HubSpot
The 652-Day Gap: HubSpot Enrichment Contributory Sharing
On August 4, 2026, enrichment data contributed by HubSpot customers may be shared with other customers. The contractual authorization to copy customer-transmitted enrichment data into HubSpot's commercial dataset is dated September 18, 2024, which is 652 days before the plain-language notice of July 2, 2026. For part of that window HubSpot's own help center stated the opposite: "HubSpot won't share the data listed above with other accounts." Documented entirely from HubSpot's own pages. Every claim is a quote, a date, and a Wayback-pinned link.
This advisory exists to warn companies running HubSpot on their sites. We do not notify vendors. We do not provide remediation windows. If you're using this vendor, this is your evidence.
What It Costs You
CAC Subsidization
Visitor data captured on a site can flow into data broker networks and identity graphs, eventually surfacing in competitor prospecting tools. The original company paid to acquire the traffic; competitors pay pennies to intercept the lead.
Signal Corruption
Overlapping tracking mechanisms corrupt attribution data. Multiple sources claim credit for single conversions. Pipeline metrics diverge from reality. Marketing decisions get made on numbers that can’t be trusted.
Legal Tail Risk
Pre-consent data collection, undisclosed data sharing, and consent signal violations create regulatory exposure. Class actions and regulatory fines can exceed entire annual marketing budgets. Liability sits with the site owner, not the vendor.
GTM Attack Surface
Third-party scripts execute with full privileges on every page load. Dangerous code patterns, external dependencies, and data interception turn marketing infrastructure into attack vectors. One compromised dependency compromises the entire site.
BTI-X: Contextual Codes
“They lied about what they take.”
Transforms any BTI-C detection into a deception finding. A vendor doing C10 (Fingerprinting) while marketing as "cookieless" is not a technical issue — it's fraud.
“They take in ways that breach your agreement.”
Transforms any BTI-C finding into a contractual breach. Technical evidence becomes legal evidence when mapped against specific DPA or contract provisions.
BTSS Score Breakdown
BTSS:1.0/TR:A/CT:N/DS:I/FL:C/PR:W/DD:C/RC:ConfirmedRegulatory Touchpoints
Personal data must be processed lawfully, fairly, and in a transparent manner. This behavior pattern (a documented reversal of a prior public statement about sharing) is addressed under the transparency principle. Determinations belong to your own advisors.
Processing requires a lawful basis. The pattern of contributing customer-transmitted data to a commercial dataset shared with other customers is addressed under Art. 6. Determinations belong to your own advisors.
Notice at or before the point of collection of the categories of personal information and the purposes for which it is used. The 652-day gap between authorization and plain-language notice is addressed under the notice-at-collection provision. Determinations belong to your own advisors.
Citation Templates
“Vendor shall not engage in behaviors classified under BTI-2026-0001 (HubSpot), including BTI-X02 (Undisclosed Sharing).”“BTI Advisory BTI-2026-0001 documents HubSpot engaging in Undisclosed Sharing (BTSS 9.0, CRITICAL).”“We have identified HubSpot as exhibiting Undisclosed Sharing behavior per BTI Advisory BTI-2026-0001. Full details: deployblackout.com/bti/BTI-2026-0001”