whats-best.ai
Search Sign in

CRM

HubSpot Sales Hub

Rest of world Report an error

Panel rating · 6 judges · How to read the stars

Category median

Sovereignty: not determined

0–5 in half steps. 5 means the rubric's top anchor is met on the evidence.

by HubSpot, Inc. · www.hubspot.com

Compare with Pipedrive → Compare with Zoho CRM → Compare with Microsoft Dynamics 365 Sales → Report an error on this page Is this your product? →

Read this page as one judge. Each weighs the same scores by what they care about.

The Data Protection Officer

Weighted verdict

Knows a CRM is a database of other people's personal data before it is a sales tool. Optimizes for GDPR posture: EU hosting, DPA, subprocessor hygiene, consent fields, retention and deletion that actually delete. Rejects US-default hosting and enrichment features that scrape contacts from the open web.

Same scores as the panel view — this lens weights them the way this judge cares.

Scored by The Data Protection Officer

Contact & data model

How this is scored

Depth and hygiene of the core records — contacts, companies, deals, custom fields, deduplication.

0 — A flat address book; no relations between people, companies and deals.

3 — The standard three objects exist but customization is cosmetic: few field types, no required fields, duplicates accumulate unchecked.

5 — Custom fields across objects, basic dedupe on create, activity history on the record; complex models still need workarounds.

8 — Rich field types with validation, merge and dedupe tooling, relationships beyond the standard model, permissioned field access.

10 — A genuinely modelable system: custom objects or equivalent, bulk hygiene tooling, field-level history — the data model bends to the business, not the reverse.

Report an error

The Data Protection Officer

Deals-as-pipelines up to 100 and 'smart properties' runs tell me a real relational model with custom properties exists, but the evidence is silent on deduplication, merge, field validation and permissioned field access — for a database of other people's personal data, unevidenced hygiene is unevidenced hygiene. Slightly above the cosmetic-customization floor only because the pipeline model is clearly substantial. 2

Report an error

Pipeline & forecasting

How this is scored

Whether the pipeline enforces a process and produces reporting a finance department accepts.

0 — A kanban of deals with amounts; nothing is enforced, nothing rolls up.

3 — Multiple pipelines and stage probabilities exist, but no required fields per stage and only canned reports.

5 — Stage requirements, win/loss capture and standard forecast views; custom reporting is limited or an add-on.

8 — Enforceable process (required fields, stage gates, routing), custom report builder, forecast by team and period with quota tracking.

10 — Forecasting a CFO signs: weighted and commit-based views, historical snapshots, attainment tracking, and reporting composable enough to answer questions the vendor never anticipated.

Report an error

The Data Protection Officer

Default and custom forecasting with team-hierarchy rollups and up to 100 dashboards at 50 reports each sits above canned reporting, but nothing in the evidence evidences required fields per stage, stage gates, quota attainment or forecast snapshots. The enforcement layer a finance department would sign off on is invisible, so I stop just past the mid anchor. 2

Report an error

Automation & workflows

How this is scored

Triggers, sequences and routing that remove manual work without a consultant.

0 — No automation beyond email templates.

3 — Simple if-this-then-that on records; no multi-step sequences, no branching.

5 — Multi-step workflows with delays and branching, email sequences, basic lead routing — capped by tier or count.

8 — Full workflow builder across objects with webhooks as steps, round-robin routing, sequence analytics.

10 — Automation as infrastructure: versioned workflows, error handling, per-step logs, and limits generous enough that the feature is not its own upsell.

Report an error

The Data Protection Officer

The only automation evidenced is credit-metered AI agents — 50 credits per resolved conversation, 100 per recommended outreach, 10 per smart-properties run — plus tracked-term conversation intelligence, with no workflow builder, branching, sequences or routing anywhere in the evidence. Automation sold by the drop, with the meter itself unpriced, is precisely the feature-as-upsell pattern the top anchor warns against, and the prospecting agent smells of automated outreach to scraped leads. 2

Report an error

Integrations & API

How this is scored

Two-way email/calendar sync, native connections, and an API that treats external systems as first-class.

0 — No API, no sync; data enters by CSV and leaves never.

3 — One-way email logging (BCC), a handful of Zapier triggers, a read-mostly API.

5 — Two-way email and calendar sync for the major providers, a documented REST API with sane limits, a modest native directory.

8 — Deep native integrations for the revenue stack, webhooks, OAuth apps, API parity with the UI for core objects.

10 — An ecosystem: public API covering everything the UI does, event streams, a marketplace, and sync so reliable the CRM can be the system of record without being the only system.

Report an error

The Data Protection Officer

A marketplace of 2,000+ apps and web services is a genuine ecosystem signal, but the evidence evidences no two-way email or calendar sync, no API documentation, no webhooks and no sync guarantees. I can credit a large directory; I cannot credit depth or API first-classness the evidence does not show. 2

Report an error

European sovereignty

How this is scored

Where other people's personal data actually lives and under whose law — entity, hosting, subprocessors, DPA.

0 — US entity, US-default hosting, no public DPA or subprocessor list.

3 — A DPA exists and an EU region is available on request or on top tiers; subprocessor exposure to US CLOUD Act reach is broad and undocumented.

