clause.watch Contracts Recent changes Start monitoring

Monitored company

Hubspot

clause.watch tracks 2 legal documents published by Hubspot, re-reading each one every six hours. Below is what each document covers, in plain English.

Legal Stuff

64,223 characters · Read the original

We monitor this document. A plain-English summary has not been published for it yet.

Privacy Policy

65,560 characters · Read the original

HubSpot Privacy Policy: User-Friendly Overview

*Policy last modified: April 14, 2026. This summary is informational and not legal advice.*

1. Data Collection & Usage

HubSpot may collect:

  • Identity and business information: name, email, phone number, address, job title, company, and account details.
  • Payment information: billing details and financial information, processed through third-party payment providers.
  • Usage and technical data: IP address, browser, device, operating system, log-in activity, viewed pages, product features used, and workflow activity.
  • Website and tracking data: cookies, pixels, web beacons, online identifiers, and information collected through HubSpot tracking code installed on customer websites.
  • Information from other sources: public websites, social media, partners, customers, affiliates, and third-party providers.
  • Integration data: information from connected services such as Gmail, Google Calendar, Drive, YouTube, and other applications.

HubSpot uses this information to:

  • Provide, authenticate, support, and bill for its services.
  • Improve and develop its products, communications, and AI features.
  • Detect fraud, security incidents, abuse, and policy violations.
  • Send marketing, promotional, event, and product communications.
  • Personalize advertising and recommendations.
  • Create and operate a commercial dataset of professional/business contact information for enrichment products.

A significant risk is that HubSpot may process data about professionals obtained indirectly from public or third-party sources and make it available to HubSpot customers for sales and marketing.

HubSpot generally retains data while it has a legitimate business, legal, or contractual need. It may delete, anonymize, or isolate data when no longer needed, but no fixed retention schedule is provided.

2. User Rights

Depending on location, users may request:

  • Access, correction, updating, deletion, or portability of personal data.
  • Restriction of or objection to processing.
  • Withdrawal of consent.
  • Opt-out from marketing, personalized advertising, and certain data sharing.
  • Removal from HubSpot’s commercial dataset.
  • Appeal of a denied privacy request.
  • Non-discrimination for exercising privacy rights.

Requests can be made through HubSpot’s privacy request or preference forms, or by emailing privacy@hubspot.com. Identity verification may be required, and legal exceptions may permit HubSpot to refuse or limit a request.

If HubSpot processes data on behalf of one of its customers, the customer—not HubSpot—is generally the data controller. Users should contact that customer directly.

California residents have additional CCPA rights, including access, deletion, correction, information about disclosures, and opting out of “sale” or “sharing.” The policy states that some data may be “sold” or “shared” with advertising partners and HubSpot customers using enrichment products.

3. Third-Party Sharing

HubSpot may share data with:

  • Hosting, payment, analytics, marketing, support, and security providers.
  • HubSpot affiliates, partners, co-marketing partners, and Marketplace providers.
  • Advertising networks for personalized advertising.
  • Customers using HubSpot enrichment products.
  • Authorities when legally required or when necessary to protect rights, safety, or security.
  • A successor company in a merger, acquisition, bankruptcy, or asset sale.

Connected integrations may receive broad access. For example, Gmail integration may read, store, modify, create, and send emails; Calendar may modify calendars and events; Drive may access and upload documents. HubSpot disclaims responsibility for third-party integration practices.

Data may be transferred internationally using contractual safeguards, including Standard Contractual Clauses and the Data Privacy Framework.

4. AI/ML Training

Yes. HubSpot states that it may use personal data processed through its products to develop, support, improve, and train AI models and machine-learning products. It does not clearly promise that customer data is always excluded or fully anonymized before such use.

However, HubSpot specifically states that Google Workspace API data is not used to develop, improve, or train generalized AI/ML models. Aggregated, non-identifying statistics may also be published externally.

