Zoom now says it may sell business contact data

Stani Mihov
Founder & CEO
·

TL;DR
What happened: On September 17, 2026, Zoom limited its statement "We do not sell your personal data" to data governed by its main Privacy Statement and added that sales of business contact data may occur through Zoom Common Room. Common Room is the sales intelligence company Zoom agreed to acquire in July, and its new privacy statement says Zoom may sell contact details it obtains from data brokers and other third-party providers to customers who use its enrichment features.
Why it matters: The change does not touch meeting content, but business contact details such as a name, work email, phone number, and job title can now be part of a data product Zoom sells to sales teams. Zoom says it is registered as a data broker under certain laws, and anyone can ask it not to sell their data through its privacy request form.
The change
On September 17, 2026, Zoom updated its Privacy Statement. In the section on U.S. state privacy rights, the old text said: "We do not sell your personal data in the conventional sense." The new text reads: "We do not sell your personal data governed by this Privacy Statement in the conventional sense." It is followed by a new sentence: "Sales of business contact related data may occur through our Zoom Common Room offering."
The update note at the bottom of the statement lists this as the only change in the new version. Venpo flagged it the next day, and the redline is on the public change page.
What changed
The edit is short, but it changes what Zoom's best-known privacy line covers:
The promise got a boundary. "We do not sell your personal data" now applies only to data governed by the main Privacy Statement, not to everything Zoom handles.
A sale is now named. The statement says sales of business contact data may happen through Zoom Common Room and points to a separate privacy statement for the details.
The details live in another document. The Zoom Common Room Privacy Statement took effect on September 16, 2026, one day before the main statement changed.
What Zoom Common Room is
On July 2, 2026, Zoom announced an agreement to acquire Common Room, a Seattle company that builds sales intelligence. Common Room combines a company's own data, such as CRM records and product usage, with outside buying signals to build a profile of each potential buyer, and its AI agents research accounts and draft outreach for sales teams. Zoom named Atlassian, Anthropic, Autodesk, Notion, Okta, and Snowflake as companies whose sales teams use it.
Profiles like these need contact details for the people being profiled. That is where the new privacy statement comes in.
What the Common Room statement allows
The Zoom Common Room Privacy Statement describes a data business that sits alongside the video product:
What it collects. Business contact information, defined as name, business email address, business phone number, job information, locale, and industry.
Where it comes from. Zoom says it obtains business contact details from "data enrichment services, data licensors, data aggregators, and data brokers."
Who it goes to. Zoom "may sell or share personal information we obtain from third party providers" to customers who use the data enrichment part of the service, to help them "identify and reach potential leads."
How Zoom classifies itself. The statement says that under certain laws, Zoom is registered as a data broker for its data enrichment offerings.
How to opt out. People can ask Zoom not to sell their data through the privacy request form linked in the statement.
What did not change
The update does not touch meeting content. The main Privacy Statement still says Zoom does not use audio, video, chat, or other communications content to train its own or third-party AI models, and that it does not use customer content for marketing. The Common Room statement describes selling information obtained from third-party providers, and it says Zoom sells personal data for money only through the Common Room data enrichment offering. Anyone reading this as "Zoom sells your meetings" would be reading it wrong.
Why this matters
"We do not sell your personal data" is one of the lines vendor reviews copy into a spreadsheet and never check again. Zoom's version now stops at the edge of one document, while a second document on the same website describes a product that buys business contact data from brokers and sells it to sales teams. Neither change shows up inside the Zoom app.
This is a pattern worth watching as vendors acquire data and AI companies. A privacy promise written for one product does not automatically stretch to cover the next one, and the new product often arrives with its own statement, as we saw when Meta rewrote its privacy policy around agentic AI. Business contact data in particular has become valuable enough that platforms are drawing firm lines around it, the same tension behind LinkedIn's split between Recruiter and Sales Navigator. Changes like these are easy to miss because they live in the text, which is the hidden risk of vendor legal changes.
Potential impact
For a SaaS company that uses Zoom, the update raises four practical questions:
Does your vendor record for Zoom say it does not sell personal data, and does that note now need the Common Room exception?
Is your sales team evaluating Zoom Common Room, and does it know that part of the enrichment data comes from data brokers and aggregators?
Do your employees, whose work contact details may appear in enrichment datasets, know that Zoom offers an opt-out from the sale of their data?
Which other products from your vendors are covered by a separate privacy statement that nobody on your team has read?
Answering the last question across every vendor is what monitoring vendor terms of service is for.
How Venpo detected it
Venpo monitors Zoom's privacy pages as part of continuous vendor risk monitoring. On September 18, it flagged the new version of the Privacy Statement, separated the one substantive edit from the date and changelog updates around it, and marked it as a narrowing of Zoom's no-sale statement. The full redline is on the Zoom change page, and every monitored Zoom document is listed on the Zoom vendor profile.
Business outcome
Teams that track Zoom got a plain-English note the day after the change, with the old and new sentences side by side and a pointer to the Common Room statement behind them. That leaves time to update the vendor record, brief the sales team before anyone signs up for enrichment data, and tell employees how to opt out. The alternative is repeating "Zoom does not sell personal data" in a security questionnaire after the sentence has changed.
Key takeaway
Zoom did not start selling meeting data, but its promise not to sell personal data now covers one privacy statement instead of the whole company, and a second statement describes a business that sells contact details sourced from data brokers. The only way to notice that difference is to read the text each time it changes, including the documents a single new sentence points to.
