FlowConsent
ServicesHow it worksPricingBlogDocumentation
ServicesHow it worksPricingBlogDocumentationLog inTry FlowConsent
Log inTry FlowConsent
FlowConsent

GDPR-compliant consent, EU-hosted, live in under ten minutes — without a cookie wall.

EU-HOSTED·RGPD·SOC 2
Product
  • Services
  • How it works
  • Pricing
  • Extension
Company
  • Blog
  • Documentation
  • Solutions
  • FlowConsent App
Legal
  • Privacy Policy
  • Terms of Service
  • Legal notice
  • Cookies
© 2026 FlowConsent by BeBranded. All rights reserved.
FrancaisDeutschEspanol
All systems operational

Does your website use third-party services? Get GDPR compliant in minutes.

Try FlowConsent
  1. Home
  2. Services
  3. CDN
  4. StackPath

StackPath

OtherWebsite

Related services

5centsCDN

5centsCDN is a web technology service that provides essential functionality for websites and digital platforms. It delivers core capabilities that support site operations, content delivery, and user experience optimization. 5centsCDN integrates seamlessly with modern web architectures, ensuring reliable performance and compatibility across browsers and devices. Trusted by businesses worldwide, 5centsCDN helps organizations maintain robust websites that meet user expectations and technical requirements.

Other
A

Acquia Cloud Platform CDN

Acquia Cloud Platform CDN is a content delivery network (CDN) that accelerates website performance by distributing content across a global network of edge servers. It reduces latency, improves page load times, and handles traffic spikes by serving cached content from the nearest location. Acquia Cloud Platform CDN supports static and dynamic content acceleration, DDoS protection, and SSL/TLS encryption. With real-time analytics and purge capabilities, Acquia Cloud Platform CDN ensures fast, reliable delivery.

Other

Airee

Airee is a foundational web service that powers critical website functions and digital experiences. It provides reliable infrastructure, seamless integration capabilities, and consistent performance across all devices and browsers. Airee supports modern development practices and scales with growing business needs. With a focus on stability and compatibility, Airee ensures your website delivers a smooth, uninterrupted experience to every visitor and search engine crawler.

Other
A

Akamai

Akamai is a versatile web technology that supports digital platforms with specialized functionality and enhanced capabilities. It provides robust tools and services that integrate with modern websites and applications seamlessly. Akamai is designed to improve operational efficiency, user experience, and digital performance. Trusted by developers and businesses alike, Akamai offers reliable solutions that scale with organizational needs and evolving web standards.

Other
A

Akamai Connected Cloud

Akamai Connected Cloud is a web hosting and cloud infrastructure provider delivering reliable, scalable hosting solutions for websites and applications of all sizes. It offers shared, VPS, and dedicated server options with SSD storage, global CDN, and automated backups. Akamai Connected Cloud provides one-click deployment, managed databases, and 24/7 monitoring. With high uptime guarantees and developer-friendly tools, Akamai Connected Cloud ensures optimal performance at scale.

Other
A

Akamai mPulse

Akamai mPulse is a digital marketing technology that helps businesses reach, engage, and convert their target audience online. It provides advanced targeting, campaign management, and performance analytics capabilities. Akamai mPulse enables marketers to deliver personalized experiences across channels, optimize campaign ROI, and gain actionable insights into customer behavior. With automation features and data-driven optimization, Akamai mPulse empowers marketing teams to achieve measurable growth.

Other
Get compliant — Try FlowConsent free

Free plan · 10-min setup

What does StackPath do?

StackPath was a content delivery network and edge platform that offered a web application firewall and bot protection to speed up and secure websites. It set first party security and load balancing cookies, mainly when a request triggered a challenge such as a captcha. Importantly, StackPath wound down its CDN and WAF in November 2023 and ceased all operations in 2024, with Akamai and Gcore acquiring parts of its technology. This guide is provided for reference and to help operators who still need to remove it and migrate to an active provider.

What StackPath Was

StackPath was a content delivery network and edge platform that helped websites load faster and stay protected by serving content from points of presence close to the visitor. Alongside caching it offered a web application firewall and bot protection that inspected requests at the edge and could block, rate limit or challenge suspicious traffic. It is important to state the current status plainly, because StackPath wound down its CDN and legacy Highwinds CDN in November 2023, discontinued its WAF at the same time, and ceased all operations in 2024. Akamai acquired select CDN assets and Gcore acquired the web application and API protection technology, but the StackPath service itself is no longer available. This page therefore serves as reference material and as guidance for operators who still need to remove StackPath and move to a supported provider. Treating it as a live integration would be inaccurate.

