Data Brokers

B2B Data Brokers and Your Work Email

By the RedactZero Team · August 31, 2026 · 9 min read

The short version

ZoomInfo, Apollo.io and RocketReach sell your name, job title, employer, work email and often a direct phone line to sales teams. You are in their databases because their users sync inboxes and address books, not because you signed up. Each has a free opt-out keyed to your work email, and since 2023 California law treats B2B contact data like any other personal data. Removal works, but profiles rebuild when someone syncs you back in, so re-check every few months.

What a B2B data broker actually is

A B2B data broker sells professional contact data - who you are, where you work, your work email and phone - to salespeople trying to reach you at your job. Unlike people-search sites, its customers are companies running outreach campaigns, not curious individuals, and its product is your inbox.

The category is huge and mostly invisible. You will rarely stumble on your own ZoomInfo profile the way you might find yourself on Whitepages, because access sits behind sales-team subscriptions. But the record is there: a work-shaped dossier that explains why strangers cold-call your direct line and why sales emails follow you from job to job.

How your work email gets into these databases

Mostly, someone who has emailed you shared their inbox. The big B2B brokers run "contributory networks": users of their free tools agree to share contact data from their own mailboxes and address books, and every signature block you have ever sent becomes raw material.

This is not a secret. ZoomInfo's own FAQ says community members "agree to let proprietary machine learning track the email signature lines of sent and received messages from their inboxes," and that its network verifies 20 million email signatures a month. Apollo.io describes a network of over 2 million data sources built from connected inboxes, CRMs and uploaded contact lists.

The second stream is scraping. ZoomInfo says its systems constantly scan corporate websites, press releases, news articles, SEC filings and job postings. RocketReach's privacy policy describes search technology that "scans the web" for publicly available information from social media, corporate sites and public records. Your LinkedIn page and your company's team page both feed the machine.

The big three: ZoomInfo, Apollo.io and RocketReach

Three names dominate the category, and their own marketing tells you the scale. ZoomInfo claims 500 million contacts, Apollo.io claims 240 million, and RocketReach claims 700 million professional profiles. If you have held a job in the US, the practical assumption is that at least one of them lists you.

BrokerClaimed database sizeWhere it says the data comes fromFree opt-out
ZoomInfo500M contacts, 100M companiesContributor inboxes (email signatures) plus web and filings scanningPrivacy center, email code verification
Apollo.io240M+ contacts, 30M+ companies2M+ contributor sources plus large-scale web crawlingRemoval form keyed to your work email
RocketReach700M profiles, 60M companiesWeb scanning, public records, customer "community program"Claim-profile flow, then remove

Database sizes are each company's own marketing claims, from zoominfo.com, apollo.io and rocketreach.co, retrieved August 2026.

Behind the big three sits a long tail of "email finder" and "sales intelligence" tools that license or scrape much of the same data. Our B2B database opt-out hub covers the category and how the removals differ from people-search sites.

Why a work-only profile still hurts you

It is tempting to shrug: the data is "just" your job title and work email. But that exact bundle - name, employer, role and a direct dial - is the starting kit for targeted phishing and phone scams against you and your employer, and it is why security teams care about these databases.

A scammer who knows your title, your boss's name and your direct line does not need to hack anything to sound convincing. Payroll-diversion emails, fake-invoice fraud and "urgent request from the CEO" calls all start with accurate org-chart data. A direct mobile number in a B2B record also gives strangers a path to you that skips your company's switchboard entirely.

There is a quieter cost too: the record follows you. Contributor networks keep re-verifying your details, so a database can learn you changed jobs before your old colleagues do, and the cold calls simply move to your new desk.

When a B2B database leaks: the 2018 Apollo breach

These databases are also breach targets, and the canonical example is Apollo. In July 2018, the company left a database publicly exposed without a password. According to Have I Been Pwned, 125.9 million email addresses were affected, alongside names, employers, job titles, phone numbers, locations and social media profiles.

No passwords or financial data leaked, but the stolen bundle was exactly the data that makes spear-phishing convincing, now free to anyone rather than sold to subscribers. It is worth checking whether your work address was caught in it - you can run a free exposure scan against known breaches, and nothing you type is stored.

The rules are different, and they changed in 2023

B2B contact data used to sit in a legal gap: US privacy debates focused on consumers, and California's CCPA initially exempted business-contact data outright. That exemption expired on January 1, 2023, so California residents now hold the same rights over B2B records - access, deletion, correction and opt-out of sale - as over any other personal data.

The industry has adjusted in visible ways. Apollo's privacy policy states plainly that it "operates as a registered business-to-business data broker." RocketReach's policy declares it is "a data broker under Texas law," and a California data broker registration exists in RocketReach's name. Registration does not shrink the databases, but it does mean documented, legally backed removal channels.

Courts have pushed back too. In Martinez v. ZoomInfo, a class action argued that showing "teaser" profiles of real people to advertise subscriptions violated right-of-publicity laws. ZoomInfo settled for $29.55 million, with final approval in November 2024, covering people in California, Illinois, Indiana and Nevada whose profiles were used this way.

