By platform

GDPR Policy Generator for Webflow

Written for Webflow forms, the CMS, custom code in Site Settings and Webflow’s own consent mode.

Generate your GDPR policy Read the GDPR policy guide

On Webflow the GDPR question almost always resolves into two: what is in Site Settings custom code, and how long form submissions sit in the dashboard. Both are answerable in an afternoon, and both are usually unanswered because the person accountable did not build the site.

Webflow sites are usually built by an agency or a freelancer and handed over, which creates a specific compliance gap: the person responsible for the privacy policy is rarely the person who added the tracking. Google Tag Manager, HubSpot, Intercom, Hotjar and a marketing pixel or two typically live in Site Settings → Custom Code, added during the build and never revisited.

Webflow itself is a processor for form submissions and site data, and it publishes a data processing addendum. Its hosting sets a small number of cookies, and Webflow Ecommerce adds order and payment flows through Stripe or PayPal. The platform is comparatively light on default tracking - which means almost everything running on a Webflow site was deliberately added.

Webflow supports a privacy consent mode with data-wf-consent attributes that can gate scripts by category, plus integrations with the main consent platforms. Used properly it blocks tags until consent; unused, every script in the head loads on first paint.

What a GDPR policy for a Webflow site has to cover

How a Webflow site actually moves personal data

Form submissions stored in Webflow

Name, email and free-text message retained in the dashboard indefinitely unless you delete them, plus a copy in whichever inbox receives the notification.

Custom code in Site Settings

GTM, ad pixels, heatmaps and chat widgets pasted into the head or body tags. These load site-wide on first paint unless tagged for consent.

Webflow hosting cookies

A small set of platform cookies for hosting and, where enabled, for the Webflow-hosted forms and localisation features.

Webflow Ecommerce orders

Customer records, order history, shipping data and payment tokens handed to Stripe or PayPal.

CMS-driven member areas

Webflow user accounts hold authentication data and access levels, which is a different processing purpose from marketing forms.

Third-party embeds

Calendly, Typeform, YouTube, Vimeo and Google Maps embeds each set cookies from their own domain as soon as the embed renders.

Third parties the draft will ask you about

Webflow Inc. · Stripe · PayPal · Google Tag Manager · HubSpot · Intercom · Hotjar · Calendly · Typeform

The rules that apply

Webflow Terms of Service and DPA

Webflow acts as processor for the personal data your site collects, with a published addendum and sub-processor list.

Webflow consent mode

Script-level consent categories via data-wf-consent, which only gate scripts you have actually tagged.

Form submission storage

Submissions are retained in the Webflow dashboard and often forwarded by email or webhook, creating two copies with different retention.

Webflow Ecommerce

Order, customer and payment-token handling through Stripe or PayPal, with its own set of disclosures.

Client hand-over responsibility

Whoever operates the site is the controller. Agency-built tracking does not stay the agency’s legal problem after hand-over.

What the generated GDPR policy contains

Publishing the document on Webflow

  1. Build each document as a static page

    Or as a CMS collection if you want to manage several policies with one template. Set the slug to /privacy-policy and similar.

  2. Add the links to the footer symbol

    Because it is a symbol, one edit puts the links on every page including new ones.

  3. Audit Site Settings → Custom Code

    List every script in the head and body tags. That list is your recipients and cookies disclosure.

  4. Tag scripts for consent

    Apply Webflow’s consent attributes or your consent platform’s blocking rules so nothing non-essential loads first.

  5. Set a form retention routine

    Decide how long submissions stay in the dashboard, and actually delete them on that schedule.

  6. Set the SEO title and description on each policy page

    Webflow does not do this for you, and a policy page with no metadata is a page Google renders badly.

Where this usually goes wrong

Tracking added during the build and never disclosed

The single most common Webflow failure. Site Settings → Custom Code usually holds two or three scripts nobody documented.

Consent banner installed without tagging scripts

A banner that does not carry data-wf-consent attributes or equivalent blocking rules changes nothing about load order.

Form submissions retained forever

Webflow keeps submissions until deleted. A policy promising a retention period that nobody enforces is worse than no promise.

Embeds loading before consent

YouTube, Vimeo, Maps and Calendly set third-party cookies the instant they render, regardless of the banner.

No named controller after agency hand-over

Policies that still name the agency, or name nobody, leave the actual operator undisclosed.

Frequently asked questions

Does Webflow provide a privacy policy?

No. Webflow provides hosting, a data processing addendum for its own role, and consent tooling. The document itself is entirely yours to write and publish.

How do I stop scripts loading before consent on Webflow?

Tag them with Webflow’s consent attributes or manage them through a consent platform that rewrites script types. Adding a banner without doing this leaves load order unchanged.

Who is the controller after an agency builds my site?

You are, once you operate it. The agency may be a processor for build and maintenance work, which is worth putting in a contract, but the public-facing responsibility is yours.

Do Webflow form submissions need a retention period?

Yes. Storage limitation applies to them like any other record, and they sit in the dashboard indefinitely until someone deletes them.

Does GDPR apply to a business outside the EU?

Yes, where you offer goods or services to people in the EU or monitor their behaviour. Article 3(2) is about where the person is, not where you are - and Article 27 may also require you to appoint an EU representative.

What is the difference between EU GDPR and UK GDPR?

The text is nearly identical, but they are separate laws with separate regulators, separate fine ceilings in different currencies, and separate transfer regimes. A business serving both needs both named, not "GDPR" as shorthand.

Do I need a Data Protection Officer?

Only where your core activities involve large-scale regular monitoring or large-scale special-category data, or you are a public authority. Many businesses do not need one - but if you do not have one, say who is accountable instead.

Is a GDPR policy the same as a privacy policy?

No. The privacy policy is the outward-facing notice. The GDPR policy set is the internal machinery - lawful basis register, ROPA, rights procedure, breach plan - that lets you answer a regulator when they ask how the notice is honoured.

GDPR Policy Generator for Webflow

Answer a short questionnaire and get a draft written for a Webflow site. Free to start, no card required.

Generate your GDPR policy

Other documents a Webflow site needs

Each one is written for the same context, not a generic template.

The same document, by platform

Go deeper

PolicifyAI is a technology provider, not a law firm, and this page is not legal advice. Generated documents are a structured starting point that a qualified adviser should review before you publish or rely on them.