5. Key User Obligations and Restrictions

Users and customers must:

  • Review and control permissions granted to third-party integrations.
  • Avoid posting sensitive information in public forums; posts may remain after account termination.
  • Comply with HubSpot’s Acceptable Use Policy and anti-spam rules.
  • Include legally required opt-out mechanisms in emails.
  • Obtain required notices and consents before transferring personal data to HubSpot.
  • Avoid using the service for unlawful, abusive, or unsolicited commercial communications.

Violations may result in suspension or termination.

6. Liability & Disputes

This privacy policy itself contains limited liability terms and does not provide a comprehensive damages cap, warranty disclaimer, or governing-law clause. Those terms are incorporated from the HubSpot Customer Terms of Service and related agreements.

For EU, UK, and Swiss individuals relying on the Data Privacy Framework, unresolved complaints may ultimately qualify for binding arbitration after specified procedures are exhausted. Lawful government disclosures may still occur.

7. Changes

HubSpot may update the policy periodically and encourages users to review it. Changes will be posted on the privacy-policy webpage. For material changes, HubSpot says it will provide direct notice, such as email. Cookie practices may also change through updates to the separate Cookie Policy without additional notice.

Change history

2026-09-06 · Privacy Policy

grew 21.0% · Observed by clause.watch

The wording changed. No written summary was produced for this revision.

2026-09-02 · Privacy Policy

shrank 17.3% · Observed by clause.watch

The wording changed. No written summary was produced for this revision.

2026-09-01 · Legal Stuff

shrank 15.8% · Observed by clause.watch

The wording changed. No written summary was produced for this revision.

2026-09-01 · Privacy Policy

grew 21.0% · Observed by clause.watch

The wording changed. No written summary was produced for this revision.

2026-09-01 · Legal Stuff

grew 18.7% · Observed by clause.watch

The wording changed. No written summary was produced for this revision.

2026-09-01 · Privacy Policy

shrank 17.3% · Observed by clause.watch

The wording changed. No written summary was produced for this revision.

2026-08-30 · Legal Stuff

shrank 15.8% · Observed by clause.watch

The wording changed. No written summary was produced for this revision.

2026-08-29 · Legal Stuff

grew 18.7% · Observed by clause.watch

The wording changed. No written summary was produced for this revision.

2026-08-29 · Legal Stuff

shrank 15.8% · Observed by clause.watch

The wording changed. No written summary was produced for this revision.

2026-08-28 · Legal Stuff

grew 18.7% · Observed by clause.watch

The wording changed. No written summary was produced for this revision.

2026-08-28 · Privacy Policy

grew 21.0% · Observed by clause.watch

No

2026-08-28 · Privacy Policy

shrank 17.3% · Observed by clause.watch

The wording changed. No written summary was produced for this revision.

2026-08-26 · Legal Stuff

shrank 15.7% · Observed by clause.watch

The wording changed. No written summary was produced for this revision.

2026-08-25 · Legal Stuff

grew 18.6% · Observed by clause.watch

The wording changed. No written summary was produced for this revision.

2026-08-25 · Privacy Policy

grew 20.9% · Observed by clause.watch

No

2026-08-24 · Privacy Policy

shrank 17.3% · Observed by clause.watch

No

2026-08-21 · Privacy Policy

grew 20.9% · Observed by clause.watch

No

2026-08-21 · Privacy Policy

shrank 17.3% · Observed by clause.watch

No

2026-08-19 · Legal Stuff

shrank 15.7% · Observed by clause.watch

The wording changed. No written summary was produced for this revision.

2026-08-18 · Legal Stuff

shrank 3.0% · Observed by clause.watch

Summary

The supplied material does not contain an actual contract diff. It only states:

> “Text modified while maintaining similar length”

Accordingly, there is not enough information to identify specific legal changes, new obligations, or altered risk allocation.

AI Training and Customer Data

No language has been provided addressing:

  • Whether customer data may be used to train, fine-tune, or improve AI models;
  • Whether customer data is used for product development, analytics, or benchmarking;
  • Whether inputs, outputs, prompts, or metadata are retained;
  • Whether data is anonymized, aggregated, or de-identified before use;
  • Whether the customer can opt out of AI training or withdraw consent;
  • Whether third-party AI providers may access or use the data;
  • Ownership or licensing rights in customer data, prompts, or outputs; or
  • Security, confidentiality, deletion, or retention requirements connected to AI use.