How to remove yourself from ZoomInfo

ZoomInfo runs a self-service privacy center, and the removal takes about 10 to 15 minutes. The one preparation step that matters: find your profile first by searching your name in the contact search on zoominfo.com, and copy the profile URL, because the form asks for it.

From there, open the privacy center via the "Do Not Sell My Personal Information" link in the site footer, request an email verification code, enter it, and submit the removal with your profile URL attached. Our step-by-step ZoomInfo opt-out guide has screenshots of each screen.

How to remove yourself from Apollo.io

Apollo's opt-out is quick - around five minutes - but it is keyed to the business email on your record, not your name. Submitting a personal address commonly returns "no match" even when a listing exists, because the profile is filed under the work address a synced contact list supplied.

Use the "Do Not Sell My Info" link in Apollo's footer, enter your work email, and click the verification link Apollo sends to complete the removal. If the record sits under a former employer's domain you can no longer access, say so via Apollo's privacy request channel. The full walkthrough is in our Apollo.io opt-out guide.

How to remove yourself from RocketReach

RocketReach routes removal through a claim-profile flow: you assert the listing is yours, then delete it. The claim path and the update path look similar, so read each screen - you are there to remove the record, not to manage it.

Start from the "Do Not Sell My Info" link at the bottom of rocketreach.co, identify your listing with your name, employer and a valid email, then open the claim link RocketReach emails you and choose to remove the profile. Our RocketReach opt-out guide covers each step and the confirmation to look for.

Why you reappear, and how to stay out

Opting out removes today's record, not the pipeline that built it. Every time a salesperson installs a contributor tool and syncs an inbox that contains you, the database gets fresh raw material, and crawlers keep re-reading your company's team page. A removed B2B profile can quietly return months later.

Three habits keep the damage down. First, re-check the big three every few months and re-file removals when you reappear. Second, keep your email signature minimal - a name and role leak less than a signature with direct dial and mobile. Third, treat your employer's public team page as part of your footprint, since scrapers certainly do.

And keep the categories straight: clearing B2B databases does not touch the people-search sites that publish your home address and relatives. Those need their own removals, covered in our free opt-out guides.

See what is exposed before you start

Run a free exposure scan to see the breaches tied to your email - including Apollo - plus the brokers likely to list you. No account, nothing stored.

Run a free exposure scan

Frequently asked questions

Why am I in ZoomInfo if I never signed up for it?

ZoomInfo builds profiles from its contributory network - users of its free tools agree to share data from their inboxes, including email signatures - plus automated scanning of corporate websites and public filings. If you have ever emailed someone in that network, your signature details may have been collected.

Is it legal for B2B data brokers to sell my work email?

Broadly yes in the US, but it is regulated. These companies register as data brokers, and since January 1, 2023 California's CCPA applies fully to B2B contact data, so California residents can demand deletion. ZoomInfo also paid a $29.55 million settlement over how it used people's names in marketing previews.

How do I remove myself from ZoomInfo?

Find your profile on zoominfo.com and copy its URL, then open ZoomInfo's self-service privacy center, verify your email address with an emailed code, and submit the removal form. Using the work email the record is filed under makes the match much more reliable.

Why does Apollo.io say it has no record of me?

Apollo's opt-out is keyed to the business email address on the record, not just your name. Searching with a personal address often returns nothing even though a listing exists under your work address. Use the email tied to your current or former employer instead.

Was Apollo.io ever breached?

Yes. In July 2018 Apollo left a database publicly exposed, and 125.9 million email addresses later appeared in the Have I Been Pwned breach index, along with names, employers, job titles, phone numbers, locations and social media profiles. Passwords and financial data were not included.

Will my profile come back after I opt out?

It can. B2B databases rebuild from newly synced address books and fresh web crawls, so a removed profile can return when a contact connects their inbox again. Re-check every few months and re-file the removal if you reappear.

Do B2B brokers publish my home address?

Usually not. Their records are work-shaped: name, job title, employer, work email and direct dial. Your home address, relatives and personal numbers typically live on people-search sites instead, which are a separate category with their own opt-out forms.

Can I stop coworkers' sales tools from re-adding me?

Not directly. The contributory model means anyone with you in their inbox or contacts can feed you back in when they install a sales tool. What you can do is keep your email signature minimal, opt out of the big three databases, and repeat the removals periodically.

Sources: ZoomInfo's data FAQ and data-sources pages (zoominfo.com); Apollo.io's homepage, B2B data page and privacy policy (apollo.io); RocketReach's privacy policy and marketing pages (rocketreach.co); Have I Been Pwned on the July 2018 Apollo breach (haveibeenpwned.com/Breach/Apollo); Morgan Lewis on the CCPA B2B exemption expiring January 1, 2023; ZoomInfo's SEC Form 8-K and Top Class Actions on the Martinez v. ZoomInfo settlement (final approval November 2024).