Skip to content

Software companies

Customer asks 'do you sell our data?': how to answer accurately

By SourceX Editorial · Reviewed by Noah Loul ·

Short answer

When a customer asks 'do you sell our data?', give the answer that matches your actual practice and your contracts, not a reflexive no. Most B2B software companies can truthfully say they do not sell or license customer data. If you license your own internal records, say so plainly and state what is excluded.

Key takeaways

  • The accurate answer rests on three facts: your contracts, your published policies and your real data flows.
  • 'We never sell data' can still mislead if customer content reaches an AI provider or appears in a licensed package.
  • Licensing the company's own engineering or internal records is different from licensing customer data, and the answer should say which.
  • One approved answer, owned by legal or privacy and used by sales and support, prevents contradictions across renewals and questionnaires.

What is the accurate answer to 'do you sell our data?'#

The accurate answer to 'do you sell our data?' is the one that matches what your company actually does with customer data, in words your contracts and privacy policy already support. For most B2B software companies that answer is no: they process customer data to provide the service and do not sell, rent or license it.

The question is rarely only about selling. Customers usually also mean: do you share our data with anyone for value, do you use it to train AI, and could it end up inside someone else's product. A good answer addresses all three without promising more than the company can keep.

Several privacy laws give 'sell' and 'share' defined meanings that can be broader than everyday use. Before a standard answer goes out, have counsel confirm it is accurate under the laws that may apply to your customers.

Three answer scripts matched to three real practices#

Three answer scripts cover most software companies, and each is accurate only for the practice it describes. Pick the script that matches the facts, adapt the details, and never borrow wording from a script that claims more restraint than your practice supports.

Script A: 'We do not sell, rent or license your data. We process it only to provide the service under our agreement with you, and our current subprocessors are listed in our trust documentation.'

Script B: 'We do not sell your data. We have licensed some of our own internal records, such as engineering history and product documentation, to an AI developer. Your account content is excluded from that license, and we can explain how the exclusion is enforced.'

Script C: 'Where our agreement with you permits it, we license de-identified support records to AI developers. Names, contact details and account identifiers are removed first, and we can point you to the clause that allows this use.'

Three answer scripts matched to three real practices
Your actual practiceStart fromWhat the answer must state
No licensing of any dataScript ANo sale, rental or licensing; use limited to providing the service; where the subprocessor list lives
Company licenses its own internal records; customer content excludedScript BWhich records were licensed, that customer content is excluded, and how exclusion is enforced
De-identified records from customer interactions licensed where contracts or consent allowScript CThe contractual or consent basis, what is removed, and any opt-out the company offers

Facts to verify before anyone answers#

The facts to verify sit in four places: signed contracts, published policies, real data flows and any data agreements the company has signed. A customer success manager answering from memory is the most common source of an inaccurate reply.

Write the results into a one-page fact sheet that legal signs off, listing each data flow and agreement. Draft the approved answer from that sheet, so a later change in practice means updating one line rather than rewriting the answer from scratch.

  • Customer agreements and data processing agreements, including any aggregated or de-identified data clause.
  • The privacy policy and trust page wording on selling, sharing and AI use.
  • Data flows to third parties: analytics tools, AI model providers, enrichment vendors and support platforms.
  • Whether product AI features send customer content to a model provider, and what that provider's terms say about training.
  • Any data licensing, research or partnership agreement the company has signed, and what each covers.
  • Earlier answers in security questionnaires, so the new answer does not contradict them.

Phrases that sound safe but mislead#

Phrases that sound safe mislead when they are broader than the facts. Absolute statements cause most of the trouble, because one AI feature or one vendor integration can make them untrue.

Vague wording carries its own cost. In August 2023, after backlash over earlier changes to its terms, Zoom added a sentence to its Terms of Service saying it would not use audio, video or chat customer content to train its AI models without consent. In May 2024, TechCrunch reported user backlash when Slack's privacy principles were found to allow customer data to train its machine-learning models unless an organization opted out. In both cases the public reaction followed from unclear terms, not from a confirmed data sale.

