Privacy Policy Generator for Webflow
Written for Webflow forms, the CMS, custom code in Site Settings and Webflow’s own consent mode.
On Webflow, almost every tracker was added deliberately by whoever built the site - which means the privacy policy is really a disclosure of decisions made during the build. Getting it right starts with reading Site Settings → Custom Code, not with a template.
Webflow sites are usually built by an agency or a freelancer and handed over, which creates a specific compliance gap: the person responsible for the privacy policy is rarely the person who added the tracking. Google Tag Manager, HubSpot, Intercom, Hotjar and a marketing pixel or two typically live in Site Settings → Custom Code, added during the build and never revisited.
Webflow itself is a processor for form submissions and site data, and it publishes a data processing addendum. Its hosting sets a small number of cookies, and Webflow Ecommerce adds order and payment flows through Stripe or PayPal. The platform is comparatively light on default tracking - which means almost everything running on a Webflow site was deliberately added.
Webflow supports a privacy consent mode with data-wf-consent attributes that can gate scripts by category, plus integrations with the main consent platforms. Used properly it blocks tags until consent; unused, every script in the head loads on first paint.
What a privacy policy for a Webflow site has to cover
Webflow Inc. as processor, with hosting locations and the data processing addendum referenced
Every script in Site Settings → Custom Code, named as a recipient with its purpose
Form submission storage: what is kept in the Webflow dashboard, where the notification copy goes, and for how long
Webflow Ecommerce order and payment flows where enabled, including the Stripe or PayPal hand-off
Member area authentication data where Webflow user accounts are in use
How a Webflow site actually moves personal data
Form submissions stored in Webflow
Name, email and free-text message retained in the dashboard indefinitely unless you delete them, plus a copy in whichever inbox receives the notification.
Custom code in Site Settings
GTM, ad pixels, heatmaps and chat widgets pasted into the head or body tags. These load site-wide on first paint unless tagged for consent.
Webflow hosting cookies
A small set of platform cookies for hosting and, where enabled, for the Webflow-hosted forms and localisation features.
Webflow Ecommerce orders
Customer records, order history, shipping data and payment tokens handed to Stripe or PayPal.
CMS-driven member areas
Webflow user accounts hold authentication data and access levels, which is a different processing purpose from marketing forms.
Third-party embeds
Calendly, Typeform, YouTube, Vimeo and Google Maps embeds each set cookies from their own domain as soon as the embed renders.
Third parties the draft will ask you about
Webflow Inc. · Stripe · PayPal · Google Tag Manager · HubSpot · Intercom · Hotjar · Calendly · Typeform
The rules that apply
Webflow Terms of Service and DPA
Webflow acts as processor for the personal data your site collects, with a published addendum and sub-processor list.
Webflow consent mode
Script-level consent categories via data-wf-consent, which only gate scripts you have actually tagged.
Form submission storage
Submissions are retained in the Webflow dashboard and often forwarded by email or webhook, creating two copies with different retention.
Webflow Ecommerce
Order, customer and payment-token handling through Stripe or PayPal, with its own set of disclosures.
Client hand-over responsibility
Whoever operates the site is the controller. Agency-built tracking does not stay the agency’s legal problem after hand-over.
What the generated privacy policy contains
Identity and contact details of the controller
Your legal entity, trading name, registered address and a working contact route - plus a representative or DPO where one is required.
Categories of personal data and their sources
What you collect directly, what you observe automatically, and what you receive from third parties such as payment providers or ad platforms.
Purposes and lawful basis, purpose by purpose
A table that pairs each processing purpose with its lawful basis rather than listing all six bases and hoping one fits.
Recipients and sub-processors
The categories of recipient, and for the ones that matter to users - payment, hosting, analytics, support - the named provider.
International transfers and their safeguards
Where data leaves its home jurisdiction, and the mechanism relied on: adequacy, standard contractual clauses, the UK addendum or IDTA.
Retention periods per data category
Concrete periods or the criteria used to set them, which is what regulators ask for first when a complaint lands.
Rights and how to exercise them
Access, rectification, erasure, portability, objection and restriction, with the actual route to make a request and the deadline you work to.
Complaints and supervisory authority
The regulator a user can escalate to, named, with a link - not a generic "your local authority".
Publishing the document on Webflow
Build each document as a static page
Or as a CMS collection if you want to manage several policies with one template. Set the slug to /privacy-policy and similar.
Add the links to the footer symbol
Because it is a symbol, one edit puts the links on every page including new ones.
Audit Site Settings → Custom Code
List every script in the head and body tags. That list is your recipients and cookies disclosure.
Tag scripts for consent
Apply Webflow’s consent attributes or your consent platform’s blocking rules so nothing non-essential loads first.
Set a form retention routine
Decide how long submissions stay in the dashboard, and actually delete them on that schedule.
Set the SEO title and description on each policy page
Webflow does not do this for you, and a policy page with no metadata is a page Google renders badly.
Where this usually goes wrong
Tracking added during the build and never disclosed
The single most common Webflow failure. Site Settings → Custom Code usually holds two or three scripts nobody documented.
Consent banner installed without tagging scripts
A banner that does not carry data-wf-consent attributes or equivalent blocking rules changes nothing about load order.
Form submissions retained forever
Webflow keeps submissions until deleted. A policy promising a retention period that nobody enforces is worse than no promise.
Embeds loading before consent
YouTube, Vimeo, Maps and Calendly set third-party cookies the instant they render, regardless of the banner.
No named controller after agency hand-over
Policies that still name the agency, or name nobody, leave the actual operator undisclosed.
Frequently asked questions
Does Webflow provide a privacy policy?
No. Webflow provides hosting, a data processing addendum for its own role, and consent tooling. The document itself is entirely yours to write and publish.
How do I stop scripts loading before consent on Webflow?
Tag them with Webflow’s consent attributes or manage them through a consent platform that rewrites script types. Adding a banner without doing this leaves load order unchanged.
Who is the controller after an agency builds my site?
You are, once you operate it. The agency may be a processor for build and maintenance work, which is worth putting in a contract, but the public-facing responsibility is yours.
Do Webflow form submissions need a retention period?
Yes. Storage limitation applies to them like any other record, and they sit in the dashboard indefinitely until someone deletes them.
Is a privacy policy legally required?
If you process personal data, in almost every market yes. GDPR and UK GDPR require the disclosure at the point of collection, CCPA/CPRA requires a notice at collection plus an annually reviewed policy, and app stores and payment processors require a public policy URL before they will list or onboard you.
Can I copy another company’s privacy policy?
It is both a copyright problem and a compliance problem. A copied policy describes someone else’s data flows, processors and retention periods, so it is inaccurate the moment you publish it - and an inaccurate transparency notice is itself a breach of GDPR Article 13.
How often does a privacy policy need updating?
Whenever your processing changes - a new analytics tool, a new payment provider, a new market - and as a backstop, review it annually. CPRA makes the twelve-month review explicit.
Does PolicifyAI give legal advice?
No. PolicifyAI is a technology provider, not a law firm. The output is a structured, jurisdiction-aware draft that a qualified adviser should review before you rely on it.
Privacy Policy Generator for Webflow
Answer a short questionnaire and get a draft written for a Webflow site. Free to start, no card required.
Generate your privacy policyOther documents a Webflow site needs
Each one is written for the same context, not a generic template.
The same document, by platform
Go deeper
PolicifyAI is a technology provider, not a law firm, and this page is not legal advice. Generated documents are a structured starting point that a qualified adviser should review before you publish or rely on them.