Privacy Policy

Version 1.0 · Effective date: 3 June 2026 · Controller: HEADING Global Intelligence B.V. (in formation)

1. Who we are

HEADING (“we”, “our”, “us”) operates the HEADING Cost Intelligence Platform at tryheading.app. We are the data controller for personal data collected through this service.

Contact: [email protected]

2. What data we collect

Account data: Name, email address, hashed password (bcrypt). Google OAuth users: name and email provided by Google.

Profile data: Household composition, domain, seniority, income bracket, housing preferences, and lifestyle priorities entered in the analysis wizard. This data is used solely to generate your relocation analysis and is not shared.

Usage data: Number of analyses run, tier, subscription status, and timestamps. Used for billing and usage-limit enforcement.

Payment data: Handled entirely by Stripe. We store only your Stripe customer ID — no card numbers or payment credentials are ever held on our servers.

Technical data: IP address hash (not raw IP) used for share-link access tracking. Error logs and anonymised performance metrics.

Support data: Messages you send through the support system.

3. How we use your data

PurposeLegal basis (GDPR Art. 6)
Deliver the service (run analyses, store reports)Performance of contract (Art. 6.1.b)
Billing and subscription managementPerformance of contract (Art. 6.1.b)
Prevent abuse (rate limiting, fraud detection)Legitimate interests (Art. 6.1.f)
Error monitoring and platform reliabilityLegitimate interests (Art. 6.1.f)
Respond to support requestsPerformance of contract (Art. 6.1.b)
Aggregate, anonymised analytics (conversion funnels)Legitimate interests (Art. 6.1.f)
Legal compliance (tax, financial regulation)Legal obligation (Art. 6.1.c)

We do not sell personal data. We do not use your data for advertising profiling or automated individual decision-making with legal effect.

4. Data sharing and sub-processors

Your account, profile, and analysis data is stored in the European Union (Frankfurt, Germany). Some processing — AI report generation, payments, and email delivery — occurs in the United States under the safeguards listed below. Each provider’s place of incorporation is listed separately from where your data is actually stored and processed.

Sub-processorPurposeIncorporatedData storage / processingTransfer safeguard
Neon Inc.PostgreSQL database hostingUnited StatesEU (Frankfurt)DPF / SCCs
Vercel Inc.Application hosting and serverless computeUnited StatesCompute: EU (Frankfurt); global CDN; build infrastructure in the USDPF
Sentry Inc.Error monitoring and crash reportingUnited StatesEU (Frankfurt)DPF
PostHog Inc.Product analytics (conversion funnels)United StatesEU (Frankfurt)SCCs
Anthropic PBCAI model inference (analysis pipeline)United StatesUnited StatesSCCs
Stripe Inc.Payment processing and subscription managementUnited StatesUnited States / globalDPF
Resend Inc.Transactional email deliveryUnited StatesUnited StatesSCCs
Upstash Inc.Job queue (QStash) and Redis rate-limitingUnited StatesEU (Frankfurt)SCCs
Google LLCOAuth authentication (optional)United StatesUnited States / globalDPF

Where data is processed in the United States, transfers rely on the EU–US Data Privacy Framework (DPF) or standard contractual clauses (SCCs).

5. Data retention

Account data: Retained until you delete your account or request erasure.

Analysis data: Retained until deleted by you or until account deletion.

Support messages: Retained for 3 years after case closure for quality and legal compliance purposes.

Billing records: Retained for 7 years to comply with financial regulations.

Error logs: Anonymised after 90 days; deleted after 1 year.

Shared city cache: City-level cost-of-living data is stored in a shared cache for up to 270 days. This data contains no personal information — it is aggregated research about geographic locations, not about individual users.

6. Your rights (GDPR)

If you are in the European Economic Area or United Kingdom, you have the following rights:

  • Access (Art. 15): Request a copy of your personal data.
  • Rectification (Art. 16): Correct inaccurate data.
  • Erasure (Art. 17): Delete your account and all associated data. Use the “Delete account” option in Settings, or email us.
  • Restriction (Art. 18): Request that we limit processing of your data.
  • Data portability (Art. 20): Receive your data in a structured, machine-readable format.
  • Objection (Art. 21): Object to processing based on legitimate interests.
  • Withdraw consent: Where processing is based on consent, you may withdraw it at any time without affecting prior processing.

To exercise any of these rights, email [email protected] or use the self-service options in your account Settings. We will respond within 30 days.

You have the right to lodge a complaint with your local supervisory authority. In the Netherlands: Autoriteit Persoonsgegevens.

7. Cookies and tracking

We use a small number of first-party cookies and browser-storage items — authentication (NextAuth session/CSRF/callback cookies) and, only with your permission, privacy-friendly analytics (PostHog, EU-hosted, no analytics cookie). See the full inventory, grouped by category, on our /cookies page.

See the full inventory — every cookie and browser-storage item we set, why, and for how long — on our Cookies page. You can change your analytics choice anytime via “Cookie settings” in the footer, or in Settings if you’re signed in.

8. Children

HEADING is not directed at children under 16. We do not knowingly collect personal data from children. If you believe a child has provided data, contact us for immediate deletion.

9. Security

We implement industry-standard technical and organisational measures: TLS encryption in transit, bcrypt password hashing, serverless architecture with minimal attack surface, error monitoring, rate limiting, and security headers (CSP, HSTS, X-Frame-Options). Stripe handles all payment security under PCI-DSS Level 1 compliance.

10. Changes to this policy

We may update this policy when our practices change. Material changes will be notified by email to registered users at least 14 days before taking effect. The effective date above reflects the latest revision.

VersionDateSummary of changes
1.03 June 2026Initial policy.

11. Contact

HEADING Global Intelligence B.V. (in formation)
Email: [email protected]
For erasure requests, use Settings → Delete account, or email us with subject “GDPR Erasure Request”.

Privacy Policy — HEADING