- Does HubSpot tracking require GDPR consent?
- Yes. The HubSpot tracking code is not essential to website operation and requires a valid legal basis under the GDPR. Most organizations use consent, which means the tracking code must not fire before the visitor provides explicit opt-in through a compliant consent management platform. Technical validation is needed to confirm that the tracking code is actually blocked before consent, not just listed as consent-gated in the policy.
- What personal data does HubSpot store?
- HubSpot stores two types of personal data. The CRM stores contact records containing names, email addresses, phone numbers, company information, and interaction history for leads and customers. The tracking system stores behavioral data associated with visitor identifiers, which are linked to a contact record when the visitor submits a form. Both categories of data are subject to GDPR, CCPA, and other applicable privacy laws and should be covered in your privacy policy.
- Does my privacy policy need to cover HubSpot email tracking?
- Yes. HubSpot email tracking pixels load when the recipient opens the email and may set cookies when the recipient clicks links back to your website. This tracking should be disclosed in your email privacy notice or within the email itself. For EU and UK contacts, email tracking may require separate consent from the consent collected for website cookies and marketing emails.