FlowConsent
ServicesBlogExtensionSolutionsPricingTry FlowConsent
FlowConsent

FlowConsent is a GDPR-compliant cookie consent management platform.

Product

  • Services
  • Extension
  • Extension support
  • Solutions
  • Pricing
  • FlowConsent App

Legal

  • Privacy Policy
  • Terms of Service
  • Legal notice

© 2026 FlowConsent by BeBranded. All rights reserved.

FrancaisDeutschEspanol

Does your website use third-party services? Get GDPR compliant in minutes.

Try FlowConsent
  1. Home
  2. Services
  3. Hosting
  4. Heroku
H

Heroku

Other

Related services

A

actionhero.js

actionhero.js is a web technology service that provides essential functionality for websites and digital platforms. It delivers core capabilities that support site operations, content delivery, and user experience optimization. actionhero.js integrates seamlessly with modern web architectures, ensuring reliable performance and compatibility across browsers and devices. Trusted by businesses worldwide, actionhero.js helps organizations maintain robust websites that meet user expectations and technical requirements.

Other

Adminer

Adminer is a foundational web service that powers critical website functions and digital experiences. It provides reliable infrastructure, seamless integration capabilities, and consistent performance across all devices and browsers. Adminer supports modern development practices and scales with growing business needs. With a focus on stability and compatibility, Adminer ensures your website delivers a smooth, uninterrupted experience to every visitor and search engine crawler.

Other
A

Akka HTTP

Akka HTTP is a web technology service that provides essential functionality for websites and digital platforms. It delivers core capabilities that support site operations, content delivery, and user experience optimization. Akka HTTP integrates seamlessly with modern web architectures, ensuring reliable performance and compatibility across browsers and devices. Trusted by businesses worldwide, Akka HTTP helps organizations maintain robust websites that meet user expectations and technical requirements.

Other
A

Alibaba Cloud Object Storage Service

Alibaba Cloud Object Storage Service is a web hosting and cloud infrastructure provider delivering reliable, scalable hosting solutions for websites and applications of all sizes. It offers shared, VPS, and dedicated server options with SSD storage, global CDN, and automated backups. Alibaba Cloud Object Storage Service provides one-click deployment, managed databases, and 24/7 monitoring. With high uptime guarantees and developer-friendly tools, Alibaba Cloud Object Storage Service ensures optimal.

Other

AlmaLinux

AlmaLinux is a foundational web service that powers critical website functions and digital experiences. It provides reliable infrastructure, seamless integration capabilities, and consistent performance across all devices and browsers. AlmaLinux supports modern development practices and scales with growing business needs. With a focus on stability and compatibility, AlmaLinux ensures your website delivers a smooth, uninterrupted experience to every visitor and search engine crawler.

Other
A

AlternC

AlternC is a foundational web service that powers critical website functions and digital experiences. It provides reliable infrastructure, seamless integration capabilities, and consistent performance across all devices and browsers. AlternC supports modern development practices and scales with growing business needs. With a focus on stability and compatibility, AlternC ensures your website delivers a smooth, uninterrupted experience to every visitor and search engine crawler.

Other
Get compliant — Try FlowConsent free

Free plan · 10-min setup

What does Heroku do?

Heroku is a Platform as a Service that has been hosting Ruby, Node.js, Python, PHP, Java, Go and Clojure applications since 2007. Acquired by Salesforce in 2010, Heroku runs on AWS with a European region (eu-west-1 Ireland) and Private Spaces in Frankfurt and Dublin. Heroku itself does not set cookies on the public visitors of a hosted application; the application owner remains responsible for any cookies and analytics it deploys on top of Heroku.

What Heroku is and how it fits in a website stack

Heroku is one of the oldest Platforms as a Service, founded in 2007 and acquired by Salesforce in 2010. It hosts Ruby, Node.js, Python, PHP, Java, Go and Clojure applications on dynos that run on AWS infrastructure, with built in CI/CD, an extensive add on marketplace (Heroku Postgres, Heroku Redis, Heroku Connect, Heroku Data for Redis, third party data and observability tools) and Heroku Shield for HIPAA and PCI workloads. Most customers operate APIs, internal tools and B2B SaaS on Heroku.

What data Heroku processes

Heroku processes the IP address, request URL, HTTP method, headers and TLS handshake parameters needed to route requests to the application dynos. Logs (Logplex) include request metadata and any log line emitted by the application. Heroku Postgres and Heroku Data add ons store the application data the customer chooses to persist. Heroku itself does not set cookies on the public visitors of customer applications.

GDPR and ePrivacy implications

IP addresses processed by the Heroku Router are personal data under the GDPR. Heroku is a processor for the customer application and a controller for limited operational purposes. Pure hosting does not write information to the visitor device, so the ePrivacy consent rule is not triggered. The application owner remains the controller for any cookies, analytics or marketing scripts it loads inside the dyno responses.

Get GDPR compliant in 10 minutes

Free plan available · No credit card required

Try FlowConsent free

International data transfers

Heroku Common Runtime offers a European region (eu-west-1 Ireland); Heroku Private Spaces extend coverage to Frankfurt and Dublin for full EU residency. The control plane, customer support and account data operate from the United States. Transfers rely on the Salesforce Data Processing Addendum, the EU Standard Contractual Clauses under Article 46(2)(c) GDPR and the EU US Data Privacy Framework, with TLS 1.3, encryption at rest, ISO 27001, SOC 2 Type II and Heroku Shield offerings for HIPAA and PCI DSS workloads.