Cookies and Data Collected

While it operated, the StackPath web application firewall could set a range of first party cookies, mostly in scenarios such as a captcha or JavaScript challenge or when load balancing was applied. Documented WAF cookies included names such as sp_lit, sbtsck, SPC, SPLB, cnfc, pvstr, DGCC and similar values used for handshake, challenge and routing purposes. The sbtsck cookie, for example, was associated with captcha and handshake handling and was typically short lived. As a CDN and edge security layer, StackPath also processed request metadata such as IP address, user agent and request headers to apply its security rules. These values can constitute personal data because they can identify or single out a visitor. Since the service has shut down, no new cookies are set, but legacy references should be cleaned up.

GDPR and ePrivacy Implications

When StackPath was in use the request metadata and security cookies it handled were personal data under the GDPR, and StackPath acted as a processor for the website operator who remained the controller. Content delivery and network security are recognised legitimate interests under Article 6(1)(f), so that basis could support the processing provided a balancing test was documented. The ePrivacy Directive applied separately to the cookies, since storing and reading information on a device generally needs consent unless it is strictly necessary for a service the user explicitly requested. Strictly necessary security and load balancing cookies are often treated as exempt, while anything broader needs consent. Because the service has ended, the live ePrivacy question is largely moot for StackPath itself, but the same analysis must now be carried out for whatever replacement provider has taken over the role.

Get GDPR compliant in 10 minutes

Free plan available · No credit card required

Try FlowConsent free

Consent Requirements and CMP Integration

Historically many operators classified the StackPath security and load balancing cookies as strictly necessary and loaded them without prior consent, on the basis that they protected and delivered the requested site. That position was only sound where the cookies were genuinely limited to security and routing and not reused for other purposes. With the service discontinued the practical task is different, because your consent management platform should no longer list StackPath as an active vendor. You should remove StackPath entries from your cookie banner and cookie inventory, and add the replacement provider with an accurate classification. If any StackPath cookies are still being served by stale configuration, treat that as a defect to fix rather than a category to keep.

International Data Transfers

StackPath was a United States company based in Dallas, Texas, and ran a global edge network, so traffic from European visitors could be processed in the United States and at edge locations in other regions. Transfers to the United States during its operation would have needed an appropriate mechanism such as Standard Contractual Clauses or, later, the EU US Data Privacy Framework. Because the service has shut down, the live transfer question now attaches to the replacement provider rather than to StackPath. As the controller you should update your records of processing to remove StackPath, confirm the transfer mechanism for the new provider, and run a transfer impact assessment for that provider where your risk approach requires one. Keeping clear records of this transition helps demonstrate accountability.

Practical Compliance Steps

Start by confirming whether StackPath is still referenced anywhere in your stack, including DNS records, CNAME entries, edge configuration and tag managers. Migrate to a supported content delivery and security provider such as Akamai, Cloudflare, Fastly or Gcore, and validate that traffic now routes correctly. Remove StackPath cookies, scripts and vendor entries from your cookie banner, cookie policy and records of processing. Carry out a fresh legitimate interest assessment and, where needed, a transfer impact assessment for the new provider, and sign its data processing agreement. Update your privacy notice and cookie policy to reflect the current provider rather than StackPath. Finally, monitor for any residual StackPath cookies and remove them so your published documentation matches reality.

GDPR consent category

Other

Websites using StackPath must obtain user consent under GDPR regulations.

Legal basisLegitimate Interest (GDPR Article 6(1)(f)) for content delivery, network security and bot mitigation, supported by a documented Legitimate Interest Assessment. Consent (Article 6(1)(a)) may be required under the ePrivacy Directive where security or load balancing cookies go beyond what is strictly necessary for the requested service.
Risk levelmedium
Applicable regulationsGDPR, ePrivacy Directive, CNIL guidelines, TTDSG (Germany), LOPDGDD (Spain), EU US Data Privacy Framework

DPIA considerations

Because StackPath has been discontinued, the most pressing data protection task is migration rather than ongoing assessment. Where the service was still referenced, a focused review should confirm that StackPath cookies and DNS or edge configuration have been fully removed and that traffic now flows through a supported provider. For the active replacement, a Data Protection Impact Assessment may be appropriate where it applies large scale bot mitigation or behavioural analysis, covering necessity, retention and international transfers. Historic records of processing should be updated to reflect that StackPath is no longer a processor.

