There is a file waiting for you in this guide: 14 companies checked live for HubSpot, exported with Derrick on 6 September 2026, free. 11 of them run it, and the file says which components. The 3 that do not are in there too, because absence is not proof.
Who uses HubSpot: the short answer
Nearly three hundred thousand companies use HubSpot, and asking who uses HubSpot is only useful once you narrow it to the ones you can sell to. HubSpot reported 299,458 paying customers as of 31 March 2026. No public list contains all of them, and no vendor file is anywhere close, because HubSpot does not publish its customer roster and the only reliable evidence is the fingerprint each customer leaves on its own website.
That fingerprint is detectable, and it is more precise than most people expect. HubSpot is not one product, so "uses HubSpot" is not one fact. A company can run its entire website on the CMS, or keep a Next.js site and only load the analytics and chat widgets, or use the CRM with no public trace at all. Those are three very different prospects, and a list that flattens them into a single boolean is why so much stack based targeting misses.
This guide covers where the published lists come from and why they decay, how to detect the stack yourself from a website, what the signal does and does not prove, and what building your own segment costs per company. If your goal is enriching records you already hold rather than finding new ones, our guide on HubSpot data enrichment workflows covers that side, and the five layer CRM data strategy covers where a stack signal sits in the wider picture.

How many companies use HubSpot, and why the number matters
299,458 paying customers is the number HubSpot itself reported for the quarter ending 31 March 2026, up roughly sixteen percent year on year. Hold that figure next to the customer counts advertised by list vendors and the arithmetic stops working. A file claiming a couple of hundred thousand HubSpot using companies is either claiming near total coverage of a private roster, which nobody has, or it is counting something looser, such as any domain that has ever loaded a HubSpot asset, including agencies testing on client sites and companies that churned two years ago.
The number matters for a second reason. Three hundred thousand is a large market and a useless segment. HubSpot's customer base runs from a two person consultancy on a starter seat to a listed enterprise on the full suite. Nothing you sell is relevant to both. The tech signal is the first filter, never the whole qualification, and the sections below are about turning it into something narrower.

Where "who uses HubSpot" lists actually come from
Search the question and the results split into three families, and it is worth knowing which one you are looking at.
The first is HubSpot's own case study directory. It is accurate and it is tiny, because it contains only customers who agreed to be a reference. Useful for proof, useless as a prospecting list.
The second is vendor files sold per record, advertising counts in the hundreds of thousands. These are built by crawling the web for HubSpot assets at some point in the past, then joining the domains to a contact database. The crawl date is the number that decides whether the file is any good, and it is the one number never shown.
The third is technographic platforms that expose the same crawl as a searchable index. Honest about the method, priced as a subscription, and still a snapshot taken on somebody else's schedule.
All three answer a slightly different question than the one you asked. You do not want every company that has ever touched HubSpot. You want the ones that use it now, in your segment, at a size where your offer applies, with a named person you can reach. That list does not exist to be bought, which is the good news: it is the reason building it is a real advantage rather than a chore.

Detect the stack yourself: what a website actually reveals
A HubSpot deployment leaves traces in the page that a detector can read without any privileged access. The useful part is that the traces are granular enough to tell you which parts of HubSpot are in use.
Two real measurements taken on 6 September 2026 make the point better than a description. The first site returns HubSpot CMS Hub as its content management system, alongside HubSpot Analytics, HubSpot Chat and the core HubSpot library. The whole web presence lives inside HubSpot. The second site returns Next.js on Vercel with React underneath, and HubSpot Analytics, HubSpot Chat and the core library on top. This company keeps its own front end and uses HubSpot for the marketing and conversation layer.
| What the detector returns | What it means | What to sell them |
|---|---|---|
| HubSpot CMS Hub as the CMS | Website, blog and landing pages all inside HubSpot | Anything touching content operations, migration, or page performance |
| HubSpot Analytics with a different CMS | Marketing and CRM inside HubSpot, front end owned elsewhere | Data flow between the site and the CRM, attribution, enrichment |
| HubSpot Chat present | Conversations routed through HubSpot | Routing, qualification, inbox and handover workflows |
| HubSpot forms only | Lead capture in HubSpot, often a partial deployment | Field quality, deduplication, lead scoring |
| No public HubSpot trace | Either not a customer, or Sales Hub only with no public surface | Nothing yet, this row needs another signal |
Read that last row carefully, because it is the honest limit of the method and the next section is about it.

