The policy discloses that personal information may be transferred to and processed in countries, including the United States, that may not offer the same level of data protection as the user's country of origin.
This analysis describes what Supabase's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This provision acknowledges that cross-border data transfers may involve jurisdictions with lower data protection standards, a disclosure that directly implicates GDPR Chapter V transfer requirements and UK adequacy framework obligations. The policy does not specify in this section what transfer mechanisms (such as Standard Contractual Clauses) are used, though the EEA/UK section may address this.
Interpretive note: The specific transfer mechanisms relied upon for EU/UK/Swiss data are not disclosed in the main policy body; compliance assessment depends on the EEA/UK section and the referenced DPA.
The updated policy discloses that Supabase may use business contact information, including email domains, to identify organizations for sales and marketing outreach. The policy now explicitly states that personal information will be shared with Customer.io, a marketing communications service provider. For marketing communications, the policy relies on user consent for three purposes: sending marketing messages, using approximate location information to determine relevant communications, and combining personal information from different sources for relevance determination. These three consents operate independently, meaning you can grant or withdraw any of them without affecting the others. You can manage these marketing-related consents separately through the consent mechanisms available in your account or in response to marketing communications.
View change record →Under this clause, personal information collected from users in the EU, UK, Switzerland, or other jurisdictions may be transferred to and stored in the United States or other countries. The agreement states that transferred data may be subject to lower protection standards in the destination country.
How other platforms handle this
to request that your data be transferred to a third party (data portability)
Your organization may allow you to access and export your data in order to back it up or transfer it to a service outside of Google.
Further, you may take legal actions in relation to any potential breach of your rights regarding the processing of your Personal Information, as well as to lodge complaints before the competent data prot...
"Personal information may be transferred to, stored and processed in a country other than the one in which it was collected. For example, the Sites are primarily hosted in and provided from the United States. Please note the country to which personal data is transferred may not provide the same level of protection for personal information as the country from which it was transferred.Excerpt from Supabase's Privacy Policy
1) REGULATORY LANDSCAPE: This provision engages GDPR Chapter V (transfers to third countries), UK GDPR international transfer requirements, and Swiss data protection law.
Enforcement risk, jurisdiction flags, contract triggers, and due diligence action items.
Search "[your state] attorney general consumer complaint" to find your state's direct complaint form
Ad personalization controls removed. Contact scanning added. Advertiser data partnerships quietly dropped. A timeline of every change.
Get the research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean.
This provision acknowledges that cross-border data transfers may involve jurisdictions with lower data protection standards, a disclosure that directly implicates GDPR Chapter V transfer requirements and UK adequacy framework obligations. The policy does not specify in this section what transfer mechanisms (such as Standard Contractual Clauses) are used, though the EEA/UK section may address this.
Under this clause, personal information collected from users in the EU, UK, Switzerland, or other jurisdictions may be transferred to and stored in the United States or other countries. The agreement states that transferred data may be subject to lower protection standards in the destination country.
ConductAtlas has identified this type of provision across 290 platforms. See the full comparison.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Supabase.