FlowConsent
ServicesBlogExtensionTry FlowConsent
FlowConsent

FlowConsent is a GDPR-compliant cookie consent management platform.

Product

  • Services
  • Extension
  • FlowConsent App

Legal

  • Privacy Policy
  • Terms of Service

© 2026 BeBranded. All rights reserved.

Francais

Does your website use third-party services? Get GDPR compliant in minutes.

Try FlowConsent
  1. Services
  2. CMS
  3. Webflow
W

Webflow

OtherWebsite

Related services

@

@sulu/web

@sulu/web is a foundational web service that powers critical website functions and digital experiences. It provides reliable infrastructure, seamless integration capabilities, and consistent performance across all devices and browsers. @sulu/web supports modern development practices and scales with growing business needs. With a focus on stability and compatibility, @sulu/web ensures your website delivers a smooth, uninterrupted experience to every visitor and search engine crawler.

Essential

1C-Bitrix

1C-Bitrix is a web technology service that provides essential functionality for websites and digital platforms. It delivers core capabilities that support site operations, content delivery, and user experience optimization. 1C-Bitrix integrates seamlessly with modern web architectures, ensuring reliable performance and compatibility across browsers and devices. Trusted by businesses worldwide, 1C-Bitrix helps organizations maintain robust websites that meet user expectations and technical requirements.

Essential
3

321 CMS

321 CMS is a powerful content management system (CMS) designed to help businesses and developers build, manage, and publish digital content with ease. It offers a flexible architecture that supports custom content types, templates, and workflows, making it ideal for websites of any scale. With 321 CMS, teams can streamline content creation, improve collaboration, and deliver engaging web experiences. Its extensible plugin ecosystem and API-first approach ensure seamless integration with existing tools and services.

Essential
6

6Valley eCommerce CMS

6Valley eCommerce CMS is a powerful content management system (CMS) designed to help businesses and developers build, manage, and publish digital content with ease. It offers a flexible architecture that supports custom content types, templates, and workflows, making it ideal for websites of any scale. With 6Valley eCommerce CMS, teams can streamline content creation, improve collaboration, and deliver engaging web experiences. Its extensible plugin ecosystem and API-first approach ensure seamless.

Essential

a-blog cms

a-blog cms provides a robust content management platform that enables organizations to create, organize, and distribute web content efficiently. Built with scalability and performance in mind, a-blog cms supports multi-site management, role-based access control, and advanced publishing workflows. Whether running a corporate website or a complex digital portal, a-blog cms delivers the flexibility and reliability needed to manage content at scale while maintaining optimal page load speeds and search engine.

Essential

AboutMyClinic

AboutMyClinic is a foundational web service that powers critical website functions and digital experiences. It provides reliable infrastructure, seamless integration capabilities, and consistent performance across all devices and browsers. AboutMyClinic supports modern development practices and scales with growing business needs. With a focus on stability and compatibility, AboutMyClinic ensures your website delivers a smooth, uninterrupted experience to every visitor and search engine crawler.

Essential
Get compliant — Try FlowConsent free

What does Webflow do?

Webflow is a US-based SaaS website builder and managed hosting platform used to design, build, and host websites without writing code. It processes visitor connection data on AWS infrastructure in the United States. As a hosting provider, Webflow acts as a data processor under a Data Processing Addendum. Its own platform cookies are strictly necessary for site functionality; no consent is required for the hosting layer itself.

What is Webflow?

Webflow is a SaaS visual website builder and managed hosting platform founded in 2013 and headquartered in San Francisco, California. It allows designers and developers to build responsive websites using a visual interface that generates clean HTML, CSS, and JavaScript, without requiring manual coding. Webflow also provides a built-in CMS, an e-commerce module, and a Memberships feature for gated content. Hosted sites run on Webflow's managed infrastructure, built on AWS and distributed via the Fastly CDN.