Risk Assessment

Because the underlying before-and-after wording is missing, it is not possible to determine whether the amendment:

  • Expands or restricts the provider’s rights to use customer data;
  • Creates a new license to customer data;
  • Changes confidentiality or privacy protections;
  • Introduces broader data-retention rights;
  • Shifts responsibility for regulatory compliance; or
  • Permits use of data to train generative AI systems.

Information Needed

Please provide the complete diff, including the original and revised language. The relevant provisions may include sections titled:

  • Data Use or Customer Data;
  • Privacy and Security;
  • Confidentiality;
  • Artificial Intelligence or Machine Learning;
  • Product Improvement;
  • Subprocessors or Third-Party Services; and
  • Data Retention and Deletion.

Without the actual text, no reliable legal comparison can be performed.

2026-08-18 · Legal Stuff

shrank 3.0% · Observed by clause.watch

Summary

No substantive contract language or markup was provided for review. The submitted text only states:

> “Text modified while maintaining similar length”

Because the actual additions, deletions, and replacements are missing, it is not possible to identify:

  • Changes to customer rights or obligations
  • New liability, indemnity, confidentiality, or termination risks
  • Changes to data ownership, access, retention, or sharing
  • Whether customer data may be used to train, fine-tune, evaluate, or improve AI models
  • Any opt-out, consent, anonymization, or data-deletion provisions
  • Whether data may be disclosed to affiliates, vendors, or third-party AI providers

AI Training Review

No language addressing AI-model training or related uses of customer data appears in the material provided. This does not establish that the contract contains no such provisions; it only means they cannot be evaluated without the actual diff.

Information Needed

Please provide the complete redlined text using the stated notation:

  • Additions: {new text}
  • Deletions: [deleted text]
  • Replacements: [old text]{new text}

2026-08-18 · Privacy Policy

shrank 3.5% · Observed by clause.watch

Summary

The diff only states that approximately 193 words were removed, but does not identify which words, clauses, or sections were deleted.

AI Training and Data Use
  • There is not enough information to determine whether the deleted language addressed:
  • Use of customer data to train, fine-tune, or improve AI models;
  • Whether customer data may be shared with model providers or subprocessors;
  • Whether data is anonymized, aggregated, or de-identified before use;
  • Customer consent or opt-out rights;
  • Restrictions on using prompts, inputs, outputs, or usage data for training; or
  • Retention and deletion of data used in AI systems.
  • If the removed text previously restricted AI training or required customer consent, its deletion could materially expand the provider’s rights to use customer data.
  • Conversely, if the deleted text authorized training or data sharing, its removal could provide the customer with greater privacy protection or reduce the provider’s permitted uses.
Other Legal Risks

Because the actual deleted language is unavailable, it is not possible to assess changes to:

  • Liability, indemnification, or warranties;
  • Confidentiality and data-security obligations;
  • Intellectual-property ownership or licenses;
  • Data retention and deletion;
  • Regulatory compliance;
  • Termination rights; or
  • Service levels and remedies.
Required Follow-Up

Obtain the full redline or the original and revised versions of the document. The deletion should be reviewed in context, particularly any provisions containing terms such as “train,” “improve,” “develop,” “machine learning,” “artificial intelligence,” “models,” “inputs,” “outputs,” “usage data,” “de-identified,” or “aggregate data.”

Between 2021-05-29 and 2022-04-15 · Legal Stuff

shrank 3.5% · Reconstructed from Internet Archive captures

Structured Summary of Important Changes

1. No identifiable changes to customer contract terms

The diff does not show substantive changes to the HubSpot Customer Terms of Service, Acceptable Use Policy, or Mutual Non-Disclosure Agreement. It primarily contains website markup, styling, JavaScript, analytics metadata, and other page-source content.

