StackLégal

Combination

GDPR Supabase, Resend, and Stripe

This page reuses the vendor entries for the stack. It says what to write in the privacy policy and in the processor list. Last update: October 5, 2026.

What the entries say

Location, DPA, further processors and transfer mechanism. Each block links to the entry, which keeps its own check date.

Supabase

Full entry

Supabase Pte. Ltd. Checked on October 4, 2026.

Hosting / location
If the customer designates a region, Supabase states that the covered data is stored and primarily processed there, unless otherwise instructed, legally required, or required for a service requested by the customer. Otherwise, processing may take place anywhere Supabase or its sub-processors have facilities. Stated headquarters: 65 Chulia Street, Singapore. The documentation states that a project is deployed in a single primary region.
DPA
Yes. Public Data Processing Addendum. Source
Further processors
Public sub-processor list. Source
Transfer (Data Privacy Framework)
Official search for “Supabase” and “Supabase Pte”: no participant. Not registered.

Plus Five Five, Inc.. Checked on October 4, 2026.

Hosting / location
The DPA states that the primary processing operations are in the United States. Stored data is stored in the United States.
DPA
Yes. Public DPA. Source
Further processors
Public list. Source
Transfer (Data Privacy Framework)
The participant “Resend”, legal name PLUS FIVE FIVE, is registered. Exact EU-U.S. Data Privacy Framework status: Active - Re-certification under Review. Source

Stripe Payments Europe, Limited for accounts outside North and South America; Stripe, LLC for accounts located in North or South America. Checked on October 4, 2026.

Hosting / location
The DPA indicates a transfer to Stripe, LLC in the United States. The privacy policy states that the majority of providers are in the European Union, the United States, and India.
DPA
Yes. The DPA is part of the Stripe Services Agreement. Source
Further processors
Public list of providers, sub-processors, and affiliates. Source
Transfer (Data Privacy Framework)
Stripe, LLC is registered. EU-U.S. Data Privacy Framework status: Active. The European entity Stripe Payments Europe, Limited is not the name on that entry. Source

What to write in the policy

You remain the controller of the processing. Three vendors see data of your users: the database, transactional email, and payment. Each has its entry, with its entity, its role, its location, its DPA, and its transfer mechanism.

Supabase Pte. Ltd is the processor, or a sub-processor if you already are one. If you chose a region, the entry states that the covered data is stored and primarily processed there: write the project's actual region. Supabase is not registered under the Data Privacy Framework. Point to its DPA and its sub-processor list.

Resend (Plus Five Five, Inc.) is the processor of email data, and an independent controller for the account, billing, and service usage. The DPA places the primary operations and storage in the United States. The “Resend” participant has status Active - Re-certification under Review.

For Stripe, name your account's entity, the dual role (processor on instruction, independent controller for fraud and AML/CFT), the transfer to Stripe, LLC in the United States, and the DPF registration of Stripe, LLC.

On cookies, the Supabase entry cites the Auth session cookie on your domain and cookies of its own site. The Resend entry indicates essential cookies. Complete this with the cookies that your application sets in addition.

History

  1. First publication. The facts are taken from the entries, which cite the official pages. What is not there stays “not disclosed”.

Clauses to paste

One clause per vendor, for the processors section. Review them: a “not disclosed” field must be completed before publication.

Sub-processor clause

Related entries

Full pack, from 39 € incl. VAT

The clauses above cover this stack only. StackLégal generates the legal notice, terms of use, terms of sale, privacy policy, Article 28 DPA and the public list, citing only the boxes you tick. One-time payment via Gumroad. This is not legal advice.