mirror of
https://github.com/supabase/supabase.git
synced 2026-10-10 11:55:05 +03:00
Terms of Service v3 (effective August 1, 2026, #48482) incorporates the Data Processing Addendum by reference, so customers no longer sign a separate DPA. Legal confirmed the PandaDoc signing flow can go; previously signed DPAs remain binding. This removes the frontend flow only. I'll remove the platform endpoint (`POST /platform/organizations/{slug}/documents/dpa`) separately once the PandaDoc contract conversation wraps. **Changed:** - **Dashboard DPA card no longer requests PandaDoc documents**: the Request DPA button and confirm modal are replaced with a View DPA link to the canonical legal page, with evergreen copy explaining the DPA is part of the Terms. Tracked via the same `document_view_button_clicked` event the other document cards use. - **Legacy `/legal/dpa` page retired**: the page told users to request a signed DPA from the dashboard, which no longer exists. It now permanently redirects to `/legal/customer-resources/data-processing-addendum` (the follow-up already flagged in #48483), and the footer link is removed. The `dpa_pdf_opened` and `dpa_request_button_clicked` events are removed with their last call sites. The latest privacy version links the canonical page directly; archived v1/v2 keep their original `/legal/dpa` link, served by the redirect. - **Orphaned DPA PDFs removed**: the four dated `Supabase+DPA+*.pdf` files under `/downloads/docs` had zero remaining references once the signing flow is gone. No redirect: nothing links these URLs, so they 404. - **Subscription tracking**: the subprocessor updates form now fires `www_subprocessor_updates_subscribed` on successful submit, so we can measure uptake of the notification list that replaces per-customer DPA emails. ## To test Verified on the Vercel previews (Playwright): - [x] Studio: `/org/_/documents` shows the DPA card with the incorporation copy and a working View DPA link (href = canonical page); no Request DPA button, no PandaDoc mention; TIA/SOC2/ISO27001/HIPAA cards unaffected - [x] www: `/legal/dpa` permanently redirects to `/legal/customer-resources/data-processing-addendum`; footer no longer shows DPA; zero console errors - [x] www: subscribing on the subprocessor page succeeds (200 from the form route, profile created with topic_4) and fires `www_subprocessor_updates_subscribed` (201 from the telemetry endpoint); test profile unsubscribed afterwards - [x] www: `/downloads/docs/Supabase+DPA+260601.pdf` returns 404 with no redirect; DPA card copy verified without the effective date ## Linear - fixes GROWTH-1068
44 lines
1.5 KiB
TypeScript
44 lines
1.5 KiB
TypeScript
import { Button } from 'ui'
|
|
|
|
import {
|
|
ScaffoldSection,
|
|
ScaffoldSectionContent,
|
|
ScaffoldSectionDetail,
|
|
} from '@/components/layouts/Scaffold'
|
|
import { InlineLink } from '@/components/ui/InlineLink'
|
|
import { useTrack } from '@/lib/telemetry/track'
|
|
|
|
export const DPA = () => {
|
|
const track = useTrack()
|
|
|
|
return (
|
|
<ScaffoldSection className="py-12">
|
|
<ScaffoldSectionDetail>
|
|
<h4 className="mb-5">Data Processing Addendum (DPA)</h4>
|
|
<div className="space-y-2 text-sm text-foreground-light [&_p]:m-0">
|
|
<p>
|
|
Our Data Processing Addendum is incorporated into our{' '}
|
|
<InlineLink href="https://supabase.com/terms">Terms of Service</InlineLink>, so all
|
|
organizations get its protections automatically. No separate signed DPA is needed.
|
|
</p>
|
|
<p>If you signed a DPA with us previously, that agreement remains binding.</p>
|
|
</div>
|
|
</ScaffoldSectionDetail>
|
|
<ScaffoldSectionContent>
|
|
<div className="@lg:flex items-center justify-center h-full">
|
|
<Button asChild variant="default">
|
|
<a
|
|
href="https://supabase.com/legal/customer-resources/data-processing-addendum"
|
|
target="_blank"
|
|
rel="noreferrer noopener"
|
|
onClick={() => track('document_view_button_clicked', { documentName: 'DPA' })}
|
|
>
|
|
View DPA
|
|
</a>
|
|
</Button>
|
|
</div>
|
|
</ScaffoldSectionContent>
|
|
</ScaffoldSection>
|
|
)
|
|
}
|