On 1 July 2026, HubSpot told customers it was expanding a feature called Contact Discovery, and in doing so would begin pooling enrichment data, business contact details, employer information and email deliverability signals, across customer accounts unless people manually opted out before 4 August. By 5 July, four days later, HubSpot had reversed the decision entirely. Founder and CTO Dharmesh Shah posted a one-line apology on LinkedIn: “Sorry. You are right. We made a mistake and are reversing that decision.” Chief Product and Technology Officer Duncan Lennox followed with a longer admission that the rollout had put business goals ahead of customer trust.
It is tempting to read this as a story about one vendor getting the optics wrong and fixing it fast, which is broadly true and reflects well on HubSpot’s willingness to reverse course in days rather than quarters. We think the more useful story is a different one. A default opt-in change to how customer data gets used sat in a terms of service update for the better part of a week before enough people noticed to force a reversal. That gap, between when a data policy changes and when customers actually register it, is the real subject worth examining, and it applies to every CRM platform, not just this one.
What did HubSpot actually announce, and why did it reverse course in four days?
What did HubSpot change and then reverse? HubSpot’s 1 July terms of service update would have shared enrichment data, business contact details, employer information and email deliverability signals, across its customer base through a commercial dataset that powered a new Contact Discovery feature, internally referred to as Trusted Prospecting. Core CRM records such as contacts, notes, deals, call recordings and custom fields were explicitly excluded and never at risk. The part that triggered the backlash was that participation was opt-out rather than opt-in: any customer using enrichment features was automatically enrolled, with the ability to withdraw split across several separate settings that most people would never think to check.
The reversal was fast because the criticism was specific and public. Sales and marketing leaders pointed out on LinkedIn that they had spent years building proprietary contact databases that HubSpot’s own tooling would now help redistribute to competitors, without anyone having asked them first. Within days, Chief Customer Officer John Dick confirmed HubSpot would not move forward with the July terms, and Duncan Lennox committed that any future enrichment changes would be fully and transparently opt-in with advance notice. That is a genuinely good outcome, and it is worth crediting a vendor for listening and moving quickly. It does not resolve the underlying question of how a change like this nearly went live in the first place.
What is data enrichment pooling, and why do CRM vendors want it?
What is data enrichment pooling? Data enrichment pooling is a model where a software vendor aggregates certain data fields across its customer base, business contact details, firmographic data, engagement signals, into a shared commercial dataset, then uses that pooled dataset to improve features for everyone drawing on it. The logic is straightforward and not inherently sinister. The more current and complete a shared pool of business contact data is, the better a prospecting or enrichment feature performs for every customer using it, in the same way a fraud detection model improves when it sees data from more transactions.
The reason vendors are reaching for this model now is that AI features are hungry for exactly this kind of data. A prospecting agent that finds and verifies new contacts is only as good as the dataset behind it, and building that dataset from public sources alone is slower and thinner than drawing on the live, constantly updated contact data already sitting inside customer accounts. That is a real and reasonable product incentive. It just runs directly into the fact that the data in question was entered by customers, about their own contacts, for their own purposes, and most of them never expected it to become part of someone else’s product.
Why did an opt-out default cause more damage than the data sharing itself?
Why did the opt-out structure cause the backlash? Because it shifted the burden of protecting the data from the vendor to the customer, and split that burden across multiple settings for enrichment participation, AI model training and tracking-code signals, so that withdrawing fully required finding and toggling all of them. Most customers only discover a change like this when someone else flags it publicly, which is exactly what happened here. The policy was defensible in the vendor’s product logic and indefensible in its delivery, and those are two different failures that are worth separating.
This is where the more optimistic reading of the episode lives. Opt-in versus opt-out is a solvable design choice, not a fundamental limit on what AI-powered CRM features can do. HubSpot’s own commitment, that future enrichment changes will be opt-in with advance notice, shows the company already understands this. Any CRM leader watching this play out has a template now for the question to ask before agreeing to the next feature that touches shared or pooled data: is this opt-in by default, is the scope of what is shared stated plainly in one place, and is there a single control that withdraws consent rather than five scattered ones.
