Data
GDPR Supabase
For “GDPR Supabase”, the entry records three points published by the vendor: Supabase Pte. Ltd is the processor (or a sub-processor), the DPA is public, and Supabase is not registered under the Data Privacy Framework. If you chose a region, write it: the vendor states that the covered data is stored and primarily processed there.
In an indie stack, Supabase is used for Postgres database, authentication, and storage. Entity cited: Supabase Pte. Ltd. The sections repeat what the vendor publishes, without filling a gap. Last update of the facts: October 4, 2026. Verified on October 4, 2026.
Translation of the French sheet. The facts do not change. The date is the date the official pages were read.
DPA Supabase
Yes. Public Data Processing Addendum.
Stated role
Supabase acts as processor (service provider) and the customer as controller. If the customer processes on behalf of its own controller, Supabase acts as a sub-processor.
Personal data
The DPA annex cites contact details (first name, last name, email), usage data, account information including the password, and any other information determined by the customer.
Sub-processors of Supabase
Public sub-processor list.
Transfers outside the EU
Hosting / location
If the customer designates a region, Supabase states that the covered data is stored and primarily processed there, unless otherwise instructed, legally required, or required for a service requested by the customer. Otherwise, processing may take place anywhere Supabase or its sub-processors have facilities. Stated headquarters: 65 Chulia Street, Singapore. The documentation states that a project is deployed in a single primary region.
EU–United States Data Privacy Framework
Official search for “Supabase” and “Supabase Pte”: no participant. Not registered.
Cookies
The policy (European services cookies section) cites Stripe, Cloudflare, YouTube, hCaptcha, PostHog, and Google Ads cookies, and names _sb_first_referrer (365 days, referrer and UTM parameters) and, for Google Analytics 4, _ga, FPID, _ga*, and FPLC. The SSR documentation states that the Auth session cookie on the customer's domain is called sb-<project_ref>-auth-token by default. Names of the Stripe, Cloudflare, YouTube, hCaptcha, PostHog, and Google Ads cookies: not disclosed.
Typical use, written by StackLégal and not by the vendor: Postgres database, authentication, and storage.
History
Last update: October 4, 2026.
Cookies: names cited in the European services policy, in place of "not disclosed".
First publication. The facts come from the official pages cited in the sources. Anything not stated there remains "not disclosed".
Clause to paste
Place it in the sub-processor section of your privacy policy. Review it: a “not disclosed” field must be completed before publication.
Sub-processor clause
Sources
Verified on October 4, 2026.
Frequently asked questions
Is Supabase a processor within the meaning of the GDPR?
Supabase acts as processor (service provider) and the customer as controller. If the customer processes on behalf of its own controller, Supabase acts as a sub-processor.
What DPA does Supabase publish?
Yes. Public Data Processing Addendum. https://supabase.com/legal/customer-resources/data-processing-addendum
Which further sub-processors does Supabase publish?
Public sub-processor list. https://supabase.com/legal/customer-resources/subprocessor-list
Where does Supabase state that it processes data, including outside the EU?
If the customer designates a region, Supabase states that the covered data is stored and primarily processed there, unless otherwise instructed, legally required, or required for a service requested by the customer. Otherwise, processing may take place anywhere Supabase or its sub-processors have facilities. Stated headquarters: 65 Chulia Street, Singapore. The documentation states that a project is deployed in a single primary region.
Is Supabase registered under the EU–United States Data Privacy Framework?
Official search for “Supabase” and “Supabase Pte”: no participant. Not registered.
Which personal data does Supabase mention?
The DPA annex cites contact details (first name, last name, email), usage data, account information including the password, and any other information determined by the customer.
Stacks that cite Supabase
These pages assemble the sheets of a common stack and state what to write in the privacy policy.
Often in the same stack
These sheets come up in searches for a Next.js SaaS. Next.js itself is not a processor: GDPR Next.js.
Related tools
Full pack, from 39 € incl. VAT
The clause above covers only one tool. StackLégal generates the legal notices, terms of use, terms of sale, privacy policy, Article 28 DPA, and the public list, naming only the boxes that are checked. One-time payment via Gumroad. This is not legal advice.