How Webflow processes visitor data

When a visitor accesses a Webflow-hosted site, their HTTP request is handled by Fastly CDN edge nodes globally and routed to AWS us-east-1 origin servers. Webflow processes visitor IP addresses and HTTP request metadata (User-Agent, referrer, request path) in server access logs for security, abuse prevention, and infrastructure reliability purposes. These logs are retained for up to 30 days. Webflow does not use this data for advertising or user profiling. No third-party tracking scripts are injected by Webflow itself; any tracking on the site is added by the operator.

GDPR role and data transfers

Under the GDPR, the operator (the Webflow customer who built the site) is the data controller, and Webflow is the data processor. Webflow provides a Data Processing Addendum (DPA) that governs this relationship and covers international data transfers via Standard Contractual Clauses (SCCs). All infrastructure is located in the United States, which constitutes a restricted transfer under GDPR Chapter V. Operators must reference this transfer in their privacy notice and ensure the Webflow DPA is signed. Webflow does not currently offer EU data residency.

Webflow Memberships and additional data processing

When the Webflow Memberships feature is enabled, Webflow collects and stores member personal data directly: email address, name, password hash, and authentication tokens. This data is stored on Webflow US infrastructure and creates a more direct data processing relationship with end users. Operators using Memberships must explicitly disclose this processing in their privacy notice, ensure members are informed about the US data transfer, and provide appropriate mechanisms for data subject rights (access, deletion, portability). The risk profile of a Memberships-enabled site is higher than a standard static site.

GDPR consent category

Other

Websites using Webflow must obtain user consent under GDPR regulations.

Legal basisContract performance (Art. 6(1)(b) GDPR) and Legitimate interest (Art. 6(1)(f) GDPR)
Risk levelmedium
Applicable regulationsGDPR, ePrivacy Directive, CCPA

DPIA considerations

Webflow is a managed hosting and website building platform, not a tracking or advertising service. Key DPIA considerations: (1) Webflow Inc. is a US company and all visitor connection data (IP addresses, HTTP headers, server logs) is processed on AWS us-east-1 infrastructure in the United States; this constitutes a restricted transfer under GDPR Chapter V, covered by SCCs in the Webflow Data Processing Addendum; (2) Webflow acts as a data processor for the operator, processing data solely according to operator instructions; it does not use visitor data for its own advertising purposes; (3) Webflow server logs retain visitor IP addresses for up to 30 days for security and abuse prevention purposes; operators should account for this in their privacy notice; (4) if Webflow Memberships is enabled, additional personal data is collected and stored (email, name, authentication tokens) and processed in the US; this increases the risk level and may trigger DPIA requirements; (5) Webflow does not offer EU data residency as of 2025; operators with strict EU data localisation requirements should evaluate alternative hosting providers. Overall risk is medium for standard sites and higher for Membership-enabled sites.

Technical details

Tracking methodSaaS website builder and managed hosting (AWS, Fastly CDN)
Server locationUnited States (Webflow Inc., AWS us-east-1 and Fastly CDN global edge nodes)
Data transferred outside the EUWebflow Inc. is a US company headquartered in San Francisco, CA. Website content and visitor connection data are processed on AWS infrastructure in the United States and distributed via Fastly CDN global edge nodes. Data transfers are governed by Standard Contractual Clauses (SCCs) under GDPR Art. 46(2)(c) as detailed in the Webflow Data Processing Addendum.

Third-party domains contacted

webflow.comassets.website-files.comuploads-ssl.webflow.comglobal-uploads.webflow.com

Cookies placed

NameTypeDurationPurpose
__wf_authStrictly NecessarySessionSet only on sites with Webflow Memberships. Stores the authenticated member session token to keep the user logged in across pages.
wf_logoutStrictly NecessarySessionUsed to handle post-logout redirect URLs on Webflow Membership sites. Cleared immediately after the redirect is processed.
AWSALBStrictly Necessary7 daysAWS Application Load Balancer cookie for session stickiness. Routes repeated requests from the same visitor to the same backend server during a session.
AWSALBCORSStrictly Necessary7 daysSame as AWSALB but set with SameSite=None for cross-origin requests. Required for proper load balancer routing in CORS contexts.

This service may collect user data. Ensure GDPR compliance with FlowConsent.

Get started free

Frequently asked questions

  • What is Webflow as a service from a GDPR perspective?

