Skip to content
heedData Supply
SampleHow it worksPricingTerms
Request a dataset

HEED policies

Privacy, explained in plain language.

HEED provides custom business-data research and dataset delivery services. This policy explains how we handle information about website visitors, customers, prospective customers, and people whose professional or business information may appear in a requested dataset.

Effective September 7, 2026Contact: hello@getheed.app
On this page ScopeInformation we handleSourcesHow we use informationHow information is disclosedRestricted dataPrivacy choicesRetention and securityContact

The short version: the website uses Google Analytics. Website checkout encrypts the customer’s target, exclusions, requested fields, quantity instruction, buyer email, and email delivery recipient before storage. Card details are handled by the payment provider. The HEED Support Telegram bot handles customer questions separately from HEED’s private operations bot. Paid HEED work can include delivering professional or business information to a customer, which some privacy laws may treat as a sale of personal information.

1. Scope

This policy applies to getheed.app, website checkout, email and Telegram support, dataset delivery, privacy requests, and related business communications. HEED also uses restricted owner-only Telegram controls internally to operate the service.

Each customer order may involve different targets, data fields, sources, verification requirements, uses, and service providers. The accepted order confirmation defines those details.

2. Information we handle

Information customers and prospects provide

  • Buyer work email, delivery recipient email, company, name, and other business contact information.
  • Dataset specifications, filters, exclusions, volumes, formats, refresh frequency, and intended use.
  • Reference lists, source files, exclusions, and other material provided for an order.
  • Quotes, order records, payment status, invoices, correspondence, support messages, feedback, and privacy requests.
  • For Telegram support: Telegram user and chat identifiers, inquiry text, ticket identifiers, timestamps, owner replies, and delivery status. HEED may retain limited attachment metadata such as type and size. Attachment content is not downloaded or forwarded; describe the issue in text and do not send passwords, payment details, API keys, or private lead files.

Website and analytics information

HEED uses Google Analytics 4. Google or HEED may receive browser and device information, approximate location derived from an IP address, referring pages, pages viewed, timestamps, interactions, and cookie or client identifiers. Google Analytics normally uses first-party cookies to distinguish visitors and sessions. Google requires sites using Analytics to disclose its use. You can learn more through Google’s Analytics privacy information and its browser opt-out add-on.

HEED also uses Google Ads conversion measurement to connect eligible visits with server-confirmed purchases. If you allow measurement, campaign identifiers (including Google click IDs and UTM parameters) may be stored in your browser, passed with checkout, and bound to the resulting order for attribution and audit records. Browser attribution state expires after 90 days; order audit records have separate retention. If enhanced conversions are enabled for the Google Ads account, HEED may send Google a one-way SHA-256 hash of the order email after a confirmed purchase, but only when you have allowed ad user data. Google may process identifiers and hashed matching data for measurement. Personalised ads remain disabled. Use the persistent Privacy choices control to allow, deny, or later revoke measurement storage.

Information that may appear in a dataset

Depending on the accepted order, a dataset may include professional names and roles, employer and company information, industry and company attributes, business contact details, public profile URLs or usernames, non-empty public profile bios, public follower-count snapshots, general business location, sources, research dates, validation status, confidence notes, and professional or company-level classifications.

3. Sources

Depending on the order, HEED may obtain information from public business websites and company pages, publicly accessible professional or business profiles, public records and directories, customer-provided information, licensed business-data providers, and research or verification providers.

Public availability does not eliminate privacy, intellectual-property, platform, marketing, or other legal requirements. HEED applies source restrictions and permitted methods while fulfilling orders.

4. How we use information

  • Process orders and payments, research, validate, document, and deliver requested datasets.
  • Communicate about requests, orders, delivery, support, corrections, and billing.
  • Maintain quality, exception, correction, suppression, and security records.
  • Operate and improve the website, understand page use, and measure request activity.
  • Prevent fraud, abuse, prohibited uses, and security incidents.
  • Comply with applicable law and protect HEED, customers, data subjects, and others.

5. How information is disclosed

Information may be disclosed to the customer receiving an ordered dataset; hosting, analytics, email, payment, research, and verification providers; professional advisers; parties involved in a business transfer; authorities or other parties when required by law or necessary for safety and legal protection; and recipients directed by the customer.

Important: providing professional or business contact data to customers is part of HEED’s paid service. Depending on the data and applicable law, that activity may be treated as a sale of personal information. HEED does not use the phrase “we never sell personal information” because it may be inaccurate for this business model.

6. Restricted and sensitive data

HEED’s service is intended for professional and business research. Do not request, submit, or use HEED to obtain Social Security numbers, account credentials, financial-account numbers, precise geolocation, biometric identifiers, private communications, medical or health information, information about minors, or other sensitive personal information unless HEED has expressly approved a lawful and documented use.

HEED may reject or stop work that creates an unacceptable legal, privacy, safety, platform, or security risk.

7. Privacy choices and requests

Depending on where you live and how HEED operates there, you may have rights to request access, a copy, correction, deletion, or limitation of certain information; opt out of certain sales or sharing; appeal a decision; and receive equal service after exercising a privacy right.

Email hello@getheed.app with Privacy Request in the subject line and identify the information, company, email, profile, or dataset involved. HEED may request enough information to verify the request and locate matching records. Some information may be retained when required for security, legal compliance, dispute resolution, or suppression.

8. Retention, security, and transfers

HEED keeps information only as long as reasonably necessary for the relevant request, order, customer relationship, quality assurance, security, legal compliance, dispute resolution, and suppression obligations. The period depends on the information and why it is held.

A paid website order specification is encrypted in a separately erasable encrypted vault. A restricted audit record retains only an opaque reference and digest, the applicable schema, catalog and terms versions, creation time, and an erasure marker. It does not retain the customer’s targeting instructions, exclusions, requested fields, buyer email, or delivery recipient.

The encrypted specification is available only to HEED’s separately authenticated private import service. The private owner-only Telegram interface does not receive the customer’s encrypted specification, encryption material, or delivery email from the public payment message. After the private importer durably confirms receipt and the order reaches the applicable terminal and retention conditions, the encrypted specification is erased. Missing import confirmation is placed into a short recovery process and then flagged for restricted operator review.

For email delivery, the recipient address is kept only in a separately erasable AES-GCM encrypted recipient vault. Delivery authorization, message, webhook, suppression, and audit records use a keyed pseudonymous recipient reference instead of a plaintext address. The encrypted address is erased when its approved retention period expires; a restricted, pseudonymous erasure record remains to make deletion replay-safe and auditable.

HEED uses reasonable administrative, technical, and organizational safeguards appropriate to the information and service. No transmission or storage method is completely secure. Providers may process information in different states or countries, subject to their service terms and applicable safeguards.

The service is for business users and is not directed to children.

9. Changes and contact

HEED may update this policy as the service, providers, practices, or law changes. The effective date at the top will be revised when material changes are made.

Questions and privacy requests can be sent to hello@getheed.app.

heedData Supply

Custom business data, researched and delivered.

SampleHow it worksPricingContactPrivacyTerms
© 2026 HEEDData as a service · United States