Cookie Policy Generator for Webflow
Written for Webflow forms, the CMS, custom code in Site Settings and Webflow’s own consent mode.
Webflow’s own cookie footprint is small, which makes the cookie policy almost entirely a document about the tools you or your agency added. That is a much easier document to make accurate - provided someone actually opens Site Settings.
Webflow sites are usually built by an agency or a freelancer and handed over, which creates a specific compliance gap: the person responsible for the privacy policy is rarely the person who added the tracking. Google Tag Manager, HubSpot, Intercom, Hotjar and a marketing pixel or two typically live in Site Settings → Custom Code, added during the build and never revisited.
Webflow itself is a processor for form submissions and site data, and it publishes a data processing addendum. Its hosting sets a small number of cookies, and Webflow Ecommerce adds order and payment flows through Stripe or PayPal. The platform is comparatively light on default tracking - which means almost everything running on a Webflow site was deliberately added.
Webflow supports a privacy consent mode with data-wf-consent attributes that can gate scripts by category, plus integrations with the main consent platforms. Used properly it blocks tags until consent; unused, every script in the head loads on first paint.
What a cookie policy for a Webflow site has to cover
Webflow platform cookies, categorised as strictly necessary or otherwise
Each custom-code script and the cookies it sets
Embeds - YouTube, Vimeo, Maps, Calendly, Typeform - and their third-party cookies
How consent gating is implemented, whether through Webflow consent attributes or a consent platform
The route back to change consent
How a Webflow site actually moves personal data
Form submissions stored in Webflow
Name, email and free-text message retained in the dashboard indefinitely unless you delete them, plus a copy in whichever inbox receives the notification.
Custom code in Site Settings
GTM, ad pixels, heatmaps and chat widgets pasted into the head or body tags. These load site-wide on first paint unless tagged for consent.
Webflow hosting cookies
A small set of platform cookies for hosting and, where enabled, for the Webflow-hosted forms and localisation features.
Webflow Ecommerce orders
Customer records, order history, shipping data and payment tokens handed to Stripe or PayPal.
CMS-driven member areas
Webflow user accounts hold authentication data and access levels, which is a different processing purpose from marketing forms.
Third-party embeds
Calendly, Typeform, YouTube, Vimeo and Google Maps embeds each set cookies from their own domain as soon as the embed renders.
Third parties the draft will ask you about
Webflow Inc. · Stripe · PayPal · Google Tag Manager · HubSpot · Intercom · Hotjar · Calendly · Typeform
The rules that apply
Webflow Terms of Service and DPA
Webflow acts as processor for the personal data your site collects, with a published addendum and sub-processor list.
Webflow consent mode
Script-level consent categories via data-wf-consent, which only gate scripts you have actually tagged.
Form submission storage
Submissions are retained in the Webflow dashboard and often forwarded by email or webhook, creating two copies with different retention.
Webflow Ecommerce
Order, customer and payment-token handling through Stripe or PayPal, with its own set of disclosures.
Client hand-over responsibility
Whoever operates the site is the controller. Agency-built tracking does not stay the agency’s legal problem after hand-over.
What the generated cookie policy contains
What the technologies actually are
Cookies, local storage, session storage, pixels, SDKs and server-side tags - the law covers storage and access on a device, not the word "cookie".
A per-cookie table
Name, provider, purpose, category and duration for each cookie, which is the format UK and EU regulators expect to see.
Category definitions
Strictly necessary, functional, analytics and advertising, with an honest explanation of why only the first runs without consent.
How consent was obtained and how to change it
The banner, the granular choices, and a permanent link to reopen preferences - the withdrawal route has to be as easy as the acceptance route.
Third-party cookies and onward use
Which providers set cookies through your site and what they do with the data once it is theirs.
Browser and device controls
Practical instructions, plus a note that blocking strictly necessary cookies will break parts of the service.
Publishing the document on Webflow
Build each document as a static page
Or as a CMS collection if you want to manage several policies with one template. Set the slug to /privacy-policy and similar.
Add the links to the footer symbol
Because it is a symbol, one edit puts the links on every page including new ones.
Audit Site Settings → Custom Code
List every script in the head and body tags. That list is your recipients and cookies disclosure.
Tag scripts for consent
Apply Webflow’s consent attributes or your consent platform’s blocking rules so nothing non-essential loads first.
Set a form retention routine
Decide how long submissions stay in the dashboard, and actually delete them on that schedule.
Set the SEO title and description on each policy page
Webflow does not do this for you, and a policy page with no metadata is a page Google renders badly.
Where this usually goes wrong
Tracking added during the build and never disclosed
The single most common Webflow failure. Site Settings → Custom Code usually holds two or three scripts nobody documented.
Consent banner installed without tagging scripts
A banner that does not carry data-wf-consent attributes or equivalent blocking rules changes nothing about load order.
Form submissions retained forever
Webflow keeps submissions until deleted. A policy promising a retention period that nobody enforces is worse than no promise.
Embeds loading before consent
YouTube, Vimeo, Maps and Calendly set third-party cookies the instant they render, regardless of the banner.
No named controller after agency hand-over
Policies that still name the agency, or name nobody, leave the actual operator undisclosed.
Frequently asked questions
Does Webflow provide a privacy policy?
No. Webflow provides hosting, a data processing addendum for its own role, and consent tooling. The document itself is entirely yours to write and publish.
How do I stop scripts loading before consent on Webflow?
Tag them with Webflow’s consent attributes or manage them through a consent platform that rewrites script types. Adding a banner without doing this leaves load order unchanged.
Who is the controller after an agency builds my site?
You are, once you operate it. The agency may be a processor for build and maintenance work, which is worth putting in a contract, but the public-facing responsibility is yours.
Do Webflow form submissions need a retention period?
Yes. Storage limitation applies to them like any other record, and they sit in the dashboard indefinitely until someone deletes them.
Do I need a cookie policy as well as a privacy policy?
In the UK and EU, yes in practice. PECR and the ePrivacy Directive regulate storing and reading information on a device separately from GDPR’s rules on processing, and the per-cookie disclosure is too detailed to bury in a privacy policy.
Do analytics cookies need consent?
In the UK and EU, yes - the ICO has said repeatedly that analytics is not "strictly necessary". Some EU regulators allow a narrow exemption for first-party, non-shared audience measurement, but the default answer is consent first.
Does a cookie policy need updating when I add a tool?
Yes, and this is the clause that goes stale fastest. Every new tag, pixel or embedded widget adds cookies your table does not list. Scanning your own site on a schedule is the only reliable way to keep it honest.
What about cookies set by embedded video and maps?
They count. An embedded YouTube player or Google Map sets third-party cookies as soon as it loads, so either it loads only after consent, or you use a privacy-preserving embed mode and say so.
Cookie Policy Generator for Webflow
Answer a short questionnaire and get a draft written for a Webflow site. Free to start, no card required.
Generate your cookie policyOther documents a Webflow site needs
Each one is written for the same context, not a generic template.
The same document, by platform
Go deeper
PolicifyAI is a technology provider, not a law firm, and this page is not legal advice. Generated documents are a structured starting point that a qualified adviser should review before you publish or rely on them.