FlowConsent
ServicesBlogExtensionSolutionsPricingTry FlowConsent
FlowConsent

FlowConsent is a GDPR-compliant cookie consent management platform.

Product

  • Services
  • Extension
  • Extension support
  • Solutions
  • Pricing
  • FlowConsent App

Legal

  • Privacy Policy
  • Terms of Service
  • Legal notice

© 2026 FlowConsent by BeBranded. All rights reserved.

FrancaisDeutschEspanol

Does your website use third-party services? Get GDPR compliant in minutes.

Try FlowConsent
  1. Home
  2. Services
  3. CMS
  4. Contentstack

Contentstack

OtherWebsite

Related services

@

@sulu/web

@sulu/web is a foundational web service that powers critical website functions and digital experiences. It provides reliable infrastructure, seamless integration capabilities, and consistent performance across all devices and browsers. @sulu/web supports modern development practices and scales with growing business needs. With a focus on stability and compatibility, @sulu/web ensures your website delivers a smooth, uninterrupted experience to every visitor and search engine crawler.

Other

1C-Bitrix

1C-Bitrix is a web technology service that provides essential functionality for websites and digital platforms. It delivers core capabilities that support site operations, content delivery, and user experience optimization. 1C-Bitrix integrates seamlessly with modern web architectures, ensuring reliable performance and compatibility across browsers and devices. Trusted by businesses worldwide, 1C-Bitrix helps organizations maintain robust websites that meet user expectations and technical requirements.

Other
3

321 CMS

321 CMS is a powerful content management system (CMS) designed to help businesses and developers build, manage, and publish digital content with ease. It offers a flexible architecture that supports custom content types, templates, and workflows, making it ideal for websites of any scale. With 321 CMS, teams can streamline content creation, improve collaboration, and deliver engaging web experiences. Its extensible plugin ecosystem and API-first approach ensure seamless integration with existing tools and services.

Other
6

6Valley eCommerce CMS

6Valley eCommerce CMS is a powerful content management system (CMS) designed to help businesses and developers build, manage, and publish digital content with ease. It offers a flexible architecture that supports custom content types, templates, and workflows, making it ideal for websites of any scale. With 6Valley eCommerce CMS, teams can streamline content creation, improve collaboration, and deliver engaging web experiences. Its extensible plugin ecosystem and API-first approach ensure seamless.

Other

a-blog cms

a-blog cms provides a robust content management platform that enables organizations to create, organize, and distribute web content efficiently. Built with scalability and performance in mind, a-blog cms supports multi-site management, role-based access control, and advanced publishing workflows. Whether running a corporate website or a complex digital portal, a-blog cms delivers the flexibility and reliability needed to manage content at scale while maintaining optimal page load speeds and search engine.

Other

AboutMyClinic

AboutMyClinic is a foundational web service that powers critical website functions and digital experiences. It provides reliable infrastructure, seamless integration capabilities, and consistent performance across all devices and browsers. AboutMyClinic supports modern development practices and scales with growing business needs. With a focus on stability and compatibility, AboutMyClinic ensures your website delivers a smooth, uninterrupted experience to every visitor and search engine crawler.

Other
Get compliant — Try FlowConsent free

Free plan · 10-min setup

What does Contentstack do?

Contentstack is an enterprise headless CMS by Contentstack LLC. The Content Delivery API serves JSON without setting cookies on the visitor, so the public delivery layer is GDPR friendly when the EU stack region is selected. Editor authentication on app.contentstack.com uses strictly necessary session cookies.

What Contentstack is and how it serves content

Contentstack is an enterprise headless content management system founded in 2018 by Contentstack LLC. Editors create entries inside content types using the app.contentstack.com web application. Published entries are served as JSON via the Content Delivery API (cdn.contentstack.io) backed by Akamai. The frontend, written in any framework, fetches JSON server side or via a JavaScript client and renders the HTML. The delivery layer is stateless and does not require any cookie on the visitor browser.

Cookies and identifiers set on visitors

The public Contentstack Content Delivery API does not set cookies on visitors. Editor side, app.contentstack.com sets session, XSRF TOKEN and tracking cookies used to authenticate logged in users and protect against cross site request forgery. The marketing site contentstack.com sets analytics cookies (Google Analytics, HubSpot, LinkedIn Insight Tag) that are scoped to contentstack.com and never reach customer websites that consume the Content Delivery API.

GDPR and ePrivacy implications

Because the public Contentstack delivery does not place identifiers on the visitor terminal, Article 5(3) of the ePrivacy Directive does not require prior consent. Article 6(1)(f) GDPR (legitimate interest) covers the limited request metadata processed at the Akamai edge. Contentstack LLC acts as processor under Article 28 GDPR with a DPA available in the dashboard. The session cookies on app.contentstack.com are strictly necessary and fall outside the consent requirement.

Get GDPR compliant in 10 minutes

Free plan available · No credit card required

Try FlowConsent free

Data transfers and Schrems II

For European projects, create the stack in an EU region (Azure Western Europe or GCP EU). When an EU region is selected, the editorial content and Content Delivery API origin stay inside the EEA. Akamai cache nodes are global, which is acceptable since only the published JSON is cached. The app.contentstack.com application is operated from the US and customer access to it constitutes a transfer covered by Standard Contractual Clauses and the EU US Data Privacy Framework. Brand Studio, Lytics CDP and Personalize add ons may process additional data in the US.