Phrases that sound safe but mislead
Phrase to avoidWhy it can misleadMore accurate wording
'We never share your data with anyone.'Subprocessors receive data to run the service'We share data only with the subprocessors listed in our documentation, to provide the service.'
'Your data is never used for AI.'AI features may send content to a model provider'Our AI features process your content to answer your requests, and our provider's terms do not allow training on it.' Use only if true.
'We don't sell data, we license it.'Sounds evasive and implies customer data is licensedName the records that were licensed and state that customer content was excluded
'It's all anonymized.'De-identification has limits and methods differ'We remove names, contact details and account identifiers, and review the result before any release.'

Who should own the answer inside the company?#

The answer should be owned by whoever owns privacy, usually the general counsel or a privacy lead, with customer success as its main user. Ownership means maintaining one approved text, updating it when practice changes and approving any deviation.

Put the approved answer where customers look: the trust page, the security questionnaire library, the customer FAQ and the support macro library. Train account managers to use it as written and to escalate contract questions rather than paraphrase.

Review the answer whenever the company adds an AI feature, signs a data agreement, changes subprocessors or updates its privacy policy. A dated version history shows what any customer was told at any point.

Illustrative: answering during a renewal#

Illustrative: a fictional property management software company licensed part of its Jira and GitHub history, along with internal runbooks, to an AI developer the year before. Customer content in its support tickets was excluded from the package.

During a renewal, a large customer's procurement lead asks whether the company sells customer data. The account manager is about to say 'no, never' and instead escalates to the general counsel, who sends Script B with a short list of the excluded record types.

The procurement lead asks one follow-up about subprocessors, receives the published list and closes the question. Because the answer matched the company's real practice, the same text goes into the security questionnaire library for future renewals.

How SourceX treats customer data in a licensing transaction#

SourceX treats customer data as excluded by default unless the rights review confirms the supplier may license it. In the Rights step of the SourceX five-step transaction, customer agreements, data processing agreements and privacy notices are reviewed before any records are prepared.

For each package, the SourceX Evidence Packet sets out permitted use and the privacy record alongside provenance, licensing rights and release authorization. That gives the supplier a documented basis for answering a customer precisely, including which record types were left out.

Frequently asked questions

Should we tell customers proactively that we license internal records?

Often it is worth doing, especially if customers are likely to ask. A short note on your trust page explaining which internal records were licensed and that customer content was excluded prevents surprises. Whether you must notify anyone depends on your contracts and the laws that may apply, which counsel should confirm.

Does licensing de-identified data count as selling it?

It can, depending on the law and the facts. Some privacy laws define selling broadly, and de-identification standards differ between them. Under the California definition as amended by the CPRA, for example, information counts as deidentified only if the business also publicly commits not to reidentify it and contractually binds recipients to the same rules. Treat the question as one for counsel, assessed deal by deal, and do not describe a practice as 'not a sale' in customer-facing text until counsel has confirmed it.

What if our customer contract is silent on licensing?

Silence is not permission. If the customer agreement and privacy policy do not clearly allow licensing of customer data, the accurate answer is that you do not license it, and your practice should match. Company-owned internal records are a separate question that a rights review answers.

Can a customer ask to see our data licensing agreements?

A customer can ask, but licensing agreements are usually confidential. You can still describe what was licensed, which record types were excluded and the controls applied. Some companies offer a written summary under NDA, which answers the real concern without disclosing commercial terms.

How often should we review the standard answer?

Review it whenever practice changes: a new AI feature, a new subprocessor, a signed data agreement or a privacy policy update. Many teams also check it during their periodic security questionnaire refresh. Keep dated versions so you can show what was said at any time.

What should a support agent say when unsure?

The agent should say the question will be confirmed and route it to the owner of the approved answer, rather than guessing. A slightly slower but accurate reply builds more trust than an instant answer that later turns out to be wrong, and it keeps every response consistent with the contracts.

Sources

  • On August 7, 2023, after backlash over March 2023 changes, Zoom added to Section 10.4 of its Terms of Service that it will not use audio, video or chat Customer Content to train its AI models without consent. Source
  • TechCrunch reported on May 17, 2024 that Slack drew user backlash after its privacy principles were found to allow customer data to train its machine-learning models unless an organization opted out. Source
  • Under Cal. Civ. Code 1798.140(m) as amended by the CPRA, deidentified information requires reasonable measures, a public commitment not to reidentify, and contractual obligations on recipients. Source

Related resources

See if your company qualifies

A short company assessment. No data uploads are needed.

See if you qualify