Is this a HubSpot problem, or a CRM industry problem?
Is data pooling unique to HubSpot? No. Every major CRM platform, Salesforce with Data 360, HubSpot with Breeze, Dynamics 365 with Copilot and Dataverse, is building AI features that improve when they can draw on more data, and every one of them faces the same commercial pull toward pooling, enrichment and cross-account learning. HubSpot happened to move first and loudly enough to get caught, which makes this episode useful precisely because it is not really about HubSpot. It is a preview of a decision every CRM vendor is going to face as their AI roadmaps mature, and a preview of how customers will react when the terms feel taken rather than given.
That is genuinely encouraging for CRM buyers, because it means this is the moment vendors are calibrating how much transparency the market demands, and the market has just shown its hand clearly. Vendors that build opt-in, clearly scoped data sharing into their AI features from the outset will earn a trust advantage over the ones that default to sharing and hope nobody checks. As an independent observer of Salesforce, HubSpot and Dynamics 365, we expect the vendors who learn this lesson fastest, rather than the ones who avoid the headline, to be the ones enterprise buyers gravitate toward over the next few product cycles.
How exposed is your own CRM data right now?
How do you check your own data-sharing exposure? Start with three questions you can answer this week. First, which AI, enrichment or prospecting features are switched on across your CRM instances, and did anyone read the terms attached to each one when it was enabled. Second, for each of those features, is participation opt-in or opt-out, and where does the setting that controls it actually live. Third, does your organisation have one person accountable for reviewing CRM vendor terms of service updates, or does that responsibility sit nowhere in particular, which is how most teams would have missed the 1 July change entirely.
Most organisations will find the answer is somewhere between reassuring and mildly uncomfortable, and either way that is useful information rather than a crisis. The point of the exercise is not to distrust every vendor feature. It is to close the gap between when a data policy changes and when your organisation actually notices, so that the next time a vendor makes a call like HubSpot’s July decision, you are the one reading the terms on day one rather than reacting to a LinkedIn post on day four.
Where should CRM leaders start this quarter?
What should CRM leaders do first about vendor data governance? Assign one owner, whether that is RevOps, IT or legal, to review terms of service and data processing updates for every CRM and CRM-adjacent tool in use, and put a standing thirty-minute slot on the calendar each quarter to do it, rather than relying on someone stumbling across the announcement. Build a simple register of every enrichment, prospecting or AI feature currently switched on, whether it is opt-in or opt-out, and who approved it. That register turns a vague sense of exposure into a specific, manageable list.
Then extend the same scrutiny forward rather than only backward. Before the next AI feature launch from any of your CRM vendors, ask the three questions above before enabling it, not after. None of this requires slowing down your adoption of genuinely useful AI capability, and it should not. It requires treating vendor terms with the same seriousness you already apply to the data quality of the records inside your CRM, because both determine whether the AI built on top of your data is something you actually trust.
The Sirocco perspective
We think HubSpot deserves real credit for reversing course in four days once it heard the reaction, and we also think the episode is a useful prompt for every CRM leader, not only HubSpot customers. In our work across Salesforce, HubSpot and Dynamics 365, we consistently see the same pattern: the organisations best placed to benefit from AI are the ones who treat their CRM data as a governed asset, with clear ownership of what gets shared, enriched or pooled, and clear visibility into vendor terms as they change. As an independent partner with no allegiance to any one vendor’s roadmap, we are able to give a straight read on what a given feature or terms update actually means for your data, rather than the read the vendor would prefer you to have.
If you want a clear picture of which AI and enrichment features are switched on across your CRM estate today, and whether the terms behind them are ones you would have chosen knowingly, that is a conversation worth having before the next vendor makes a change like HubSpot’s. You can schedule a consultation with our team whenever the timing suits.
Get in Touch
If you are not sure which AI, enrichment or prospecting features are switched on across your CRM estate, or what their terms actually allow, we can help you find out and set proper ownership around it. Tell us where your CRM data lives today and we will help you map a governance model that fits.
