Heroku

Heroku

Cloud platform as a service for deploying and scaling web applications. Heroku is primarily backend infrastructure with no direct script presence on end-user sites. Applications hosted on Heroku may set standard session and authentication cookies.

Overview

Heroku is a cloud platform as a service (PaaS) owned by Salesforce, used by developers to deploy, manage, and scale web applications. Heroku is backend infrastructure — it hosts applications but doesn't inject scripts into the websites it serves. Applications running on Heroku may set their own cookies for session management, but these come from the application itself, not from Heroku as a third-party.

If Heroku appears in a third-party script audit, it's because the application is hosted on Heroku's infrastructure, not because Heroku is loading external tracking scripts.

What This Script Does

Heroku itself has no third-party script presence:

  • Application hosting: Runs web applications on Heroku's cloud infrastructure with managed deployment and scaling
  • No client-side scripts: Heroku does not inject scripts, pixels, or tracking code into hosted applications
  • Application cookies: Any cookies set are from the hosted application itself, not from Heroku as a third party

Consent & Compliance

  • GDPR: Heroku as infrastructure doesn't process visitor personal data beyond hosting. The hosted application's own data processing determines consent requirements.
  • ePrivacy Directive: No third-party cookies or scripts from Heroku.

Should You Block This Without Consent?

Heroku does not load third-party scripts on websites. It's infrastructure that hosts applications. There is nothing to block in the context of website consent management.

No.

Is Heroku GDPR compliant?

Heroku typically loads functional trackers, which are not strictly necessary for your site to work. Under the GDPR and the ePrivacy Directive, non-essential cookies and trackers must stay blocked until a visitor gives clear opt-in consent. So Heroku can be fully GDPR compliant, but only if your site holds its scripts until consent is granted and lets visitors decline just as easily. Compliance depends on how your site loads Heroku, not on Heroku itself.

Visit website

Consent Categories

Also Known As

heroku cookiesheroku consentheroku session cookiesheroku gdprheroku privacy complianceheroku app cookie management

Industries

Programming and Developer SoftwareComputers Electronics and Technology

Tracked Domains (1)

heroku.comEssential

heroku.com is an essential domain operated by Heroku, used to keep the site working, including security, load balancing, and sessions.

Frequently Asked Questions

Related Vendors

Beehiiv
Beehiiv
Newsletter publishing and monetization platform. Scripts embed subscription forms and newsletter content widgets on external websites. Sets cookies to track reader identity, referral attribution, and subscription conversion events across site visits.
Zopim
Zopim
Legacy brand for Zendesk Chat. Scripts embed a live chat widget for real-time customer support conversations. Sets session cookies to maintain chat history and visitor context across pages; may set persistent cookies for returning visitor recognition.
Cookie-Script
Cookie-Script
Cookie consent management and compliance platform. Scripts display configurable consent banners, capture user consent preferences by category, and enforce script blocking for non-consented cookies. Stores consent records locally; supports GDPR, CCPA, and regional compliance frameworks.
Osano
Osano
Osano is a data privacy platform offering consent management, vendor monitoring, and privacy compliance tools. Scripts display consent interfaces on websites and selectively block non-consented tracking scripts. Vendor risk assessments and consent records are centralized in the Osano platform for legal and compliance teams.
CookieYes
CookieYes
CookieYes is a cookie consent management platform used to achieve GDPR, CCPA, and ePrivacy compliance. Scripts scan for cookies on the site, display a customizable consent banner, and block third-party scripts based on user consent choices. Consent logs are maintained for compliance auditing.
MTCaptcha
MTCaptcha
MTCaptcha is a CAPTCHA security service that embeds challenge widgets on forms and login pages to verify human users and prevent automated bot abuse. Scripts present visual or behavioral challenges and report verification results to the host site to gate form submission.

Manage consent for Heroku

ConsentStack automatically detects and manages Heroku trackers so your site stays compliant with global privacy regulations.