The change
On September 17, 2026, Zoom updated its Privacy Statement. In the section on U.S. state privacy rights, the old text said: "We do not sell your personal data in the conventional sense." The new text reads: "We do not sell your personal data governed by this Privacy Statement in the conventional sense." It is followed by a new sentence: "Sales of business contact related data may occur through our Zoom Common Room offering."
The update note at the bottom of the statement lists this as the only change in the new version. Venpo flagged it the next day, and the redline is on the public change page.
What changed
The edit is short, but it changes what Zoom's best-known privacy line covers:
The promise got a boundary. "We do not sell your personal data" now applies only to data governed by the main Privacy Statement, not to everything Zoom handles.
A sale is now named. The statement says sales of business contact data may happen through Zoom Common Room and points to a separate privacy statement for the details.
The details live in another document. The Zoom Common Room Privacy Statement took effect on September 16, 2026, one day before the main statement changed.
What Zoom Common Room is
On July 2, 2026, Zoom announced an agreement to acquire Common Room, a Seattle company that builds sales intelligence. Common Room combines a company's own data, such as CRM records and product usage, with outside buying signals to build a profile of each potential buyer, and its AI agents research accounts and draft outreach for sales teams. Zoom named Atlassian, Anthropic, Autodesk, Notion, Okta, and Snowflake as companies whose sales teams use it.
Profiles like these need contact details for the people being profiled. That is where the new privacy statement comes in.
What the Common Room statement allows
The Zoom Common Room Privacy Statement describes a data business that sits alongside the video product:
What it collects. Business contact information, defined as name, business email address, business phone number, job information, locale, and industry.
Where it comes from. Zoom says it obtains business contact details from "data enrichment services, data licensors, data aggregators, and data brokers."
Who it goes to. Zoom "may sell or share personal information we obtain from third party providers" to customers who use the data enrichment part of the service, to help them "identify and reach potential leads."
How Zoom classifies itself. The statement says that under certain laws, Zoom is registered as a data broker for its data enrichment offerings.
How to opt out. People can ask Zoom not to sell their data through the privacy request form linked in the statement.
What did not change
The update does not touch meeting content. The main Privacy Statement still says Zoom does not use audio, video, chat, or other communications content to train its own or third-party AI models, and that it does not use customer content for marketing. The Common Room statement describes selling information obtained from third-party providers, and it says Zoom sells personal data for money only through the Common Room data enrichment offering. Anyone reading this as "Zoom sells your meetings" would be reading it wrong.
Why this matters
"We do not sell your personal data" is one of the lines vendor reviews copy into a spreadsheet and never check again. Zoom's version now stops at the edge of one document, while a second document on the same website describes a product that buys business contact data from brokers and sells it to sales teams. Neither change shows up inside the Zoom app.
This is a pattern worth watching as vendors acquire data and AI companies. A privacy promise written for one product does not automatically stretch to cover the next one, and the new product often arrives with its own statement, as we saw when Meta rewrote its privacy policy around agentic AI. Business contact data in particular has become valuable enough that platforms are drawing firm lines around it, the same tension behind LinkedIn's split between Recruiter and Sales Navigator. Changes like these are easy to miss because they live in the text, which is the hidden risk of vendor legal changes.
Potential impact
For a SaaS company that uses Zoom, the update raises four practical questions:
Does your vendor record for Zoom say it does not sell personal data, and does that note now need the Common Room exception?
Is your sales team evaluating Zoom Common Room, and does it know that part of the enrichment data comes from data brokers and aggregators?
Do your employees, whose work contact details may appear in enrichment datasets, know that Zoom offers an opt-out from the sale of their data?
Which other products from your vendors are covered by a separate privacy statement that nobody on your team has read?
Answering the last question across every vendor is what monitoring vendor terms of service is for.
How Venpo detected it
Venpo monitors Zoom's privacy pages as part of continuous vendor risk monitoring. On September 18, it flagged the new version of the Privacy Statement, separated the one substantive edit from the date and changelog updates around it, and marked it as a narrowing of Zoom's no-sale statement. The full redline is on the Zoom change page, and every monitored Zoom document is listed on the Zoom vendor profile.
Business outcome
Teams that track Zoom got a plain-English note the day after the change, with the old and new sentences side by side and a pointer to the Common Room statement behind them. That leaves time to update the vendor record, brief the sales team before anyone signs up for enrichment data, and tell employees how to opt out. The alternative is repeating "Zoom does not sell personal data" in a security questionnaire after the sentence has changed.
Key takeaway
Zoom did not start selling meeting data, but its promise not to sell personal data now covers one privacy statement instead of the whole company, and a second statement describes a business that sells contact details sourced from data brokers. The only way to notice that difference is to read the text each time it changes, including the documents a single new sentence points to.
Real-time change notifications
Stay ahead of every legal change
Get updates, product news and expert tips on navigating legal changes
Dispute resolution clause now requires mandatory arbitration in all regions
Data retention period extended from 2 years to 5 years for all services
New restrictions on AI-generated content in product descriptions
Third-party data sharing expanded to include analytics partners
Real-time change notifications
Stay ahead of every legal change
Get updates, product news and expert tips on navigating legal changes
Dispute resolution clause now requires mandatory arbitration in all regions
Data retention period extended from 2 years to 5 years for all services
New restrictions on AI-generated content in product descriptions
Third-party data sharing expanded to include analytics partners
