Files
supabase/apps/www/pages/privacy.tsx
claude[bot]andClaude adca15deab chore(www): add Privacy Policy v4 (data controller entity, Freebuff cookie) (#50392)
<!-- ccr-slack-attribution -->
_Requested by **Sofia Calado** · [Slack
thread](https://supabase.slack.com/archives/C0161K73J1J/p1789462983606899)_

## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

## What kind of change does this PR introduce?

Content update — a new version (v4) of the Privacy Policy legal page,
added following the existing versioned-legal-page pattern (v1-v3 already
present, selectable via a version dropdown).

## What is the current behavior?

Before: On `/privacy`, the latest selectable version is "Version 3 — May
13, 2026". That text names "Supabase, Inc" as the entity you're dealing
with — both in the opening paragraph ("Thank you for your interest in
Supabase, Inc., ...") and again as the named data controller in the
EEA/UK/Switzerland disclosures section ("Supabase, Inc is the data
controller..."). The Section 8 cookie table (EEA cookies) lists nine
cookies/rows (Stripe x3, Cloudflare x2, Youtube, hCaptcha, Posthog,
Google Analytics 4, Google Ads, `_sb_first_referrer`) and does not
mention Freebuff anywhere.

## What is the new behavior?

After: `/privacy` gains a new "Version 4" entry in the dropdown, at the
top of the list (selected by default). Reading Version 4, the same two
passages instead name "Supabase Pte. Ltd." as the entity/data
controller. The Section 8 cookie table gains one additional row for
"Freebuff" (Type: Advertising; dropped when you visit the Site after
interacting with a Freebuff ad; 30-day duration; purpose: measuring ad
campaign performance and attributing conversions to ad clicks upon
consent; linking to the Freebuff Privacy Policy), formatted identically
to the existing rows. Versions 1-3 are unchanged and remain selectable.

## Additional context

Two changes, scoped exactly as requested:
1. **Data controller entity**: every "Supabase, Inc" / "Supabase Inc."
reference that names the data controller is replaced with "Supabase Pte.
Ltd." — at the top of the policy and in the EEA disclosures section. No
other "Supabase" references (e.g. plain brand mentions) were touched.
2. **Freebuff cookie row**: added to the Section 8 (EEA cookies) table,
matching the existing table's markdown formatting exactly.

**Open question — effective date needs Sofia/Nicole's input before
merge.** No effective date was given for v4. The version-selector
component (`LegalDocVersions`) requires a non-empty `effectiveDate`
string per version to render (used both in the dropdown label and, for a
single-version page, an on-page line) — there's no way to add the
version without wiring some string. Following the pattern's convention
of never inventing a plausible-looking date, `effectiveDate` is set to
the literal placeholder `'TBD'` for v4 in `apps/www/pages/privacy.tsx`.
**This must be replaced with a real effective date before this PR
merges** — flagging for Sofia Calado / Nicole Kramer to confirm.

**Validation**: `pnpm --filter=www build` fails in this sandbox due to
an unrelated prebuild step (`docs` app's `build:federated-content`
script needs live GitHub API credentials to fetch tags — 401 Bad
credentials — not related to this change). `tsc --noEmit` on `apps/www`
ran clean of any error touching `privacy.tsx` or the privacy `.mdx`
files (all reported errors are pre-existing, about unrelated missing
generated assets/images). As a direct substitute, all four
`apps/www/data/legal/privacy/*.mdx` files (v1-v4) were compiled through
the app's actual MDX pipeline (`@mdx-js/mdx` with the same
`remark-code-hike` + `remark-gfm` + `rehype-slug` config as
`next.config.mjs`) and all compiled successfully, confirming the new
table syntax and content are valid MDX/GFM.

Files touched:
- `apps/www/data/legal/privacy/v4.mdx` (new)
- `apps/www/pages/privacy.tsx` (added v4 to the `versions` array)

🤖 Generated with [Claude Code](https://claude.com/claude-code)

https://claude.ai/code/session_01BzHiVEUzjvrwxgnxCrrER1

---------

Co-authored-by: Claude <noreply@anthropic.com>
2026-09-16 17:26:21 +08:00

42 lines
1.6 KiB
TypeScript

import { MDXProvider } from '@mdx-js/react'
import DefaultLayout from '~/components/Layouts/Default'
import SectionContainer from '~/components/Layouts/SectionContainer'
import LegalDocVersions, { type LegalDocVersion } from '~/components/Legal/LegalDocVersions'
import PageBreadcrumb from '~/components/Sections/PageBreadcrumb'
import PageHeader from '~/components/Sections/PageHeader'
import V1 from '~/data/legal/privacy/v1.mdx'
import V2 from '~/data/legal/privacy/v2.mdx'
import V3 from '~/data/legal/privacy/v3.mdx'
import V4 from '~/data/legal/privacy/v4.mdx'
import mdxComponents from '~/lib/mdx/mdxComponents'
import { NextSeo } from 'next-seo'
const meta = {
title: 'Privacy Policy | Supabase',
description: 'Supabase Privacy Policy',
}
const versions: LegalDocVersion[] = [
{ id: 'v4', label: 'Version 4', effectiveDate: 'September 16, 2026', Component: V4 },
{ id: 'v3', label: 'Version 3', effectiveDate: 'May 13, 2026', Component: V3 },
{ id: 'v2', label: 'Version 2', effectiveDate: 'March 16, 2026', Component: V2 },
{ id: 'v1', label: 'Version 1', effectiveDate: 'May 28, 2025', Component: V1 },
]
export default function PrivacyPolicyPage() {
return (
<DefaultLayout>
<NextSeo {...meta} />
<PageHeader
breadcrumb={<PageBreadcrumb items={[{ label: 'Legal', href: '/legal' }]} />}
h1="Privacy Policy"
/>
<MDXProvider components={mdxComponents()}>
<SectionContainer className="prose">
<LegalDocVersions versions={versions} />
</SectionContainer>
</MDXProvider>
</DefaultLayout>
)
}