The policy states that personal data submitted through Supabase's platform by enterprise customers relating to their own end users is processed by Supabase as a data processor under a separate data processing addendum, and this privacy notice does not govern that processing.
This analysis describes what Supabase's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This provision establishes that end users of applications built on Supabase are not covered by this privacy notice, placing the primary disclosure obligation on the Supabase customer (the application operator) rather than Supabase itself. This has direct implications for enterprise customers who must maintain their own adequate privacy disclosures and ensure their DPA with Supabase is GDPR Article 28 compliant.
The updated policy discloses that Supabase may use business contact information, including email domains, to identify organizations for sales and marketing outreach. The policy now explicitly states that personal information will be shared with Customer.io, a marketing communications service provider. For marketing communications, the policy relies on user consent for three purposes: sending marketing messages, using approximate location information to determine relevant communications, and combining personal information from different sources for relevance determination. These three consents operate independently, meaning you can grant or withdraw any of them without affecting the others. You can manage these marketing-related consents separately through the consent mechanisms available in your account or in response to marketing communications.
View change record →Under this clause, individuals whose personal data is processed through applications built on Supabase are directed to consult the privacy notice of the application operator rather than Supabase's own policy. The agreement establishes that Supabase's obligations for such data are governed by a separate data processing addendum with the relevant enterprise customer.
How other platforms handle this
Where ZipRecruiter processes your Personal Data in the capacity of a service provider (data processor), and you seek access, or want to correct, amend, or delete your Personal Data...we will provide you with the data controller's contact information, so you can contact them directly.
to request that your data be transferred to a third party (data portability)
Your organization may allow you to access and export your data in order to back it up or transfer it to a service outside of Google.
"Our Service allows customers to submit, manage or otherwise use content relating to others, such as end users of applications built and managed through the Service or their employees and contractors ("Customer Data"). We use such Customer Data primarily as a processor, meaning we process such Customer Data on behalf of and under the instructions of the relevant customer, in accordance with our data processing addendum. This Privacy Notice does not apply to such processing; if you believe your personal information has been included in any Customer Data, we recommend you read the Privacy Notice of the respective customer.Excerpt from Supabase's Privacy Policy
1) REGULATORY LANDSCAPE: This provision directly engages GDPR Article 28 (processor obligations), which requires a written contract between controller and processor specifying the nature and purpose of processing.
Enforcement risk, jurisdiction flags, contract triggers, and due diligence action items.
Ad personalization controls removed. Contact scanning added. Advertiser data partnerships quietly dropped. A timeline of every change.
Get the research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean.
This provision establishes that end users of applications built on Supabase are not covered by this privacy notice, placing the primary disclosure obligation on the Supabase customer (the application operator) rather than Supabase itself. This has direct implications for enterprise customers who must maintain their own adequate privacy disclosures and ensure their DPA with Supabase is GDPR Article 28 compliant.
Under this clause, individuals whose personal data is processed through applications built on Supabase are directed to consult the privacy notice of the application operator rather than Supabase's own policy. The agreement establishes that Supabase's obligations for such data are governed by a separate data processing addendum with the relevant enterprise customer.
ConductAtlas has identified this type of provision across 290 platforms. See the full comparison.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Supabase.