GDPR Policy Generator for Webflow
Written for Webflow forms, the CMS, custom code in Site Settings and Webflow’s own consent mode.
On Webflow the GDPR question almost always resolves into two: what is in Site Settings custom code, and how long form submissions sit in the dashboard. Both are answerable in an afternoon, and both are usually unanswered because the person accountable did not build the site.
Webflow sites are usually built by an agency or a freelancer and handed over, which creates a specific compliance gap: the person responsible for the privacy policy is rarely the person who added the tracking. Google Tag Manager, HubSpot, Intercom, Hotjar and a marketing pixel or two typically live in Site Settings → Custom Code, added during the build and never revisited.
Webflow itself is a processor for form submissions and site data, and it publishes a data processing addendum. Its hosting sets a small number of cookies, and Webflow Ecommerce adds order and payment flows through Stripe or PayPal. The platform is comparatively light on default tracking - which means almost everything running on a Webflow site was deliberately added.
Webflow supports a privacy consent mode with data-wf-consent attributes that can gate scripts by category, plus integrations with the main consent platforms. Used properly it blocks tags until consent; unused, every script in the head loads on first paint.
What a GDPR policy for a Webflow site has to cover
A record of processing built from the actual script list, not from an assumed stack
Form submission retention in the Webflow dashboard and in the notification inbox
The Webflow data processing addendum plus terms with every embedded third party
Consent enforcement through Webflow consent attributes or a consent platform
The controller named after agency hand-over, with an accountable person
How a Webflow site actually moves personal data
Form submissions stored in Webflow
Name, email and free-text message retained in the dashboard indefinitely unless you delete them, plus a copy in whichever inbox receives the notification.
Custom code in Site Settings
GTM, ad pixels, heatmaps and chat widgets pasted into the head or body tags. These load site-wide on first paint unless tagged for consent.
Webflow hosting cookies
A small set of platform cookies for hosting and, where enabled, for the Webflow-hosted forms and localisation features.
Webflow Ecommerce orders
Customer records, order history, shipping data and payment tokens handed to Stripe or PayPal.
CMS-driven member areas
Webflow user accounts hold authentication data and access levels, which is a different processing purpose from marketing forms.
Third-party embeds
Calendly, Typeform, YouTube, Vimeo and Google Maps embeds each set cookies from their own domain as soon as the embed renders.
Third parties the draft will ask you about
Webflow Inc. · Stripe · PayPal · Google Tag Manager · HubSpot · Intercom · Hotjar · Calendly · Typeform
The rules that apply
Webflow Terms of Service and DPA
Webflow acts as processor for the personal data your site collects, with a published addendum and sub-processor list.
Webflow consent mode
Script-level consent categories via data-wf-consent, which only gate scripts you have actually tagged.
Form submission storage
Submissions are retained in the Webflow dashboard and often forwarded by email or webhook, creating two copies with different retention.
Webflow Ecommerce
Order, customer and payment-token handling through Stripe or PayPal, with its own set of disclosures.
Client hand-over responsibility
Whoever operates the site is the controller. Agency-built tracking does not stay the agency’s legal problem after hand-over.
What the generated GDPR policy contains
Article 13 and 14 transparency notice
The full disclosure set, split by whether the data came from the person or from somewhere else.
Lawful basis register
Every processing activity mapped to one of the six bases, with the legitimate interests assessment written down where you rely on that basis.
Records of processing (Article 30)
The internal register a supervisory authority can ask for at any time, covering purposes, categories, recipients, transfers and retention.
Data subject rights procedure
How a request arrives, how identity is verified, who handles it, and the one-month clock with its two-month extension.
International transfer mechanism
Adequacy, SCCs with a transfer impact assessment, or the UK IDTA/addendum - named per destination, not asserted in general.
Breach detection and 72-hour notification
The internal escalation path, the assessment test, and the template for notifying the regulator and, where required, the individuals.
Processor and sub-processor controls
Article 28 terms, the sub-processor list, and the change-notification commitment your customers will ask for.
Publishing the document on Webflow
Build each document as a static page
Or as a CMS collection if you want to manage several policies with one template. Set the slug to /privacy-policy and similar.
Add the links to the footer symbol
Because it is a symbol, one edit puts the links on every page including new ones.
Audit Site Settings → Custom Code
List every script in the head and body tags. That list is your recipients and cookies disclosure.
Tag scripts for consent
Apply Webflow’s consent attributes or your consent platform’s blocking rules so nothing non-essential loads first.
Set a form retention routine
Decide how long submissions stay in the dashboard, and actually delete them on that schedule.
Set the SEO title and description on each policy page
Webflow does not do this for you, and a policy page with no metadata is a page Google renders badly.
Where this usually goes wrong
Tracking added during the build and never disclosed
The single most common Webflow failure. Site Settings → Custom Code usually holds two or three scripts nobody documented.
Consent banner installed without tagging scripts
A banner that does not carry data-wf-consent attributes or equivalent blocking rules changes nothing about load order.
Form submissions retained forever
Webflow keeps submissions until deleted. A policy promising a retention period that nobody enforces is worse than no promise.
Embeds loading before consent
YouTube, Vimeo, Maps and Calendly set third-party cookies the instant they render, regardless of the banner.
No named controller after agency hand-over
Policies that still name the agency, or name nobody, leave the actual operator undisclosed.
Frequently asked questions
Does Webflow provide a privacy policy?
No. Webflow provides hosting, a data processing addendum for its own role, and consent tooling. The document itself is entirely yours to write and publish.
How do I stop scripts loading before consent on Webflow?
Tag them with Webflow’s consent attributes or manage them through a consent platform that rewrites script types. Adding a banner without doing this leaves load order unchanged.
Who is the controller after an agency builds my site?
You are, once you operate it. The agency may be a processor for build and maintenance work, which is worth putting in a contract, but the public-facing responsibility is yours.
Do Webflow form submissions need a retention period?
Yes. Storage limitation applies to them like any other record, and they sit in the dashboard indefinitely until someone deletes them.
Does GDPR apply to a business outside the EU?
Yes, where you offer goods or services to people in the EU or monitor their behaviour. Article 3(2) is about where the person is, not where you are - and Article 27 may also require you to appoint an EU representative.
What is the difference between EU GDPR and UK GDPR?
The text is nearly identical, but they are separate laws with separate regulators, separate fine ceilings in different currencies, and separate transfer regimes. A business serving both needs both named, not "GDPR" as shorthand.
Do I need a Data Protection Officer?
Only where your core activities involve large-scale regular monitoring or large-scale special-category data, or you are a public authority. Many businesses do not need one - but if you do not have one, say who is accountable instead.
Is a GDPR policy the same as a privacy policy?
No. The privacy policy is the outward-facing notice. The GDPR policy set is the internal machinery - lawful basis register, ROPA, rights procedure, breach plan - that lets you answer a regulator when they ask how the notice is honoured.
GDPR Policy Generator for Webflow
Answer a short questionnaire and get a draft written for a Webflow site. Free to start, no card required.
Generate your GDPR policyOther documents a Webflow site needs
Each one is written for the same context, not a generic template.
The same document, by platform
Go deeper
PolicifyAI is a technology provider, not a law firm, and this page is not legal advice. Generated documents are a structured starting point that a qualified adviser should review before you publish or rely on them.