Privacy Policy
Version 1.0 · Effective date: 3 June 2026 · Controller: HEADING Global Intelligence B.V. (in formation)
1. Who we are
HEADING (“we”, “our”, “us”) operates the HEADING Cost Intelligence Platform at tryheading.app. We are the data controller for personal data collected through this service.
Contact: [email protected]
2. What data we collect
Account data: Name, email address, hashed password (bcrypt). Google OAuth users: name and email provided by Google.
Profile data: Household composition, domain, seniority, income bracket, housing preferences, and lifestyle priorities entered in the analysis wizard. This data is used solely to generate your relocation analysis and is not shared.
Usage data: Number of analyses run, tier, subscription status, and timestamps. Used for billing and usage-limit enforcement.
Payment data: Handled entirely by Stripe. We store only your Stripe customer ID — no card numbers or payment credentials are ever held on our servers.
Technical data: IP address hash (not raw IP) used for share-link access tracking. Error logs and anonymised performance metrics.
Support data: Messages you send through the support system.
3. How we use your data
| Purpose | Legal basis (GDPR Art. 6) |
|---|---|
| Deliver the service (run analyses, store reports) | Performance of contract (Art. 6.1.b) |
| Billing and subscription management | Performance of contract (Art. 6.1.b) |
| Prevent abuse (rate limiting, fraud detection) | Legitimate interests (Art. 6.1.f) |
| Error monitoring and platform reliability | Legitimate interests (Art. 6.1.f) |
| Respond to support requests | Performance of contract (Art. 6.1.b) |
| Aggregate, anonymised analytics (conversion funnels) | Legitimate interests (Art. 6.1.f) |
| Legal compliance (tax, financial regulation) | Legal obligation (Art. 6.1.c) |
We do not sell personal data. We do not use your data for advertising profiling or automated individual decision-making with legal effect.
4. Data sharing and sub-processors
Your account, profile, and analysis data is stored in the European Union (Frankfurt, Germany). Some processing — AI report generation, payments, and email delivery — occurs in the United States under the safeguards listed below. Each provider’s place of incorporation is listed separately from where your data is actually stored and processed.
| Sub-processor | Purpose | Incorporated | Data storage / processing | Transfer safeguard |
|---|---|---|---|---|
| Neon Inc. | PostgreSQL database hosting | United States | EU (Frankfurt) | DPF / SCCs |
| Vercel Inc. | Application hosting and serverless compute | United States | Compute: EU (Frankfurt); global CDN; build infrastructure in the US | DPF |
| Sentry Inc. | Error monitoring and crash reporting | United States | EU (Frankfurt) | DPF |
| PostHog Inc. | Product analytics (conversion funnels) | United States | EU (Frankfurt) | SCCs |
| Anthropic PBC | AI model inference (analysis pipeline) | United States | United States | SCCs |
| Stripe Inc. | Payment processing and subscription management | United States | United States / global | DPF |
| Resend Inc. | Transactional email delivery | United States | United States | SCCs |
| Upstash Inc. | Job queue (QStash) and Redis rate-limiting | United States | EU (Frankfurt) | SCCs |
| Google LLC | OAuth authentication (optional) | United States | United States / global | DPF |
Where data is processed in the United States, transfers rely on the EU–US Data Privacy Framework (DPF) or standard contractual clauses (SCCs).
5. Data retention
Account data: Retained until you delete your account or request erasure.
Analysis data: Retained until deleted by you or until account deletion.
Support messages: Retained for 3 years after case closure for quality and legal compliance purposes.
Billing records: Retained for 7 years to comply with financial regulations.
Error logs: Anonymised after 90 days; deleted after 1 year.
Shared city cache: City-level cost-of-living data is stored in a shared cache for up to 270 days. This data contains no personal information — it is aggregated research about geographic locations, not about individual users.
6. Your rights (GDPR)
If you are in the European Economic Area or United Kingdom, you have the following rights:
- Access (Art. 15): Request a copy of your personal data.
- Rectification (Art. 16): Correct inaccurate data.
- Erasure (Art. 17): Delete your account and all associated data. Use the “Delete account” option in Settings, or email us.
- Restriction (Art. 18): Request that we limit processing of your data.
- Data portability (Art. 20): Receive your data in a structured, machine-readable format.
- Objection (Art. 21): Object to processing based on legitimate interests.
- Withdraw consent: Where processing is based on consent, you may withdraw it at any time without affecting prior processing.
To exercise any of these rights, email [email protected] or use the self-service options in your account Settings. We will respond within 30 days.
You have the right to lodge a complaint with your local supervisory authority. In the Netherlands: Autoriteit Persoonsgegevens.
7. Cookies and tracking
We use a small number of first-party cookies and browser-storage items — authentication (NextAuth session/CSRF/callback cookies) and, only with your permission, privacy-friendly analytics (PostHog, EU-hosted, no analytics cookie). See the full inventory, grouped by category, on our /cookies page.
See the full inventory — every cookie and browser-storage item we set, why, and for how long — on our Cookies page. You can change your analytics choice anytime via “Cookie settings” in the footer, or in Settings if you’re signed in.
8. Children
HEADING is not directed at children under 16. We do not knowingly collect personal data from children. If you believe a child has provided data, contact us for immediate deletion.
9. Security
We implement industry-standard technical and organisational measures: TLS encryption in transit, bcrypt password hashing, serverless architecture with minimal attack surface, error monitoring, rate limiting, and security headers (CSP, HSTS, X-Frame-Options). Stripe handles all payment security under PCI-DSS Level 1 compliance.
10. Changes to this policy
We may update this policy when our practices change. Material changes will be notified by email to registered users at least 14 days before taking effect. The effective date above reflects the latest revision.
| Version | Date | Summary of changes |
|---|---|---|
| 1.0 | 3 June 2026 | Initial policy. |
11. Contact
HEADING Global Intelligence B.V. (in formation)
Email: [email protected]
For erasure requests, use Settings → Delete account, or email us with subject “GDPR Erasure Request”.