Sub-processors and service providers
The services Heading uses to operate its platform.
Last updated: 8 October 2026
Heading uses the services below to operate the platform. Where Heading processes customer personal data on the customer's behalf, providers that process that data support that processing. Providers can have other roles, including processing Heading's own account, payment or website data. The role and data involved depend on the feature used; this list does not classify every provider as a sub-processor for every customer.
Platform services
| Provider | Service and data involved | When used |
|---|---|---|
| Vercel | Application and documentation hosting, content delivery, file storage and AI Gateway routing. Requests, uploaded files and model requests may pass through these services. | Hosting for the platform; storage and model routing for features that use them. |
| Neon | PostgreSQL database hosting for account, team, brand and service records. | Core platform storage. |
| Inngest | Background job orchestration. Job events and relevant service data are used to run scheduled and event-driven work. | Background processing. |
| Resend | Transactional email delivery, including recipient addresses and email content. | Account and service emails. |
| Stripe | Payment processing and subscription billing, including customer, billing and transaction details. | Paid plans and checkout. |
| DataForSEO | Search and AI response data collection, using the search queries, prompts and domains submitted for monitoring and research. | Monitoring and research features. |
| Anthropic, OpenAI, Google, DeepSeek, Alibaba (Qwen) and Mistral | AI model services available through the configured model gateway. Prompts, conversation content and relevant context are sent when a model is used. | According to the selected model and gateway routing; not every provider is used for every request. |
| Account authentication and customer-connected Google services. Account and connection details, and data accessed under the customer's permissions, are involved. | Google sign-in or a customer-connected Google feature. | |
| Parallel | Web search used through the AI gateway, including search queries and relevant request context. | Gateway search for features and models that use this backend. |
| Vercel Connect | Connections to external accounts used by agent features, including authorisation and connection details. | When a user connects an external account. |
| Cloudflare Turnstile | Bot protection, using browser and interaction signals to assess requests. | On protected forms when Turnstile is configured. |
Optional website and support services
These services stay off in the web app and documentation site until the relevant cookie choice is accepted. Availability differs by site.
| Provider | Service and data involved | When used |
|---|---|---|
| Google Analytics | Website usage analytics, including page views and browser information. | With analytics consent in the web app. |
| PostHog | Product and website usage analytics, including events and browser information. | With analytics consent in the web app, when configured. |
| Vercel Analytics and Speed Insights | Website usage and performance measurements. | With analytics consent where installed. |
| Intercom | Support chat, including messages and visitor information, and account details for signed-in support. | With support-chat consent where installed. |
You can revisit Cookie settings on the site to change your choices. Email support@useheading.com if you prefer to contact support without chat.
Customer-selected connections
A connected external service, such as a customer's Google account or analytics property, is used only when that feature is connected or invoked. Review the connection screen and that provider's terms for the access involved. Providers reached through a data collection service or gateway are not necessarily direct contractual sub-processors of Heading.
Processing terms and updates
The customer processing terms are in Schedule 1 of the Terms of Service. That Schedule governs sub-processor authorisation and objections. This register does not add a separate notice policy or contractual promise.
Processing locations, account-specific contract terms and certifications are not asserted here. Contact support@useheading.com for information about your processing arrangements. This list is based on the services configured in the application; individual features and connections can change which services process a customer's data.