Keep in mind that you have to pay $20 / month to get host name SSL on Heroku even with your own cert, so from that standpoint this is a "good deal". However, one problem I've noticed with this approach is that in the cert Cloudflare uses you can see the 10 or do other domains that share the cert. I'm sure the average customer won't check, but having my cert also be valid for "cheaptoys.com" just felt wrong. Also, doesn't this mean the data is being unencrypted by CF then rencrypted and sent to Heroku? So CF can potentially see the contents of the transmission?
I believe it's because cloudflare also acts as the root DNS for the domain, so in order for it to work for google and facebook, they would have to deliberately point their nameservers at cloudflare's DNS.