Practical compliance steps

Select an EU stack region at creation since regions cannot be migrated afterwards. Sign the Contentstack DPA and document the processor in your RoPA with region, purpose and DPA reference. Enable SSO and MFA for editor accounts. Use delivery tokens scoped to a single environment for your public frontend, never publish management tokens client side. Govern any third party tracker injected through Contentstack content behind a consent management platform.

GDPR consent category

Other

Websites using Contentstack must obtain user consent under GDPR regulations.

Legal basisArticle 6(1)(f) GDPR (legitimate interest) for content delivery via the Content Delivery API. Strictly necessary cookies are used in app.contentstack.com for editor authentication. No consent required for the public delivery.
Risk levellow
Applicable regulationsGDPR, ePrivacy Directive, DSGVO, RGPD, LSSI, Schrems II, EU US Data Privacy Framework when the US region is selected

DPIA considerations

A DPIA is generally not required for the public Contentstack delivery layer when the EU region is used. It should be considered when Contentstack is integrated with Personalize, Lytics CDP or Brand Studio features, when special category data is stored in entries, or when the US region is used for European visitor flows. Document the region selection, the DPA with Contentstack LLC and access controls on the editor application.

Sample consent text

This website uses Contentstack to deliver editorial content. The Contentstack Content Delivery API does not set cookies on visitors. No consent is required for the public delivery. Authentication cookies only apply to editors logged into app.contentstack.com.

Technical details

Tracking methodEnterprise headless CMS delivered via Content Delivery Network and REST/GraphQL Content APIs over HTTPS. The frontend fetches JSON without setting any cookies on visitors. Editors log into app.contentstack.com which uses session and CSRF cookies for authentication.
Server locationContentstack LLC, headquartered in San Francisco, California. The platform offers multiple data centers including North America (Azure us east, AWS us east 1), Europe (Azure Western Europe / Amsterdam), Australia (Azure Australia East) and the GCP based gcp-na-1 and gcp-eu-1 regions. Akamai CDN serves the content globally.
Cookieless tracking availableYes
Data transferred outside the EUFor European projects, Contentstack offers an EU stack region (Azure Western Europe) and a GCP EU region (gcp-eu-1, Belgium). When these EU regions are selected the stored content and the Content Delivery API stay in the EEA. The corporate app and support tools may still route through the United States. Akamai edge servers are global. Standard Contractual Clauses cover the residual transfers.

Third-party domains contacted

contentstack.comapp.contentstack.comcdn.contentstack.ioeu-cdn.contentstack.comimages.contentstack.ioazure-eu-images.contentstack.com

Cookies placed

NameTypeDurationPurpose
connect.sidfirst-party (app.contentstack.com)SessionEditor session cookie that authenticates a logged in user in the Contentstack web application. Strictly necessary, not set on the public website.
XSRF-TOKENfirst-party (app.contentstack.com)SessionAnti CSRF token used by the Contentstack app to protect state changing requests. Strictly necessary, only present in the editor interface.
_gathird-party (marketing site only)2 yearsGoogle Analytics identifier used on contentstack.com (marketing site). Does not appear on customer websites that consume the Content Delivery API.

This service may collect user data. Ensure GDPR compliance with FlowConsent.

Get started freeScan your site

Frequently asked questions

Does Contentstack set cookies on website visitors?

No. The public Content Delivery API serves JSON without any cookies. Cookies are set on app.contentstack.com (editor application) for session, XSRF protection and tracking, and on contentstack.com (marketing site) for analytics, but neither propagates to customer websites that consume the Content Delivery API.

Do I need consent for Contentstack under GDPR and ePrivacy?

No consent is required for the public delivery because no identifier is stored on the visitor terminal. The strictly necessary editor cookies on app.contentstack.com are exempt under Article 5(3) ePrivacy. Consent only applies to third party trackers embedded in your frontend.

What is the legal basis for processing visitor data with Contentstack?

Article 6(1)(f) GDPR (legitimate interest) covers the limited request metadata processed at the Akamai CDN edge. Contentstack LLC is documented as processor under Article 28 GDPR with a DPA available in the dashboard.

Does Contentstack transfer data to the United States?

Content storage stays in the EEA when an EU stack region is selected (Azure Western Europe or GCP EU). The app.contentstack.com editor application is operated from the US, so accessing it as an editor constitutes a transfer covered by SCCs and the EU US Data Privacy Framework. Brand Studio, Lytics CDP and Personalize add ons can process additional data in the US.

Is a DPIA required for Contentstack?

A DPIA is generally not required for a public editorial deployment when an EU region is used. It should be considered when Contentstack is combined with Personalize, Lytics CDP, large user generated content workflows or when sensitive data is stored in entries.

How do I implement Contentstack compliantly?

Pick an EU stack region at creation, sign the Contentstack DPA, document the processor in your RoPA, enable SSO and MFA for editors, scope delivery tokens to a single environment, never publish management tokens client side and govern third party scripts injected through content via a consent management platform.

What are the alternatives to Contentstack?

Alternatives in the enterprise headless CMS space include Storyblok (Austria), Contentful (Germany), Sanity (Norway), Strapi Cloud Enterprise (France), Sitecore XM Cloud, Adobe Experience Manager and Optimizely Content Cloud.

How do I update the cookie policy for Contentstack?

List Contentstack as a content processor in your privacy policy with the EU stack region, purpose, DPA reference and a note on the US based editor application transfer. The public site does not need Contentstack in the cookie banner because no cookies are placed on visitors.