Get the weekly research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.
The policy authorizes HubSpot to share user data with advertising vendors who use cookies, web beacons, and similar tracking technologies to deliver targeted advertisements on third-party websites and services.
This analysis describes what HubSpot's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This provision authorizes disclosure of user browsing and activity data to advertising technology vendors for cross-site targeting purposes, which may require evaluation under GDPR consent requirements and ePrivacy Directive guidance applicable to cookie-based tracking in EU member states.
Interpretive note: The precise scope of data shared with advertising vendors and whether that sharing constitutes a sale under CCPA or CPRA is not fully specified in the excerpted document text and may depend on the specific integrations in use.
The updated policy now explicitly discloses that HubSpot collects Email Engagement Data (such as open, delivery, bounce, and click statuses) from emails sent through its Subscription Services using embedded tracking technologies. This represents formalization of a data collection practice into explicit policy language. However, the policy simultaneously removed a previously stated sentence directing users to a form for removing their personal data from HubSpot's commercial dataset. The updated terms do not indicate an alternative removal mechanism.
View change record →Separately specifies advertising-related data sharing practices and third-party tracking for ad delivery, clarifying scope beyond general vendor sharing.
View full change record →Under this provision, HubSpot may share identifiers, browsing activity, and usage data with advertising vendors who use that data to serve targeted ads on other platforms, including through cookie and web beacon tracking mechanisms.
How other platforms handle this
The right to know with whom we have shared your Personal Data, for what purposes, and what Personal Data has been shared (including whether Personal Data was disclosed to third parties for their own direct marketing purposes)
If GitHub detects the GPC signal from your device, GitHub will not share your data (we do not sell your data).
If you want to see what information we have collected about you, you can request a copy of your data in the Data & Privacy section of your User Settings. You should receive your data packet within 30 days.
Monitoring
HubSpot has changed this document before.
Receive same-day alerts, structured change summaries, and monitoring for up to 20 platforms.
"We may share information about you with third-party vendors who assist us in delivering advertising to you on other websites and services. These vendors may use cookies, web beacons, and similar technologies to collect information about your use of our Services and other websites to provide you with targeted advertisements.Excerpt from HubSpot's Privacy Policy
1. REGULATORY LANDSCAPE: This provision engages GDPR consent requirements, the ePrivacy Directive as implemented across EU member states, and the CCPA and CPRA provisions addressing sale and sharing of personal information for cross-context behavioral advertising. The FTC has enforcement authority in the US context. The Irish DPC is the lead EU supervisory authority for HubSpot's GDPR obligations. 2. GOVERNANCE EXPOSURE: High. Sharing data with advertising vendors for cross-site targeting is a practice subject to heightened regulatory scrutiny under GDPR and CPRA. Where this sharing constitutes a sale or sharing of personal information under CPRA, California residents must be offered an opt-out mechanism. 3. JURISDICTION FLAGS: EU and EEA users face the highest exposure, as cookie-based advertising tracking typically requires prior informed consent under GDPR and ePrivacy rules. California residents have opt-out rights under CPRA. Illinois and other state privacy law frameworks may also apply depending on data types involved. 4. CONTRACT AND VENDOR IMPLICATIONS: Organizations using HubSpot's marketing tools should assess whether tracking pixels or ad integrations embedded in HubSpot-powered pages involve sharing their customers' data with advertising vendors in ways that require additional consent or disclosure under their own privacy programs. 5. COMPLIANCE CONSIDERATIONS: Compliance teams should audit HubSpot's cookie consent mechanisms to verify that advertising tracking does not activate prior to affirmative consent for EU users, and should confirm whether a Do Not Sell or Share opt-out is available and functional for California users.
Regulatory citations, enforcement risk, and due diligence action items.
Ad personalization controls removed. Contact scanning added. Advertiser data partnerships quietly dropped. A timeline of every change.
Provision-level monitoring, governance timelines, and regulatory mapping built from archived source documents and historical version tracking.
This provision authorizes disclosure of user browsing and activity data to advertising technology vendors for cross-site targeting purposes, which may require evaluation under GDPR consent requirements and ePrivacy Directive guidance applicable to cookie-based tracking in EU member states.
Under this provision, HubSpot may share identifiers, browsing activity, and usage data with advertising vendors who use that data to serve targeted ads on other platforms, including through cookie and web beacon tracking mechanisms.
ConductAtlas has identified this type of provision across 295 platforms. See the full comparison.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by HubSpot.