Practical compliance steps

Sign the Salesforce Data Processing Addendum, deploy your applications in the European region (or in a Private Space in Frankfurt or Dublin) for EU residency, configure log retention rules on Logplex, encrypt sensitive columns in Heroku Postgres and consider Heroku Shield for HIPAA and PCI workloads. Document Heroku as a processor in your record of processing activities and mention the US transfer to Salesforce in the privacy notice.

GDPR consent category

Other

Websites using Heroku must obtain user consent under GDPR regulations.

Legal basisLegitimate Interest (Art. 6(1)(f) GDPR) for hosting and routing the customer application; performance of a contract (Art. 6(1)(b) GDPR) for the underlying contract with Heroku; the application owner remains the controller for end user data stored on dynos and add ons
Risk levelmedium
Applicable regulationsGDPR, ePrivacy Directive (Cookie Law), CCPA, HIPAA (with Salesforce BAA on Shield)

DPIA considerations

A DPIA is generally not required for a standard SaaS hosted on Heroku. A DPIA is recommended when the application performs systematic profiling, when Heroku Postgres and Heroku Connect store large volumes of EU personal data, when Heroku Shield is used for HIPAA workloads or when the customer operates in a regulated sector.

Sample consent text

This application is hosted on Heroku, a Platform as a Service operated by Heroku Inc. (a Salesforce company, USA) on AWS in the Ireland region. Heroku processes the IP address, request URL and headers needed to route the traffic. By accepting, you allow this transfer to Heroku and Salesforce servers, including in the United States, under EU Standard Contractual Clauses and the EU US Data Privacy Framework.

Technical details

Tracking methodPlatform as a Service (PaaS) hosting Ruby, Node.js, Python, PHP, Java, Go and Clojure applications on dynos backed by AWS; HTTP routing through the Heroku Router
Server locationAWS regions selected by the customer: Common Runtime in us-east-1 and eu-west-1 (Ireland); Private Spaces in additional AWS regions (Frankfurt, Dublin, Virginia, Oregon, Tokyo, Sydney); company headquartered in San Francisco (Heroku, a Salesforce company)
Cookieless tracking availableYes
Data transferred outside the EUHeroku is a Platform as a Service operated by Heroku Inc., a subsidiary of Salesforce Inc. (USA). The Common Runtime offers a European region (eu-west-1 Ireland), while Private Spaces extend coverage to Frankfurt and Dublin. The control plane, account management, billing and support are operated from the United States. Transfers rely on the Salesforce Data Processing Addendum, the EU Standard Contractual Clauses under Article 46(2)(c) GDPR and the EU US Data Privacy Framework.

Third-party domains contacted

heroku.comherokuapp.comheroku-app.comsalesforce.com

This service may collect user data. Ensure GDPR compliance with FlowConsent.

Get started freeScan your site

Frequently asked questions

Does Heroku set cookies on visitor devices?

No. Heroku is a hosting platform and does not set any cookies on the public visitors of customer applications. Cookies on a site hosted on Heroku come from the application code itself or from third party scripts that the application loads.

Is consent required for Heroku under GDPR and ePrivacy?

No. Pure hosting and HTTP routing do not write information to the device, so the ePrivacy consent rule is not triggered. Consent obligations come from the application running on Heroku, not from Heroku itself.

What is the legal basis for processing data through Heroku?

For hosting and routing the application, the legal basis is legitimate interest under Article 6(1)(f) GDPR. The contract with Heroku is processed under Article 6(1)(b) GDPR. Personal data stored in Heroku Postgres or Heroku Connect follows the legal basis chosen by the application owner.

How are data transfers to the United States protected?

Heroku is operated by Salesforce. Salesforce signs the EU Standard Contractual Clauses under Article 46(2)(c) GDPR via its Data Processing Addendum and confirms participation in the EU US Data Privacy Framework. Supplementary measures include TLS 1.3, encryption at rest, ISO 27001 and SOC 2 Type II, with Heroku Shield for HIPAA and PCI workloads.

Is a DPIA required for Heroku?

A DPIA is not required for a standard application on Heroku. A DPIA is recommended when the hosted application performs systematic profiling of EU users, when Heroku Postgres stores large volumes of personal data, when Heroku Shield is used for HIPAA workloads or when the application targets regulated sectors.

How do I deploy Heroku in a GDPR compliant way?

Sign the Salesforce Data Processing Addendum, run production in the eu-west-1 region or in a Frankfurt or Dublin Private Space, configure log retention, encrypt sensitive columns in Heroku Postgres and document Heroku as a processor in your record of processing activities. Mention the US transfer to Salesforce in the privacy notice and audit any add on that processes personal data.

What are the alternatives to Heroku in Europe?

European or open source alternatives include Scaleway Serverless (France), Clever Cloud (France), OVHcloud Web PaaS (France), Render with EU regions, Fly.io with European regions, Coolify (self hosted, open source) and self hosted Kubernetes on Hetzner or Scaleway clusters.

How do I update the cookie policy when using Heroku?

List Heroku (Salesforce) as the hosting processor, mention that the application is deployed in the EU Ireland region or in a Private Space, state that data including IP addresses may be transferred to the United States under SCCs and the EU US Data Privacy Framework, and link to the Salesforce Privacy Policy.