Combinations
GDPR for stack combinations
A stack page assembles entries that are already published: DPA, location, further processors, transfer outside the EU. It says what to write in the privacy policy. It does not add a fact the entry does not contain.
Two combinations for now. GDPR Next.js explains why the framework is not named as a processor. Published on October 5, 2026. This is not legal advice.
- GDPR Next.js, Vercel, and Stripe
What a Next.js SaaS hosted on Vercel and paid through Stripe must name in its privacy policy and its processor list. Facts taken from the entries, 5 October 2026.
- GDPR Supabase, Resend, and Stripe
What a SaaS on Supabase, Resend, and Stripe must name in its privacy policy and its processor list. Facts taken from the entries, 5 October 2026.
Frequently asked questions
Why is Next.js not in the processor list?
Next.js is the framework. It does not host the data for you. The stack page names Vercel for hosting and Stripe for payment. The detail is on the GDPR Next.js page.
Do these pages replace the entries?
No. Each combination links to the entries, which keep the check date and the official URLs. A “not disclosed” field on an entry stays that way here.
Full pack, from 39 € incl. VAT
These pages cover one combination only. StackLégal generates the legal notice, terms of use, terms of sale, privacy policy, Article 28 DPA and the public list, citing only the boxes you tick. One-time payment via Gumroad. This is not legal advice.