Sample consent text

This site previously used the StackPath content delivery network and web application firewall, which could set security cookies on your device to protect and speed up the site. StackPath has been discontinued, so please refer to the current provider listed in this notice.

Technical details

Tracking methodContent delivery network and edge WAF that set first party security and load balancing cookies when challenges or bot protection were triggered, with behavioural analysis applied at the edge. The service has been discontinued, so this describes how it operated.
Server locationUnited States (StackPath, LLC, Dallas, Texas) with a former global network of edge points of presence across North America, Europe, Asia and Australia. The company ceased operations in 2024.
Data transferred outside the EUStackPath was a United States company and processed traffic at a global edge network, so data could be processed in the United States and other regions. As the service has shut down, operators should migrate to an active provider and assess transfers for that replacement.

Third-party domains contacted

stackpathcdn.comstackpathdns.comstackpath.comhwcdn.net

Cookies placed

NameTypeDurationPurpose
sp_litfirst party securitySession to short livedSet by the StackPath web application firewall during security checks to help verify the visitor and apply protection rules. Set only when the service was active.
sbtsckfirst party securityApproximately 1 dayAssociated with captcha and handshake handling in the StackPath WAF to confirm a visitor passed a challenge.
SPLBfirst party functionalSessionLoad balancing cookie used by the StackPath edge to route a visitor consistently to a backend during their session.
SPCfirst party securitySession to short livedStackPath WAF cookie used as part of bot protection and request validation when a security action was triggered.

This service may collect user data. Ensure GDPR compliance with FlowConsent.

Get started freeScan your site

Frequently asked questions

What cookies did StackPath set?

While it operated, the StackPath web application firewall could set first party cookies such as sp_lit, sbtsck, SPC, SPLB, cnfc and pvstr, mainly during captcha or JavaScript challenges and for load balancing. The sbtsck cookie was tied to captcha and handshake handling and was usually short lived. Because StackPath has shut down, no new cookies are set, but old ones should be removed from stale configuration.

Was consent required to use StackPath?

When StackPath ran, operators often treated the security and load balancing cookies as strictly necessary under the ePrivacy exemption and loaded them without consent, provided they were limited to security and routing. Anything broader needed consent. Since the service is discontinued, the live task is to remove StackPath from your consent banner and assess the replacement provider instead.

What was the legal basis for StackPath?

Content delivery and network security are recognised legitimate interests under Article 6(1)(f), which usually supported StackPath processing with a documented balancing test. The ePrivacy Directive separately governed the cookies. StackPath acted as a processor for the website operator, who remained the controller.

Did StackPath transfer data to the United States?

Yes. StackPath was a United States company based in Dallas and ran a global edge network, so European traffic could be processed in the United States and other regions. Those transfers needed a mechanism such as Standard Contractual Clauses or the EU US Data Privacy Framework. The transfer question now applies to your replacement provider.

Is a DPIA needed for StackPath?

Because StackPath has been discontinued, the priority is migration rather than a fresh assessment of the dead service. A focused check should confirm StackPath has been fully removed. A Data Protection Impact Assessment may be appropriate for the active replacement where it applies large scale bot mitigation or behavioural analysis.

How do I implement compliance now that StackPath has shut down?

Confirm StackPath is no longer referenced in DNS, CNAME records, edge configuration or tag managers, then migrate to a supported provider such as Akamai, Cloudflare, Fastly or Gcore. Remove StackPath cookies and vendor entries from your cookie banner and records of processing, and document the replacement with its own legal basis and transfer mechanism.

What are the alternatives to StackPath?

Following the shutdown, common alternatives include Akamai, which acquired StackPath CDN assets, Cloudflare, Fastly and Gcore, which acquired the StackPath web application and API protection technology. Choose based on your performance, security, hosting region and data residency needs.

How do I update my cookie policy after StackPath?

Remove the StackPath cookies and vendor description from your cookie policy and replace them with the current provider. List the new provider security cookies, their purpose and duration, and note where data is processed and the transfer mechanism. Then check that no residual StackPath cookies remain so the policy is accurate.