Supabase updated its privacy policy on May 15, 2026 to disclose expanded use of business contact information for sales and marketing outreach, expanded sharing of personal information with the marketing service provider Customer.io, and clarified consent requirements for marketing communications including location-based and cross-source data analysis. The updated policy establishes that marketing-related consents are independent and can be managed separately.
Consumers: You can now control three different marketing uses of your data independently rather than as a single consent.
Consumers: Supabase now explicitly discloses it will use your business contact information to contact your organization for sales purposes.
Consumers: Supabase now names Customer.io as a specific vendor that will receive your personal data for marketing purposes.
The updated policy discloses that Supabase may use business contact information, including email domains, to identify organizations for sales and marketing outreach. The policy now explicitly states that personal information will be shared with Customer.io, a marketing communications service provider. For marketing communications, the policy relies on user consent for three purposes: sending marketing messages, using approximate location information to determine relevant communications, and combining personal information from different sources for relevance determination. These three consents operate independently, meaning you can grant or withdraw any of them without affecting the others. You can manage these marketing-related consents separately through the consent mechanisms available in your account or in response to marketing communications.
→ Review and manage your marketing communication preferences in your Supabase account settings to control consent for marketing messages, location-based determination, and cross-source data analysis independently.
Policy discloses use of email domains and business contact information to identify organizations for sales and marketing outreach.
Policy explicitly names Customer.io as a service provider that receives personal information for marketing communications.
Policy establishes three independent marketing consents that can be granted or withdrawn separately without affecting each other.
This change record describes what was added, removed, or modified in the document. Analysis reflects what the updated agreement states or permits. It does not constitute a legal determination about enforceability. Applicability may vary by jurisdiction. Methodology
Supabase disclosed expanded marketing practices and clarified consent requirements for marketing-related personal information use. The policy now explicitly names Customer.io as a service provider receiving personal data. The change appears designed to provide clearer notice …
Regulatory exposure, obligation change, escalation trigger, board-ready language, and recommended action for legal and compliance teams.
Unlock the full institutional analysis — InsightConductAtlas provides verified policy intelligence sourced directly from platform documents. All analysis is intended to support, not replace, legal and compliance review. Record CA-C-002132.
Supabase removed the explicit publication date and version history from the opening of their Privacy Policy in an update detected …
Supabase revised its Terms of Service in an update detected on July 31, 2026, making predominantly formatting and punctuation changes …
Supabase updated its legal entity from a Delaware corporation to a Singapore-based company and refined several procedural details in its …
Get the research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean.
Get alerted when this policy changes again, including what changed and why it matters.