com/bti/BTI-2026-0001
Created: 2026-07-02Updated: 2026-07-08Version: 2
#hubspot#enrichment#contributory-sharing#documentary#critical
Permanent URL: deployblackout.com/bti/BTI-2026-0001