What the tech signal does and does not tell you
Front end detection sees what a browser sees. That produces two blind spots you should plan around rather than pretend away.
The first is the silent customer. A company running Sales Hub for its reps, with no HubSpot tracking on a marketing site built by an agency, is a paying customer with no public fingerprint. You will never find them this way, and no vendor file finds them either, because vendor files are built from the same crawl.
The second is the false positive. Marketing agencies and HubSpot partners load HubSpot assets on sites they build for clients, and a landing page spun up for one campaign can leave a trace long after the account lapsed. A domain that shows a single HubSpot asset and nothing else deserves a second signal before it enters a campaign.
The practical rule is that a stack detection is a strong qualifier and a weak disqualifier. Present means present. Absent means unknown. Treat the absent rows as a separate segment to enrich by another route rather than as rejections, and you keep the half of the market everyone else throws away.
From "who uses HubSpot" to a segment worth selling to
A domain with a confirmed stack is not yet a prospect. Three joins turn it into one, and each is a column you can run over the whole list.
Company shape. Headcount, industry and country decide whether your offer applies at all. Enrich Companies pulls the available company information at 1 credit per company and runs on the free plan. If your best current customers already use HubSpot, Find Similar Companies turns one of them into a whole matched list at 1 credit per company, which is often a faster route to the segment than detection alone.
The named person. The stack tells you the company uses HubSpot. It does not tell you who administers it. Find a company's people lists current and former staff at 1 credit per person and filters by job function, so you keep the revenue operations or marketing operations owner rather than everyone on the payroll.
The reachable address. Email Finder costs 5 credits per email and bills only per result found, and Email Verification confirms the mailbox at 1 credit before you send.

What a HubSpot user list costs to build
Bought technographic files are priced per record or as a subscription, and quoted rather than listed. Built rows price per step, and you only pay for the steps that resolve.
| Step | Feature | Cost | Billed |
|---|---|---|---|
| Detect the stack | Website Technologies | 2 credits / website | Per row requested |
| Qualify the company | Enrich Companies | 1 credit / company | Per row, free plan included |
| Find the owner | Find a company's people | 1 credit / person | Per person |
| Find the address | Email Finder | 5 credits / email | Per result found |
| Verify the address | Email Verification | 1 credit / email | Per result |
That is 2 credits to answer the question on any domain, and roughly 10 credits for a fully qualified and contactable row. The detection step is the cheap one on purpose: you run it across a wide list, keep the confirmed rows, and only spend the remaining eight credits on those. Detection itself sits on a paid plan. Paid plans start at 9 euros a month, and at the largest plan the credit floor of 0.0016 euros puts a complete qualified row near 1.6 cents. Derrick behaves the same at fifty domains and at fifty thousand.
Why "who uses HubSpot" lists go stale so fast
Stack data decays faster than firmographic data, and for a reason worth understanding rather than just budgeting around. Company name, country and industry change rarely. A marketing stack changes whenever a new head of marketing arrives, which in practice is every couple of years in a growing company.
Three movements break a stack list. A migration onto HubSpot creates a prospect your file does not contain. A migration off it leaves a row that still looks valid until someone pitches a HubSpot integration to a company that left last quarter, which is the most expensive way to open a conversation. And a partial rollout, where marketing adopts HubSpot while sales stays elsewhere, makes both the present and absent labels half true at once.
The answer is the same as for any decaying list. Keep the definition, not the file. A stored query, re-run on a date you choose, beats a purchased snapshot every time. And when a migration is the thing you actually sell against, Signal tracks leads and accounts for job changes, funding, hiring sprees and tech stack moves, and starts at 20 euros a month, so the move reaches you when it happens rather than at your next refresh.
Running the detection in one sheet
The whole thing is one spreadsheet with a domain in column A and a date stamp in the last column. Domain, detected CMS, HubSpot components found, detection date, headcount, industry, named owner, job function, found address, verification status. Each column is re-runnable on its own, which is what makes the list a living definition rather than a file.
The same steps run from three surfaces and the right one depends on where the answer needs to land. The spreadsheet sidebar suits a list a human will read and correct. The REST API suits a check that has to run whenever a new account enters the CRM, which is the natural place for stack detection to live. And an MCP connection suits asking an AI assistant whether a given account runs HubSpot, and getting the answer inside the conversation instead of a tab. A web app is coming as well. Match the surface to the workflow.
One habit is worth more than the tooling: write the detection date into every row. Without it you cannot tell a confirmed customer from a company that left, and six months later the whole file becomes untrustworthy at once. Our CRM data quality report covers what undated fields do to a database over time.
Five mistakes when targeting HubSpot users
- Treating "uses HubSpot" as one fact. CMS Hub, analytics only and chat only are different companies with different problems. Segment on the components, not the brand.
- Reading absence as rejection. Sales Hub leaves no public trace. The undetected rows are an unworked segment, not a disqualified one.
- Buying on record count. HubSpot had 299,458 paying customers in March 2026. Any file claiming comparable coverage of a roster HubSpot does not publish is measuring something else.
- Skipping the second signal on thin detections. One HubSpot asset and nothing else is often an agency artefact or a dead campaign page.
- Storing the file instead of the query. Stacks change with every new marketing lead. A dated, re-runnable definition survives that. A CSV does not.
Key takeaways
- HubSpot reported 299,458 paying customers as of 31 March 2026, and does not publish the roster, so no complete list exists to buy.
- Detection reads the components separately: CMS Hub, analytics, chat and forms tell you which parts of HubSpot are in use.
- Two live measurements on 6 September 2026 showed one site fully on CMS Hub and another on Next.js with only the analytics and chat layers.
- Present is a strong qualifier, absent is unknown, because Sales Hub only customers leave no public trace.
- Detection costs 2 credits per domain, and a fully qualified contactable row lands near 10 credits.
- Stack data decays with every change of marketing leadership, so keep the query and the detection date, not the file.
Continue exploring this cluster
Start enriching your sheet in 30 seconds
Free for 100 credits/month. No credit card.