    From a GDPR perspective, Webflow is a managed hosting and website building platform, not a tracking or advertising service. When you use Webflow to host a site, Webflow acts as a data processor on your behalf. It processes visitor connection data (IP addresses, HTTP request metadata) solely for infrastructure and security purposes. Webflow does not inject tracking scripts, does not build visitor profiles, and does not use visitor data for its own advertising. Any tracking on a Webflow-hosted site comes from scripts added by the operator, not from Webflow itself.

  • Does using Webflow mean my visitors' data is transferred to the United States?

    Yes. Webflow Inc. is a US company and all hosted sites run on AWS infrastructure in the United States, distributed via Fastly CDN edge nodes worldwide. Every visitor HTTP request ultimately reaches US-based origin servers, and Webflow retains server logs including IP addresses for up to 30 days. This constitutes a restricted data transfer under GDPR Chapter V. Webflow covers this transfer with a Data Processing Addendum (DPA) including Standard Contractual Clauses (SCCs). Operators must disclose this transfer in their privacy notice.

  • What cookies does Webflow set on my website?

    For standard static sites, Webflow sets no tracking cookies. It may set a small number of strictly necessary technical cookies for specific features: __wf_auth (session duration) is set only on sites with Webflow Memberships enabled, storing the authenticated member session token; wf_logout (session duration) is used to handle post-logout redirects on Membership sites; and AWSALB or similar load balancer cookies may be set transiently by the AWS infrastructure for session stickiness during requests. None of these require user consent as they are strictly necessary for the requested service.

  • Is Webflow GDPR compliant?

    Webflow provides the tools to operate a GDPR-compliant website, but compliance depends on how the operator configures and uses the platform. Webflow itself offers a Data Processing Addendum with SCCs covering US data transfers, retains logs for limited periods, has no advertising purpose, and acts as a data processor. Operators must: sign the Webflow DPA, disclose the US data transfer in their privacy notice, configure any additional analytics or advertising services with appropriate consent management, and handle data subject requests for any personal data Webflow stores on their behalf (particularly for Membership sites).

  • Does Webflow offer EU data residency?

    No. As of 2025, Webflow does not offer a EU data residency option. All hosted sites and associated data are processed on AWS infrastructure in the United States. Operators with strict EU data localisation requirements, such as those in regulated sectors (healthcare, finance, public sector), should evaluate whether Webflow meets their specific compliance obligations or whether an EU-hosted alternative is necessary. Webflow covers the transfer with SCCs, but cannot guarantee that visitor data never leaves the US infrastructure.

  • Is Webflow a data controller or a data processor under GDPR?

    Webflow is a data processor. The operator (the Webflow customer who built and published the site) is the data controller, responsible for determining the purposes and means of processing visitor data. Webflow processes data solely on the operator's behalf and according to their instructions, as described in the Data Processing Addendum. This is a more favourable arrangement for operators than services like Meta Pixel, where Meta acts as an independent data controller for its own purposes. However, operators remain fully responsible for any other services (analytics, advertising, etc.) they add to their Webflow site.

  • Does Webflow have its own built-in analytics and do they require consent?

    Webflow provides basic traffic analytics in the site dashboard, derived from server-side request logs. These are aggregated, do not use cookies, and are not shared with visitors. They do not require visitor consent. For more detailed analytics, operators typically add third-party tools (Google Analytics, Plausible, Fathom, etc.) to their Webflow site, which must be configured with appropriate consent management. Webflow does not bundle any third-party analytics by default.

  • What are the GDPR implications of enabling Webflow Memberships?

    Enabling Webflow Memberships significantly increases the data processing scope. Webflow stores member personal data directly on its US infrastructure: email address, display name, password hash, authentication tokens, and membership status. Operators must: update their privacy notice to disclose this processing and the US data transfer; provide members with data subject rights mechanisms (access, deletion, portability); ensure the Webflow DPA covers this additional processing; and consider whether a DPIA is required given the direct storage of identifiable personal data on a US platform. The risk profile of a Memberships site is materially higher than a standard static site.