5 — EU hosting selectable at signup, published DPA and subprocessor list; core processing still touches US entities.

8 — EU entity or EU-default hosting with published subprocessors, consent-friendly fields, retention and deletion controls; residual US exposure named and narrow.

10 — European entity, EU-only processing including subprocessors, deletion that provably deletes — sovereignty a DPO can sign off without a caveat file.

Report an error

The Data Protection Officer

A US entity (Cambridge MA, NYSE-listed) with data residency, ownership and subprocessor exposure all marked unknown, no DPA and no subprocessor list in evidence — the deletion-on-request clause and the hedge-and-isolate retention wording in the privacy policy are the entirety of the GDPR posture, and a Berlin sales phone line is not an EU data center. Add 750–1,500 hours of call transcription per month processing third parties' personal data with zero evidenced European controls: nothing here a DPO could sign. 3 2

Report an error

Import, export & exit

How this is scored

Getting in with history intact, and out with everything — the anti-lock-in criterion.

0 — Import is a support ticket; export is contacts-only CSV missing notes, activities and files.

3 — Self-serve CSV import with mapping; export covers main objects but drops activity history, attachments or relations.

5 — Guided migration from major competitors, full-object CSV export, API access sufficient to rebuild the database elsewhere with effort.

8 — Complete export (all objects, history, files) self-serve in open formats, import with dedupe and dry-run, no API metering that prices exit out of reach.

10 — Exit as a feature: documented full-fidelity export, migration tooling both directions, and contractual data-return terms — leaving is a weekend, which is exactly why you can stay.

Report an error

The Data Protection Officer

The evidence is entirely silent on import, export, migration and API data-return — no CSV, no full-fidelity export, nothing an exit plan could rest on; the only lifecycle control evidenced anywhere is deletion on request. By the anchors, silence on exit scores as lock-in, and lock-in on a database of other people's data is a compliance problem, not just a commercial one. 3

Report an error

Pricing transparency

How this is scored

Whether a buyer can compute the real invoice — per seat, per month, at renewal — from public pages alone.

0 — No public prices at all; every tier is a sales conversation.

3 — An entry price exists, but the tiers most buyers need are unpriced, or per-seat maths is obscured by bundles, minimums or mandatory onboarding fees.

5 — Most tiers carry real numbers with billing period and VAT treatment stated, but at least one commonly needed capability hides in an unpriced tier or usage-metered add-on.

8 — Every tier priced publicly including annual/monthly split; limits, seat minimums and overage rules stated; only genuine enterprise contracts are custom.

10 — Complete price computability: every tier, add-on, usage meter and renewal rule public, with a calculator or table that makes the invoice at 3 and 30 seats a two-minute exercise.

Report an error

The Data Protection Officer

The pricing page does publish hard per-tier limits — 500 to 12,000 calling minutes, 1 to 100 pipelines, transcription hours — plus the per-seat model and free view-only seats, which is honest limit disclosure. But no currency figure for any tier appears in the evidence, and AI capabilities are metered in credits whose price is never stated, so the real invoice cannot be computed from this evidence. 2

Report an error

European sovereignty — proven facts

0 of 4 dimensions proven

Built only from facts shown on the vendor's own pages. A dimension we could not prove is left open, not scored as zero.

Ownership Not determined ⚠ unverified — uncited Report an error
Data residency Not determined — uncited Report an error
Subprocessors Not determined ⚠ unverified — uncited Report an error

Where this could be wrong

What we left out

A claim that does not survive our checks costs us the claim, not the page. This is what was taken off this one.

Sources (13)

The pages every claim on this page was read from — each one checked, dated, and kept verifiable.

  1. 1 Vendor product page www.hubspot.com Checked 15 Sep 2026 Details →
  2. 2 Vendor pricing page www.hubspot.com Checked 15 Sep 2026 +1 earlier capture: 11 Sep 2026 Details →
  3. 3 Privacy policy legal.hubspot.com Checked 15 Sep 2026 Details →
  4. 4 Security / trust page legal.hubspot.com Checked 30 Sep 2026 Details →
  5. 5 Contact & data model — found from sitemap knowledge.hubspot.com Checked 1 Oct 2026 Details →
  6. 6 Contact & data model — found from sitemap knowledge.hubspot.com Checked 1 Oct 2026 Details →
  7. 7 Pipeline & forecasting — found from sitemap www.hubspot.com Checked 1 Oct 2026 Details →
  8. 8 Pipeline & forecasting — found from sitemap www.hubspot.com Checked 1 Oct 2026 Details →
  9. 9 Automation & workflows — found from sitemap knowledge.hubspot.com Checked 1 Oct 2026 Details →
  10. 10 Automation & workflows — found from sitemap knowledge.hubspot.com Checked 1 Oct 2026 Details →
  11. 11 Integrations & API — found from sitemap knowledge.hubspot.com Checked 1 Oct 2026 Details →
  12. 12 Import, export & exit — found from sitemap knowledge.hubspot.com Checked 1 Oct 2026 Details →
  13. 13 Import, export & exit — found from sitemap knowledge.hubspot.com Checked 1 Oct 2026 Details →