StackLégal

Data

GDPR Supabase

For “GDPR Supabase”, the entry records three points published by the vendor: Supabase Pte. Ltd is the processor (or a sub-processor), the DPA is public, and Supabase is not registered under the Data Privacy Framework. If you chose a region, write it: the vendor states that the covered data is stored and primarily processed there.

In an indie stack, Supabase is used for Postgres database, authentication, and storage. Entity cited: Supabase Pte. Ltd. The sections repeat what the vendor publishes, without filling a gap. Last update of the facts: October 4, 2026. Verified on October 4, 2026.

Translation of the French sheet. The facts do not change. The date is the date the official pages were read.

DPA Supabase

Yes. Public Data Processing Addendum.

Read the DPA

Stated role

Supabase acts as processor (service provider) and the customer as controller. If the customer processes on behalf of its own controller, Supabase acts as a sub-processor.

Personal data

The DPA annex cites contact details (first name, last name, email), usage data, account information including the password, and any other information determined by the customer.

Sub-processors of Supabase

Public sub-processor list.

List published by the vendor

Transfers outside the EU

Hosting / location

If the customer designates a region, Supabase states that the covered data is stored and primarily processed there, unless otherwise instructed, legally required, or required for a service requested by the customer. Otherwise, processing may take place anywhere Supabase or its sub-processors have facilities. Stated headquarters: 65 Chulia Street, Singapore. The documentation states that a project is deployed in a single primary region.

EU–United States Data Privacy Framework

Official search for “Supabase” and “Supabase Pte”: no participant. Not registered.

Cookies

The policy (European services cookies section) cites Stripe, Cloudflare, YouTube, hCaptcha, PostHog, and Google Ads cookies, and names _sb_first_referrer (365 days, referrer and UTM parameters) and, for Google Analytics 4, _ga, FPID, _ga*, and FPLC. The SSR documentation states that the Auth session cookie on the customer's domain is called sb-<project_ref>-auth-token by default. Names of the Stripe, Cloudflare, YouTube, hCaptcha, PostHog, and Google Ads cookies: not disclosed.

Typical use, written by StackLégal and not by the vendor: Postgres database, authentication, and storage.

History

Last update: October 4, 2026.

  1. Cookies: names cited in the European services policy, in place of "not disclosed".

  2. First publication. The facts come from the official pages cited in the sources. Anything not stated there remains "not disclosed".

Clause to paste

Place it in the sub-processor section of your privacy policy. Review it: a “not disclosed” field must be completed before publication.

Sub-processor clause

Add this vendor to your free sub-processors widget

Sources

Verified on October 4, 2026.

Frequently asked questions

Is Supabase a processor within the meaning of the GDPR?

Supabase acts as processor (service provider) and the customer as controller. If the customer processes on behalf of its own controller, Supabase acts as a sub-processor.

What DPA does Supabase publish?

Yes. Public Data Processing Addendum. https://supabase.com/legal/customer-resources/data-processing-addendum

Which further sub-processors does Supabase publish?

Public sub-processor list. https://supabase.com/legal/customer-resources/subprocessor-list

Where does Supabase state that it processes data, including outside the EU?

If the customer designates a region, Supabase states that the covered data is stored and primarily processed there, unless otherwise instructed, legally required, or required for a service requested by the customer. Otherwise, processing may take place anywhere Supabase or its sub-processors have facilities. Stated headquarters: 65 Chulia Street, Singapore. The documentation states that a project is deployed in a single primary region.

Is Supabase registered under the EU–United States Data Privacy Framework?

Official search for “Supabase” and “Supabase Pte”: no participant. Not registered.

Which personal data does Supabase mention?

The DPA annex cites contact details (first name, last name, email), usage data, account information including the password, and any other information determined by the customer.

Stacks that cite Supabase

These pages assemble the sheets of a common stack and state what to write in the privacy policy.

Often in the same stack

These sheets come up in searches for a Next.js SaaS. Next.js itself is not a processor: GDPR Next.js.

Related tools

All the sheets data

Full pack, from 39 € incl. VAT

The clause above covers only one tool. StackLégal generates the legal notices, terms of use, terms of sale, privacy policy, Article 28 DPA, and the public list, naming only the boxes that are checked. One-time payment via Gumroad. This is not legal advice.