Accordingly, the diff does not provide enough text to assess changes involving:

  • Customer or HubSpot rights and obligations
  • Fees, renewals, termination, or suspension
  • Warranties, indemnities, or liability limits
  • Confidentiality or data-processing obligations
  • Governing law or dispute resolution
  • Ownership or licensing of customer content

2. AI-model training and customer data

No provision expressly addresses whether HubSpot may use customer data, customer content, personal data, or usage data to:

  • Train, fine-tune, or improve artificial-intelligence models
  • Develop machine-learning products or services
  • Share data with third-party AI providers
  • Create aggregated or de-identified training datasets
  • Opt customers in or out of AI training

Therefore, no change concerning AI-model training can be reliably identified from this diff. The relevant contractual language may be absent from the supplied excerpt or obscured by the formatting.

3. Website scripts and cookie-related changes

The diff includes apparent additions or changes to a JavaScript routine that:

  • Detects a hideNav=true URL parameter
  • Hides the global navigation
  • Adds that parameter to links on the page
  • Uses a MutationObserver to modify links in a cookie-policy banner
  • Logs certain invalid URLs to the browser console

These appear to be website-functionality changes rather than contractual terms. They may affect how users navigate legal pages, including cookie-policy links, but the diff does not establish any change to consent requirements or data-use permissions.

4. Analytics and tracking metadata

The page source includes HubSpot analytics variables and calls that record items such as:

  • Page ID and content type
  • Language
  • Portal ID
  • Whether the visitor is a HubSpot user
  • Canonical URL and page metadata

This may involve ordinary website analytics, but the excerpt does not state what data is collected, how long it is retained, or whether it is used for AI training. Those issues would need to be assessed under the applicable Privacy Policy, Cookie Policy, or data-processing terms.

5. Data-quality limitation

The diff contains extensive malformed or repeated tokens such as word, which makes it difficult to determine whether any contractual text was omitted or incorrectly rendered. A clean text diff of the actual legal terms is necessary for a definitive legal analysis.

Between 2019-09-20 and 2021-05-29 · Legal Stuff

shrank 20.0% · Reconstructed from Internet Archive captures

Structured Summary

1. Overall assessment

The diff does not appear to show substantive changes to HubSpot’s Customer Terms of Service or other legal provisions. The visible legal headings remain unchanged, including:

  • Acceptable Use Policy
  • Mutual Non-Disclosure Agreement
  • HubSpot Customer Terms of Service
  • Privacy Policy and related legal-center links

The diff is dominated by website markup, JavaScript, analytics variables, navigation logic, and corrupted or placeholder text.

2. Customer data and AI-model training

No provision in the supplied diff expressly addresses:

  • Whether customer data may be used to train AI models;
  • Whether HubSpot may use customer content, prompts, outputs, or usage data for model training;
  • Opt-out or opt-in rights concerning AI training;
  • De-identification, aggregation, or retention of data used for training;
  • Ownership or licensing of data used to develop or improve AI systems; or
  • Restrictions on using confidential or personal information for AI purposes.

Accordingly, the diff does not identify any new or changed authorization to use customer data for AI-model training. However, because the actual substantive terms are not included in readable form, this diff is insufficient to confirm that no such provision exists elsewhere in the full agreement.

3. Website and technical changes

The apparent additions relate primarily to:

  • Setting page language and analytics metadata;
  • Tracking page views and content identifiers;
  • Hiding global navigation when a hideNav=true parameter is used;
  • Propagating that parameter across links;
  • Monitoring page changes using a MutationObserver; and
  • Cookie-banner and policy-link behavior.

These changes may affect website functionality and potentially the handling of analytics or cookie-related information, but they do not, by themselves, amend contractual rights concerning customer data.

4. Data-protection considerations

The presence of analytics variables and cookie-related scripts may indicate continued or modified website tracking. Organizations should separately review:

  • The Cookie Policy;
  • Privacy Policy;
  • Consent-management settings;
  • Analytics-provider disclosures; and
  • Any data-processing agreement.

Those documents may contain relevant data-use permissions that are not reflected in the Customer Terms diff.

