Files
Pamela Chia 4ae0c08967 feat: tos v3 update banner + publish subprocessor list (#48524)
Terms of Service v3 (effective August 1, 2026, #48482) incorporates the
Data Processing Addendum by reference, and Legal asked for an in-app
notice announcing the change. The subprocessor list page that the new
Terms, DPA, and notice all point at was merged as an intentionally
hidden draft (#48100) and never un-hidden.

**Changed:**

- **Dashboard ToS-update banner**: re-enables `BannerTOSUpdate` with the
v3 copy provided by Legal (DPA incorporation, subprocessor list
location, fees provisions). New expiry (August 29) and a new
localStorage key, since anyone who dismissed the May v2 banner would
otherwise never see this one.
- **Subprocessor list page published**: removes `noindex,nofollow` and
links the page from the Legal Hub index, so the page customers are told
to subscribe on is actually discoverable.
- **Studio e2e fixture updated**: the global Playwright fixture
suppressed the banner via the old localStorage key; with the gate live
again it would have rendered the banner into every e2e run. It now sets
the new key.

## To test

Verified on the Vercel previews :

- [x] Studio: banner renders on dashboard load with the Notice badge and
new copy; Learn more dialog shows the three changes with correct hrefs
(DPA page, subprocessor list, /terms); Understood dismisses and persists
across reload via `terms-of-service-update-2026-08-01`
- [x] www: `/legal` lists Subprocessor List under Customer Legal
Resources; `/legal/customer-resources/subprocessor-list` serves `robots`
meta `index,follow` and renders the download button + subscribe form;
zero console errors on all tested pages

## Linear

- fixes GROWTH-1067


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **New Features**
* Added a publicly accessible Subprocessor List to the legal resources.
* Updated the Terms of Service notice to reflect the August 1, 2026
update, including data processing, subprocessors, fraud prevention, and
consumer provisions.

* **Documentation**
* Made the Subprocessor List discoverable through standard search
indexing and the legal resources page.
* Extended the Terms of Service banner availability through August 29,
2026.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-07-31 15:49:08 +08:00

128 lines
3.9 KiB
TypeScript

import { LOCAL_STORAGE_KEYS } from 'common'
import {
Badge,
Button,
Dialog,
DialogClose,
DialogContent,
DialogDescription,
DialogFooter,
DialogHeader,
DialogSection,
DialogSectionSeparator,
DialogTitle,
DialogTrigger,
} from 'ui'
import { InlineLink } from '../../InlineLink'
import { BannerCard } from '../BannerCard'
import { useBannerStack } from '../BannerStackProvider'
import { useLocalStorageQuery } from '@/hooks/misc/useLocalStorage'
export const BannerTOSUpdate = () => {
const { dismissBanner } = useBannerStack()
const [, setTOSUpdateAcknowledged] = useLocalStorageQuery(
LOCAL_STORAGE_KEYS.TERMS_OF_SERVICE_UPDATE,
false
)
return (
<BannerCard
onDismiss={() => {
setTOSUpdateAcknowledged(true)
dismissBanner('tos-update-banner')
}}
>
<div className="flex flex-col gap-y-2">
<Badge variant="default" className="w-min -ml-0.5 uppercase inline-flex items-center mb-2">
Notice
</Badge>
<div className="flex flex-col gap-y-1 mb-2">
<p className="text-sm font-medium">We're updating our Terms of Service</p>
<p className="text-xs text-foreground-lighter text-balance">
Our Data Processing Addendum is now built into the Terms, effective August 1, 2026.
</p>
</div>
<UpdatedTermsOfServiceDialog />
</div>
</BannerCard>
)
}
const UpdatedTermsOfServiceDialog = () => {
const [, setTOSUpdateAcknowledged] = useLocalStorageQuery(
LOCAL_STORAGE_KEYS.TERMS_OF_SERVICE_UPDATE,
false
)
return (
<Dialog>
<DialogTrigger asChild>
<Button variant="default" className="w-min">
Learn more
</Button>
</DialogTrigger>
<DialogContent>
<DialogHeader>
<DialogTitle>Terms of Service update</DialogTitle>
<DialogDescription>
We're updating our Terms of Service, effective August 1, 2026.
</DialogDescription>
</DialogHeader>
<DialogSectionSeparator />
<DialogSection className="text-sm flex flex-col gap-y-2">
<p>What's changing:</p>
<ul className="list-disc pl-4 flex flex-col gap-y-2">
<li>
Our{' '}
<InlineLink href="https://supabase.com/legal/customer-resources/data-processing-addendum">
Data Processing Addendum
</InlineLink>{' '}
is now built into the Terms, so all customers get its protections automatically. No
separate signed DPA is needed.
</li>
<li>
Our subprocessor list now lives at{' '}
<InlineLink href="https://supabase.com/legal/customer-resources/subprocessor-list">
supabase.com/legal/customer-resources/subprocessor-list
</InlineLink>
, where you can subscribe to receive updates to the list.
</li>
<li>
We've added provisions to our fees section relevant to fraud prevention and the rights
of EU and UK consumers.
</li>
</ul>
<p>
The updated Terms (Version 3) take effect on August 1, 2026. By continuing to use the
Services after that date, you agree to the updated Terms. You can review the changes{' '}
<InlineLink href="https://supabase.com/terms">here</InlineLink>.
</p>
<p>
If you have a separate signed subscription agreement or DPA with us, that agreement
continues to govern your use of our Services.
</p>
</DialogSection>
<DialogFooter>
<DialogClose asChild>
<Button
variant="default"
className="opacity-100"
onClick={() => setTOSUpdateAcknowledged(true)}
>
Understood
</Button>
</DialogClose>
</DialogFooter>
</DialogContent>
</Dialog>
)
}