July 2026 · Platform Guide

Privacy Policy for Webflow Sites: Free Generator & Guide

Webflow combines a visual designer, CMS, and hosting platform — and each layer introduces distinct data flows that your privacy policy must address. Webflow sites are hosted on Amazon CloudFront and Fastly, use Webflow's own CMS for structured content, collect data through Webflow Forms stored on Webflow servers, and often run custom JavaScript embeds (analytics, chat widgets, marketing pixels). Plus, if you use Webflow Ecommerce or Webflow Logic, additional data processing applies. Here is exactly what your Webflow privacy policy must cover.

Webflow-Specific Privacy Considerations

1. Webflow Hosting & Infrastructure

All Webflow sites are hosted on Amazon CloudFront (AWS global content delivery network) with Fastly as a secondary CDN layer. This means visitor traffic flows through AWS edge locations worldwide, and AWS infrastructure logs — including IP addresses, request headers, HTTP method, URI, status code, and response size — are collected by default. Webflow also uses Fly.io for server-side compute on certain plans. Your privacy policy must disclose this multi-layered hosting infrastructure and reference the privacy policies of Amazon Web Services, Fastly, and Fly.io as subprocessors.

2. Webflow Forms & User Submissions

Webflow Forms are the primary data collection mechanism on most Webflow sites. When a visitor submits a form, the data is sent directly to Webflow's servers and stored in the Webflow database. Form submissions are also emailed to the site owner via Webflow's email relay. Webflow retains form submission data indefinitely unless you manually delete it from the CMS. Form data is not encrypted at rest on Webflow's servers by default. Your policy must disclose what form data you collect (name, email, phone, message, uploads), that it is stored on Webflow infrastructure, and your data retention practices.

3. Webflow CMS & Dynamic Content

The Webflow CMS powers dynamic content like blog posts, portfolios, job listings, and directories. If your site uses CMS collections to store user-generated content (comments, reviews, listings, member profiles), each collection stores data on Webflow's servers. CMS items include the data you define in your collection fields, plus metadata such as creation date, last updated date, and author/slug references. Your privacy policy must address any CMS collections that contain user data and specify that this data is stored and processed via Webflow's cloud infrastructure.

4. Webflow Ecommerce

Webflow Ecommerce collects customer names, email addresses, shipping addresses, billing addresses, phone numbers, order history, product preferences, and abandoned cart data. Webflow does not process credit card payments directly — payments are handled by Stripe (required) through Stripe.js or Stripe Elements embedded in your checkout page. Stripe receives the payment information; Webflow never stores raw card numbers. Your privacy policy must list Stripe as a payment processor, reference its privacy policy, and disclose what order data Webflow stores (product details, amounts, shipping info, customer contact details).

5. Webflow Integrations & Custom Code Embeds

Webflow allows custom code embeds in the head, body, and footer of every page. This means you can (and likely do) embed third-party scripts that collect data: Google Analytics, Google Ads, Facebook Pixel, HubSpot, Intercom, Hotjar, LinkedIn Insight Tag, TikTok Pixel, Reddit Pixel, and Twitter Ads. Unlike some platforms, Webflow gives you full control over what scripts run — which makes you fully responsible for disclosing each one. Your privacy policy must include a section listing all third-party scripts embedded via custom code and linking to their respective privacy policies.

6. Webflow Cookies & Client-Side Storage

Webflow sets several first-party cookies by default: _webflow_session (session management, essential), _webflow_global (global site preferences), wf_analytics_session (analytics session tracking), wf_analytics_visitor (visitor identification for Webflow's built-in analytics), and wf_visitor_id (anonymous visitor ID). Webflow also uses localStorage in the browser for Designer-related caching and preferences. Beyond Webflow's own cookies, any custom code you add (analytics, pixels, chat widgets) will set its own third-party cookies. Your policy must distinguish between Webflow's essential cookies and optional third-party tracking technologies you have added.

7. Webflow Localization & EU Compliance

Webflow's Localization feature lets you create region-specific site versions, including multilingual content and localized checkout for EU markets. If you use Localization, you may be collecting location-specific data such as preferred language, region-specific pricing preferences, and currency selections. The Localization feature stores visitor locale preferences in a cookie. For EU sites, you must ensure your privacy policy meets GDPR standards including data subject rights (access, rectification, erasure, portability), lawful basis for processing, and international transfer safeguards. Webflow stores all site data on AWS US-based servers by default, so Standard Contractual Clauses (SCCs) or equivalent transfer mechanisms may apply for EU visitors.

8. Webflow Logic & Server-Side Automations

Webflow Logic (formerly Webflow Automate) runs server-side workflows triggered by site events — form submissions, CMS changes, Ecommerce orders, or Stripe webhooks. These workflows can pass data to third-party APIs such as Zapier, Make (formerly Integromat), Airtable, Google Sheets, Slack, Salesforce, and any HTTP API endpoint. If you use Webflow Logic, your privacy policy must disclose that user data may be transmitted to external services via automated workflows and name the specific services you connect to.

Generate Your Webflow Privacy Policy — Free

Select "Privacy Policy", choose "Webflow" as your platform, and list the custom embeds, integrations, and Ecommerce features you use. Instant, platform-specific generation.

Generate Webflow Privacy Policy →