CA-C-002132
Supabase — Supabase Privacy Policy
Entity
Date detected
May 15, 2026
Effective date
May 15, 2026
Severity
Direction
Neutral
Affected users
all users business users
Taxonomy
Advertising use expansion
Changes
+4 sentences added · 3 sentences modified
Share 𝕏 Share in Share 🔒 PDF
Watch Supabase Get alerts when this policy changes.
Watch — Free

Event Summary

Supabase updated its privacy policy on May 15, 2026 to disclose expanded use of business contact information for sales and marketing outreach, expanded sharing of personal information with the marketing service provider Customer.io, and clarified consent requirements for marketing communications including location-based and cross-source data analysis. The updated policy establishes that marketing-related consents are independent and can be managed separately.

MEDIUM

Consumer Impact

The updated policy discloses that Supabase may use business contact information, including email domains, to identify organizations for sales and marketing outreach. The policy now explicitly states that personal information will be shared with Customer.io, a marketing communications service provider. For marketing communications, the policy relies on user consent for three purposes: sending marketing messages, using approximate location information to determine relevant communications, and combining personal information from different sources for relevance determination. These three consents operate independently, meaning you can grant or withdraw any of them without affecting the others. You can manage these marketing-related consents separately through the consent mechanisms available in your account or in response to marketing communications.

Governance Analysis

The updated policy establishes explicit disclosure of a specific marketing vendor (Customer.io) and clarifies the consent framework for marketing uses of personal information, including location-based and cross-source data analysis. This provides greater specificity about third parties receiving data and establishes granular controls over marketing-related uses, which affects how users and downstream organizations must document vendor relationships and consent mechanisms.

Available Actions

Review and manage your marketing communication preferences in your Supabase account settings to control consent for marketing messages, location-based determination, and cross-source data analysis independently.

If No Action Is Taken

Marketing communications will be sent and personal information will be shared with Customer.io according to the updated terms.

Location-based determination of marketing relevance and cross-source data combination for marketing purposes will proceed as described in the policy unless consent is withdrawn.

Key Clauses Affected

business contact information use

Policy discloses use of email domains and business contact information to identify organizations for sales and marketing outreach.

Customer.io service provider disclosure

Policy explicitly names Customer.io as a service provider that receives personal information for marketing communications.

independent marketing consents

Policy establishes three independent marketing consents that can be granted or withdrawn separately without affecting each other.

Full clause-by-clause analysis available with Compliance.
These clauses may change again. Get alerted when they do. Watch Supabase — Free

This change record describes what was added, removed, or modified in the document. Analysis reflects what the updated agreement states or permits. It does not constitute a legal determination about enforceability. Applicability may vary by jurisdiction. Methodology

Evidence Verification

✓ Verified
Previous Version
2cff08d82b7b8221c2013b71675ff3f9be44665cb217bf333c53624b94d69114
May 5, 2026 06:38 UTC
✓ Verified
Current Version
7df721dc6d9c35ddc3e51a229e364e46fa9c80975d256d592eac70d7094298d3
May 15, 2026 01:20 UTC
✓ Verified
Change Detected
May 15, 2026 01:20 UTC
Analysis Methodology
✓ Verified
Source Document
https://supabase.com/privacy
Citation Record
Entity: Supabase
Document: Supabase Privacy Policy
Record ID: CA-C-002132
Captured: 2026-05-15 01:20:27 UTC
URL: https://conductatlas.com/change/2026-05-15-supabase-supabase-privacy-policy-2132/
Accessed: June 10, 2026
Permanent archival reference. Stable identifier suitable for legal filings, compliance documentation, and research citation.

Impact Summary

1
New obligations
2
Expanded
Consumers Added

You can now control three different marketing uses of your data independently rather than as a single consent.

Consumers Added

Supabase now explicitly discloses it will use your business contact information to contact your organization for sales purposes.

+ 1 more obligation changes. Full breakdown available with Monitor.

Track changes →
For legal and compliance teams

Institutional Analysis

Assessment

Supabase disclosed expanded marketing practices and clarified consent requirements for marketing-related personal information use. The policy now explicitly names Customer.io as a service provider receiving personal data. The change appears designed to provide clearer notice of marketing data practices and establish granular consent control. Organizations that incorporate Supabase into their vendor stack should review whether this expanded disclosure affects their own privacy notices, particularly for customers whose personal information may be used in cross-source marketing analysis. The change does not appear to create new GDPR/CCPA obligations beyond existing transparency and consent requirements, but clarifies the scope of disclosed practices.

Regulatory Exposure

GDPR (articles 6, 13, 21 on lawful basis, transparency, and objection rights); CCPA (sections 1798.100-1798.120 on disclosure and consumer rights); state privacy laws with marketing communication opt-out requirements

Full compliance analysis

Obligation analysis, escalation trigger, board language, and recommended action.

Monitor $19/mo Compliance $249/mo

Monitor: regulatory citations + obligations. Compliance: full compliance memo.

ConductAtlas provides verified policy intelligence sourced directly from platform documents. All analysis is intended to support, not replace, legal and compliance review. Record CA-C-002132.

Clause-Level Changes

Provisions Modified
User Content and AI-Powered Tool Inputs
Medium

The severity level increased from 'low' to 'medium', elevating the importance of this provision regarding user content and AI tool data handling.

Before/after clause text available with Compliance. See Compliance →

9 provisions unchanged.

Cross-platform context

See how other platforms handle similar provisions across the ConductAtlas archive.

Compare across platforms → Browse regulations →

Full Changes

See the full side-by-side comparison of every sentence added, removed, and modified.

🔒 Full diff — Monitor

Document Context

Version history → Policy drift analysis → Document page →
Document
Supabase Privacy Policy
Entity
Supabase
Captured
May 15, 2026
Source URL
https://supabase.com/privacy
More from Supabase
May 6, 2026 Medium
Supabase Terms of Service

Supabase updated its legal entity from a Delaware corporation to a Singapore-based company and refined several procedural details in its …

May 5, 2026 Low
Supabase Terms of Service

Supabase changed its corporate structure from a Singapore entity (SUPABASE PTE. LTD.) to a Delaware corporation (Supabase, Inc.) on May …

Related Analysis
Privacy · April 29, 2026
What 38 AI Companies Actually Say About Your Data (2026)

We read the privacy policies and terms of service of 38 AI platforms. Here is what they say about training, retention, arbitration, and lia…

Track Supabase policy changes

Get alerted when this policy changes again — including what changed and why it matters.

Prefer a weekly summary instead?

Get the biggest policy changes across 320+ platforms every Sunday.