Supabase uses tracking tools including cookies to measure ad performance and deliver personalized advertisements, and California residents can manage their tracking preferences through the Privacy Settings on the site.
This analysis describes what Supabase's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
Tracking for personalized advertising means that your browsing behavior on and potentially off the Supabase site may be used to target you with ads, which is a broader use than many developer-focused platform users would expect.
Interpretive note: The policy references a Privacy Settings control but does not describe its technical scope, consent granularity, or whether it supports Global Privacy Control signals, making compliance completeness difficult to assess.
The updated policy discloses that Supabase may use business contact information, including email domains, to identify organizations for sales and marketing outreach. The policy now explicitly states that personal information will be shared with Customer.io, a marketing communications service provider. For marketing communications, the policy relies on user consent for three purposes: sending marketing messages, using approximate location information to determine relevant communications, and combining personal information from different sources for relevance determination. These three consents operate independently, meaning you can grant or withdraw any of them without affecting the others. You can manage these marketing-related consents separately through the consent mechanisms available in your account or in response to marketing communications.
View change record →Supabase uses cookies and tracking technologies that may share your behavioral data with third-party advertising vendors for personalized ad delivery. You can adjust these preferences through the Privacy Settings button on the Supabase website.
How other platforms handle this
We may display advertisements on our Services and those advertisements may be targeted to your interests based on your personal information. We may share your personal information with advertising partners for interest-based advertising purposes. You may opt out of interest-based advertising by visi...
src="https://trc.taboola.com/1142432/trc/3/json" ... src="https://www.googletagmanager.com/gtag/js?id=DC-15299257" ... src="https://tr.snapchat.com/config/com/af90c7f8-bd28-4988-b1ce-1711aad792f4.js" ... src="https://tr.snapchat.com/config/com/8fbe1595-8c5a-46b1-bbb2-66f3d57debde.js" ... src="https:...
At Ledger, earning and maintaining our users' trust is a top priority. That's why we are deeply committed not only to protecting your privacy and securing your personal data, but also to being fully transparent about how we handle it.
Monitoring
Supabase has changed this document before.
Receive same-day alerts, structured change summaries, and monitoring for up to 25 platforms.
"California - Your California Privacy Rights: If you are a California resident, California Civil Code Section 1798.83 permits you to request information regarding the disclosure of personal information to third parties for their direct marketing purposes during the immediately preceding calendar year. We may use tracking tools to measure the performance of our advertising campaigns and help deliver personalized ads. You can manage your preferences in the Privacy Settings.— Excerpt from Supabase's Supabase Privacy Policy
REGULATORY LANDSCAPE: This provision engages CCPA (particularly CCPA's definition of 'sale' and 'sharing' of personal information as amended by CPRA, which covers cross-context behavioral advertising), the EU ePrivacy Directive and GDPR (which together require informed consent for non-essential cookies for EEA/UK users), and the FTC Act regarding deceptive advertising and tracking practices. Enforcement authorities include the California Privacy Protection Agency (CPPA), the FTC, EU data protection authorities, and the UK ICO. GOVERNANCE EXPOSURE: Medium. The use of third-party tracking for personalized advertising is common but requires robust consent mechanisms for EEA and UK users (opt-in consent under ePrivacy/GDPR) and opt-out mechanisms for California users under CPRA. The policy references a Privacy Settings control but does not describe its technical implementation in detail, making it difficult to assess whether consent granularity meets regulatory requirements. JURISDICTION FLAGS: EEA and UK users require affirmative (opt-in) consent for non-essential tracking cookies before they are set. California users have the right to opt out of the sale or sharing of personal information including cross-context behavioral advertising data. The CPPA has issued enforcement guidance on cookie consent and global privacy controls that may apply to Supabase's implementation. CONTRACT AND VENDOR IMPLICATIONS: Enterprise customers accessing Supabase from regulated environments (particularly those subject to GDPR) should confirm that Supabase's cookie consent mechanism is compliant and that any tracking data collected about their employees or end users does not inadvertently create data flows that conflict with the enterprise's own privacy obligations. COMPLIANCE CONSIDERATIONS: Legal teams should review whether Supabase's Privacy Settings tool supports Global Privacy Control (GPC) signals, which California and some EU frameworks recognize as a valid opt-out signal. Cookie consent audit should verify that non-essential cookies are not set before consent is obtained for EEA/UK users. If Supabase's advertising tracking constitutes a 'sale' or 'sharing' under CPRA, a 'Do Not Sell or Share My Personal Information' mechanism must be clearly accessible.
Full compliance analysis
Regulatory citations, enforcement risk, and due diligence action items.
Free: track 1 platform + weekly digest. Monitor: 25 platforms + same-day alerts. No credit card required.
Ad personalization controls removed. Contact scanning added. Advertiser data partnerships quietly dropped. A timeline of every change.
Compliance Governance Intelligence
Need to monitor specific governance provisions?
Compliance includes provision-level monitoring, governance timelines, regulatory mapping, and audit-ready analysis.
Built from archived source documents, structured governance mappings, and historical version tracking.
Tracking for personalized advertising means that your browsing behavior on and potentially off the Supabase site may be used to target you with ads, which is a broader use than many developer-focused platform users would expect.
Supabase uses cookies and tracking technologies that may share your behavioral data with third-party advertising vendors for personalized ad delivery. You can adjust these preferences through the Privacy Settings button on the Supabase website.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Supabase.