5. Important limitation

The diff contains extensive malformed text, including repeated word placeholders and encoded fragments. It appears to compare rendered webpage source rather than the operative legal text. A reliable legal-change analysis would require:

1. The prior and current versions of the actual Customer Terms;

2. The complete readable text of any AI or data-use clauses; and

3. The applicable Privacy Policy, Product Terms, and Data Processing Agreement.

Between 2016-11-24 and 2019-09-20 · Legal Stuff

grew 18.1% · Reconstructed from Internet Archive captures

The wording changed. No written summary was produced for this revision.

Between 2017-09-08 and 2018-04-04 · Privacy Policy

shrank 2.1% · Reconstructed from Internet Archive captures

Structured Summary of Important Changes

Overall assessment

The diff does not show substantive changes to privacy, customer-data use, or AI-model training terms. It appears primarily to involve:

  • Removal of website HTML, JavaScript, tracking variables, and styling content;
  • Removal of HubSpot page metadata and navigation code;
  • Addition of an apparently malformed or repeated string;
  • No identifiable changes to the operative Privacy Policy language.

Because the diff is heavily corrupted and largely consists of technical webpage content, it is not possible to confirm whether any underlying legal text was changed elsewhere.

Changes identified

1. Website and technical code removed

Large portions of technical content were deleted, including:

  • Cookie-banner and cookie-management references;
  • HubSpot logo and page-navigation elements;
  • Analytics variables and tracking configuration;
  • Page identifiers, language settings, and HubSpot account metadata;
  • JavaScript controlling hidden navigation and link parameters.

These changes appear to affect the presentation, analytics, or operation of the webpage rather than the contractual privacy terms.

2. Malformed content added

The diff shows an addition consisting of a repeated encoded-looking string:

> mmMwWLliI0fiflO&1...

Its purpose and meaning cannot be determined from the diff. If this content is actually published, it could indicate:

  • A formatting or deployment error;
  • Corrupted page content;
  • An unintended tracking or query-string value; or
  • A security or quality-control issue.

It should be investigated before relying on the revised page.

Customer data and AI-model training

No identifiable AI-training change

The diff contains no clear language addressing:

  • Whether customer data may be used to train, fine-tune, or improve AI models;
  • Whether customer content is used for generalized or product-specific model training;
  • Opt-out or opt-in rights concerning AI training;
  • De-identification, aggregation, or retention of data used for training;
  • Use of customer prompts, outputs, files, or metadata for AI development; or
  • Restrictions on using confidential or personal information in training datasets.

Accordingly, this diff provides no basis to conclude that HubSpot has expanded or restricted its rights to use customer data for AI training.

Key risks and follow-up

  • Diff integrity risk: The supplied comparison appears incomplete or malformed and may omit the actual legal text.
  • Interpretation risk: Technical deletions should not be treated as deletion of legal rights unless the underlying Privacy Policy wording is separately reviewed.
  • Publication risk: The repeated encoded string should be checked for accidental exposure, broken rendering, or unintended tracking behavior.
  • Recommended action: Obtain a clean, text-only comparison of the Privacy Policy, including the sections on customer content, service improvement, machine learning, AI, subprocessors, retention, and opt-out rights.

Between 2016-05-17 and 2017-09-08 · Privacy Policy

grew 9.4% · Reconstructed from Internet Archive captures

The wording changed. No written summary was produced for this revision.

Between 2016-09-12 and 2016-11-24 · Legal Stuff

shrank 4.0% · Reconstructed from Internet Archive captures

The wording changed. No written summary was produced for this revision.

Between 2016-04-19 and 2016-09-12 · Legal Stuff

grew 2.7% · Reconstructed from Internet Archive captures

The wording changed. No written summary was produced for this revision.

Between 2016-01-26 and 2016-05-17 · Privacy Policy

grew 2.5% · Reconstructed from Internet Archive captures

The wording changed. No written summary was produced for this revision.

Watch this company's contracts

We re-read these documents every six hours and email you when the wording changes.

Start monitoring free