mirror of
https://github.com/supabase/supabase.git
synced 2026-10-06 01:45:10 +03:00
<!-- ccr-slack-attribution --> _Requested by **Sofia Calado** · [Slack thread](https://supabase.slack.com/archives/C0161K73J1J/p1789462983606899)_ ## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? Content update — a new version (v4) of the Privacy Policy legal page, added following the existing versioned-legal-page pattern (v1-v3 already present, selectable via a version dropdown). ## What is the current behavior? Before: On `/privacy`, the latest selectable version is "Version 3 — May 13, 2026". That text names "Supabase, Inc" as the entity you're dealing with — both in the opening paragraph ("Thank you for your interest in Supabase, Inc., ...") and again as the named data controller in the EEA/UK/Switzerland disclosures section ("Supabase, Inc is the data controller..."). The Section 8 cookie table (EEA cookies) lists nine cookies/rows (Stripe x3, Cloudflare x2, Youtube, hCaptcha, Posthog, Google Analytics 4, Google Ads, `_sb_first_referrer`) and does not mention Freebuff anywhere. ## What is the new behavior? After: `/privacy` gains a new "Version 4" entry in the dropdown, at the top of the list (selected by default). Reading Version 4, the same two passages instead name "Supabase Pte. Ltd." as the entity/data controller. The Section 8 cookie table gains one additional row for "Freebuff" (Type: Advertising; dropped when you visit the Site after interacting with a Freebuff ad; 30-day duration; purpose: measuring ad campaign performance and attributing conversions to ad clicks upon consent; linking to the Freebuff Privacy Policy), formatted identically to the existing rows. Versions 1-3 are unchanged and remain selectable. ## Additional context Two changes, scoped exactly as requested: 1. **Data controller entity**: every "Supabase, Inc" / "Supabase Inc." reference that names the data controller is replaced with "Supabase Pte. Ltd." — at the top of the policy and in the EEA disclosures section. No other "Supabase" references (e.g. plain brand mentions) were touched. 2. **Freebuff cookie row**: added to the Section 8 (EEA cookies) table, matching the existing table's markdown formatting exactly. **Open question — effective date needs Sofia/Nicole's input before merge.** No effective date was given for v4. The version-selector component (`LegalDocVersions`) requires a non-empty `effectiveDate` string per version to render (used both in the dropdown label and, for a single-version page, an on-page line) — there's no way to add the version without wiring some string. Following the pattern's convention of never inventing a plausible-looking date, `effectiveDate` is set to the literal placeholder `'TBD'` for v4 in `apps/www/pages/privacy.tsx`. **This must be replaced with a real effective date before this PR merges** — flagging for Sofia Calado / Nicole Kramer to confirm. **Validation**: `pnpm --filter=www build` fails in this sandbox due to an unrelated prebuild step (`docs` app's `build:federated-content` script needs live GitHub API credentials to fetch tags — 401 Bad credentials — not related to this change). `tsc --noEmit` on `apps/www` ran clean of any error touching `privacy.tsx` or the privacy `.mdx` files (all reported errors are pre-existing, about unrelated missing generated assets/images). As a direct substitute, all four `apps/www/data/legal/privacy/*.mdx` files (v1-v4) were compiled through the app's actual MDX pipeline (`@mdx-js/mdx` with the same `remark-code-hike` + `remark-gfm` + `rehype-slug` config as `next.config.mjs`) and all compiled successfully, confirming the new table syntax and content are valid MDX/GFM. Files touched: - `apps/www/data/legal/privacy/v4.mdx` (new) - `apps/www/pages/privacy.tsx` (added v4 to the `versions` array) 🤖 Generated with [Claude Code](https://claude.com/claude-code) https://claude.ai/code/session_01BzHiVEUzjvrwxgnxCrrER1 --------- Co-authored-by: Claude <noreply@anthropic.com>