Can't argue with the logic

Then again if the company collects the information because they are well defined as a "Partner" with a site that you gave your information to and agreed in one way or another that you allowed them to share your information with their "Partners" then they have the right do such data collection and you could still be found in the wrong, no matter your intentions or their business practices.
Its the gray line similar to the idea of attacking back when defending your network. One would like it would make sense but there are laws that protect the bad folks as well as the good folks and depending on where the originate, you may be crossing some international lines. Best bet for testing tools is to try and build yourself a web app lab of such. I'm sure you can get some sample sites that can quickly be thrown in for use, or you can test against sites like hackthissite.org.