Your HubSpot portal can collect years of contacts, form submissions, emails, deals, and support history before anyone asks what should be deleted. That creates privacy exposure, bloated lists, and reports built on records nobody still needs.
A practical HubSpot data retention policy gives every data category a purpose, owner, review date, and disposal method. Start with the policy decisions, then configure HubSpot to support them.
Key Takeaways
- Set retention periods by data category and business purpose, not one blanket inactivity rule.
- Get written approval from legal, privacy, security, and the business owner before applying deletion rules.
- Use HubSpot properties, active lists, workflows, and the built-in contact retention setting for controlled cleanup.
- Define exclusions for legal holds, active contracts, disputes, and regulated records before deleting anything.
- Test on a small segment, then monitor integrations, exports, backups, reports, and workflow dependencies.
Start With a Retention Schedule, Not an Auto-Delete Rule
A retention policy answers four simple questions: What data do you have, why do you keep it, how long do you need it, and how will you dispose of it?
That sounds basic, yet many small teams start with a 365-day inactivity rule and only later discover that an old contact is tied to an active customer, an open invoice, or a legal request. A deletion setting can’t make those business decisions for you.

Build a schedule that ties each data class to a clear trigger. The trigger matters more than a calendar date. For example, a prospect’s clock might begin after their last meaningful interaction. A customer’s clock may begin when the contract ends.
Retention periods are not universal legal advice. Legal, privacy, security, and the relevant business owner should approve each period for the jurisdictions and contracts that apply to your company. The Salesforce guide to data retention policies also stresses the need to define data categories, access, and end-of-life handling.
Use this starter schedule as a working template.
| Data category | Business purpose | Retention trigger | Starter period | Disposal method | Accountable owner |
|---|---|---|---|---|---|
| Marketing leads | Lead nurturing and attribution | Last meaningful engagement | 12 to 24 months | Delete or anonymize where appropriate | Marketing lead |
| Sales prospects | Sales follow-up and pipeline history | Closed-lost date or last sales activity | 12 to 24 months | Delete after review | Sales lead |
| Customer contacts | Account management and support | Contract end date | Contract term plus approved period | Delete, with hold exclusions | Customer success lead |
| Deal records | Revenue reporting and audit support | Deal close date | Approved finance period | Archive or delete | Revenue operations |
| Consent records | Proof of consent and preferences | Consent withdrawal or record closure | Approved legal period | Restrict or delete | Privacy owner |
| Test and duplicate records | No valid business purpose | Creation or identification date | Immediate to 30 days | Delete | HubSpot admin |
The table is a decision record, not a technical configuration. Keep it in a shared document with approval dates, policy versions, and links to related contracts or privacy records.
Map Where HubSpot Data Travels Before You Set Rules
HubSpot is rarely the only place where a contact record exists. A form submission can flow to Slack, Zapier, a spreadsheet, a billing tool, a support platform, or a warehouse. A retention policy that covers only the CRM leaves copies behind.
First, inventory each category in HubSpot. Include standard objects such as contacts, companies, deals, tickets, and marketing email activity. Then list custom properties, file attachments, form fields, imports, and any custom objects your team uses.
For each category, record:
- Where the data enters HubSpot, such as forms, imports, APIs, or manual entry.
- Which teams can view or change it.
- Which integrations receive it or write data back.
- Whether users routinely export it to CSV files or shared drives.
- Which event starts the retention clock.
Good data mapping also exposes unnecessary collection. If a form asks for a personal phone number but nobody uses it, remove the field. The small-business data mapping guidance offers a useful reminder: identify applicable rules first, then map the data you hold.
Next, define exclusions before any cleanup begins. Common exclusions include active contracts, unpaid invoices, open support cases, legal holds, security investigations, and records needed to meet tax or sector requirements. Add an internal property such as “Retention hold” with controlled values. Limit who can set or remove that value.
Never use inactivity alone as proof that a record has no business or legal value.
This is also the point to settle the difference between deletion and anonymization. Deletion removes the personal data according to the system’s behavior and your documented process. Anonymization changes or removes identifying fields so the remaining data cannot reasonably identify a person. Clearing an email address while retaining a unique identifier, detailed activity history, and linked records may not meet that standard.
Backups need their own line in the policy. They support recovery and should have a defined rotation period and restricted access. Don’t treat backups as a hidden production archive that keeps personal data forever.
Configure HubSpot for Controlled Retention
HubSpot’s built-in retention setting focuses on inactive contacts. According to HubSpot’s current retention settings documentation, go to Settings > Account Management > Privacy & Consent > Setup > Privacy tools. There, you can enable automatic deletion for inactive contacts.
HubSpot’s default inactivity window is 365 days. You can edit the number of days with no activity. The setting also lets you apply the ruleset to eligible existing contacts and future contacts, or only contacts that become eligible after activation.
Don’t turn it on across your whole database first. Existing contacts may include former customers, strategic partners, or records with incomplete lifecycle data. Start with future contacts or a low-risk group while your team validates the schedule.
For anything more nuanced than inactive contacts, build a review workflow around your own fields. Create properties such as:
- Retention review date
- Retention decision
- Retention hold
- Contract end date
- Last meaningful engagement date
- Disposal completed date
Use lifecycle stage, deal status, ticket status, and those properties to create active lists. For example, an active list might identify former customers whose contract ended 18 months ago, have no open tickets, and aren’t marked for retention hold.
A workflow can set the review date after a lifecycle change, notify the assigned owner 30 days before review, and create a task for approval. After approval, add the record to a final deletion list. This controlled approach is safer than treating every dormant record the same.
HubSpot workflows can also remove contacts from marketing communications before a disposal decision. That helps prevent accidental campaigns while a record awaits review. For broader consent and privacy controls, review HubSpot’s CRM compliance guidance.
Keep a deletion log outside the record itself when required. Capture the date, rule applied, approver, record count, and any exception. If a customer or regulator asks how you handled a category of data, that record is more useful than a vague claim that “cleanup happens automatically.”
Run a Pre-Launch Check Before Deleting Records
Your first retention run should feel like a controlled release, not a bulk purge. Export only what you have a documented reason to preserve, then store it securely with access limits and an expiration date.
Use this pre-launch checklist:
- Confirm that legal, privacy, security, and the relevant business owner approved each retention period and exclusion.
- Review active contracts, open deals, unpaid invoices, support tickets, legal holds, and security investigations.
- Check integrations such as Zapier, billing tools, support software, analytics platforms, and data warehouses.
- Identify recurring CSV exports, shared-drive files, and email attachments that may contain the same data.
- Verify that retention holds override automated workflow actions.
- Test the rules on internal contacts, obvious spam, duplicates, or a small low-risk segment.
- Review affected lists, reports, personalization tokens, dashboards, and workflow enrollment before scaling.
- Document backup retention, restore access, and what happens if deleted data is restored during recovery.
After the test, review the outcome with the people who use the data. Sales may discover a report depends on historical deals. Marketing may find an audience workflow assumes a property exists. Security may identify an integration token with wider permissions than expected.
Monitor the policy at least quarterly. Track record volumes by object, deletion counts, duplicate rates, bounced email trends, workflow errors, and integration failures. Update the schedule when you add a new product, enter a new market, change billing systems, or collect a new type of personal data.
Make Retention Part of Everyday HubSpot Hygiene
A retention policy works when it becomes part of normal operating habits. Owners need clear responsibilities, and new properties or integrations need a retention review before they go live.
Start small. Inventory one data category this week, then assign its owner, business purpose, retention trigger, and disposal method. That single entry gives you a usable foundation for a HubSpot data retention policy that can grow with your business.