Cookie Policy Generator for Framer
Written for Framer forms, the CMS, custom code in site settings and third-party embeds.
Framer’s own cookie footprint is minimal, which makes the cookie policy almost entirely a list of what you added. That is a document you can actually make accurate, provided someone checks the site settings rather than copying a table.
Framer sites are usually marketing sites for products and studios, built quickly and instrumented immediately: an analytics script, a scheduling embed, a form that posts to an email tool, and often a chat widget. The platform is light on default tracking, so almost everything collecting data was added deliberately.
Framer acts as a processor for form submissions and hosting, publishes a data processing addendum, and stores form entries in the dashboard until deleted. Its own cookie footprint is small, but custom code added under site settings loads exactly where you put it.
The pattern that causes trouble is speed. A Framer site can go from blank to launched in an afternoon, and the legal pages are typically the last thing added - if they are added at all.
What a cookie policy for a Framer site has to cover
Framer platform and hosting cookies, categorised honestly
Each analytics or product-tracking script and the cookies it sets
Chat widget and scheduling embed cookies
How consent gating is implemented and what it actually blocks
How a visitor reopens the banner to change their choice later
How a Framer site actually moves personal data
Form submissions
Name, email and message stored in the Framer dashboard, plus a copy wherever the notification is sent.
Analytics added via custom code
Plausible, Fathom, GA4 or a product analytics snippet, loading on first paint unless deliberately deferred.
Scheduling and demo embeds
Calendly or Cal.com iframes that collect booking data directly into the provider.
Chat widgets
Intercom or Crisp, which set cookies and retain conversation transcripts.
Framer hosting and CDN
Server logs including IP addresses, retained by the platform under its own policy.
CMS collections
Where a policy or blog is CMS-driven, editorial data lives alongside the site content.
Third parties the draft will ask you about
Framer B.V. · Calendly or Cal.com · Plausible or Google Analytics 4 · Intercom or Crisp · Loops or Resend · Stripe
The rules that apply
Framer Terms and DPA
Framer processes form submissions and site data on your behalf, with a published addendum.
Custom code placement
Scripts added to the head or body of site settings load on every page unless gated deliberately.
Form submission storage
Entries are retained in the Framer dashboard and usually forwarded to an email address or webhook.
Third-party embeds
Calendly, Typeform, YouTube and Loom embeds each set their own cookies from their own domains.
CMS-driven pages
A single policy template can render several documents, which keeps them consistent if used deliberately.
What the generated cookie policy contains
What the technologies actually are
Cookies, local storage, session storage, pixels, SDKs and server-side tags - the law covers storage and access on a device, not the word "cookie".
A per-cookie table
Name, provider, purpose, category and duration for each cookie, which is the format UK and EU regulators expect to see.
Category definitions
Strictly necessary, functional, analytics and advertising, with an honest explanation of why only the first runs without consent.
How consent was obtained and how to change it
The banner, the granular choices, and a permanent link to reopen preferences - the withdrawal route has to be as easy as the acceptance route.
Third-party cookies and onward use
Which providers set cookies through your site and what they do with the data once it is theirs.
Browser and device controls
Practical instructions, plus a note that blocking strictly necessary cookies will break parts of the service.
Publishing the document on Framer
Create a page per document with a clean path
Or a CMS collection if you want one template to render several policies.
Link them in the footer component
So every page carries the link, including new ones.
List everything in site settings custom code
That list is your recipients and cookies disclosure.
Gate analytics and chat behind consent
For UK and EU visitors, before they load rather than after.
Set a form retention routine
And delete entries on that schedule.
Set the page-level SEO title and description
Framer will not do it for you, and a policy page with no metadata renders poorly in search.
Where this usually goes wrong
Launching without any legal pages
The most common Framer failure, because the build is fast and the pages are an afterthought.
Analytics and chat loading before consent
For UK and EU traffic, both need consent before they run.
Scheduling embeds collecting data invisibly
A Calendly iframe collects name, email and sometimes phone directly into Calendly’s systems.
Form entries kept indefinitely
They sit in the dashboard until someone deletes them.
No named controller on a studio site
Agency-built sites frequently launch with no identifiable operator in the policy.
Frequently asked questions
Does Framer include legal pages?
No. Framer provides hosting, forms and a data processing addendum for its own role. Every document on the site is yours to write and publish.
Where do Framer form submissions go?
Into the Framer dashboard, and usually also to whichever email address or webhook you configured - two copies with two retention positions.
Do I need a cookie banner on a Framer site?
If you serve UK or EU visitors and run analytics, chat or embeds, yes - and it has to hold those until consent rather than merely announce them.
Do I need a cookie policy as well as a privacy policy?
In the UK and EU, yes in practice. PECR and the ePrivacy Directive regulate storing and reading information on a device separately from GDPR’s rules on processing, and the per-cookie disclosure is too detailed to bury in a privacy policy.
Do analytics cookies need consent?
In the UK and EU, yes - the ICO has said repeatedly that analytics is not "strictly necessary". Some EU regulators allow a narrow exemption for first-party, non-shared audience measurement, but the default answer is consent first.
Does a cookie policy need updating when I add a tool?
Yes, and this is the clause that goes stale fastest. Every new tag, pixel or embedded widget adds cookies your table does not list. Scanning your own site on a schedule is the only reliable way to keep it honest.
What about cookies set by embedded video and maps?
They count. An embedded YouTube player or Google Map sets third-party cookies as soon as it loads, so either it loads only after consent, or you use a privacy-preserving embed mode and say so.
Cookie Policy Generator for Framer
Answer a short questionnaire and get a draft written for a Framer site. Free to start, no card required.
Generate your cookie policyOther documents a Framer site needs
Each one is written for the same context, not a generic template.
The same document, by platform
Go deeper
PolicifyAI is a technology provider, not a law firm, and this page is not legal advice. Generated documents are a structured starting point that a qualified adviser should review before you publish or rely on them.