Does your website use third-party services? Get GDPR compliant in minutes.
Try FlowConsentFree plan · 10-min setup
Flickity is a front end JavaScript carousel and slider library by Metafizzy. It sets no cookies and collects no personal data, making it a low risk, functional, cookieless interface component.
Flickity is a front end JavaScript carousel and slider library created by Dave DeSandro under the Metafizzy brand. It runs entirely in the visitor browser to power touch friendly, responsive carousels and galleries. Because all of its logic executes on the client side and it stores nothing about the visitor, Flickity is a low risk, functional component from a privacy point of view.
Flickity turns a group of elements into a flickable, swipeable carousel with options such as autoplay, page dots, previous and next buttons, free scrolling and fullscreen. It is delivered as a CSS file and a JavaScript file that you either host on your own server or load from a public content delivery network. The library has no backend service and sends no data to Metafizzy when it runs.
Flickity sets no cookies and writes nothing to local storage or session storage that identifies a visitor. It does not collect names, email addresses, behavioural profiles or any other personal data. The library simply reads the markup already on the page and renders an interactive carousel, so there is no tracking layer to disclose in a cookie banner.
Because Flickity sets no cookies and reads no information from the visitor device, the consent rules of the ePrivacy Directive are not triggered by the library itself. The one nuance under the GDPR appears when you load Flickity from a third party CDN. In that case the visitor browser must request the file from the CDN, which means the visitor IP address and user agent reach the CDN operator. That request is a small data transfer you should be aware of.
Get GDPR compliant in 10 minutes
Free plan available · No credit card required
A self hosted Flickity needs no consent because nothing is stored on the device and no personal data is processed. The appropriate legal basis is legitimate interest under Article 6(1)(f) of the GDPR for providing a functional interface. If you load the library from a non essential third party CDN, some organisations choose to rely on consent for that external request, but most treat a single static asset request as a functional necessity covered by legitimate interest.
The common CDNs for Flickity are jsDelivr, unpkg and cdnjs, and their servers may sit outside the European Union, including in the United States. When the browser fetches the file, the visitor IP address travels to that CDN. This is the only realistic international transfer linked to Flickity, and it disappears the moment you host the files yourself.
To keep things simple, host Flickity on your own domain so no visitor IP leaves your infrastructure. If you prefer a CDN, add a Subresource Integrity hash to the script and style tags so the file cannot be tampered with, and record the CDN in your records of processing activities. Mention the functional carousel in your privacy notice for completeness, and you can leave your cookie policy untouched because the library sets no cookies.
Websites using Flickity must obtain user consent under GDPR regulations.
DPIA considerations
Flickity is a self contained front end library that sets no cookies and processes no personal data, so a dedicated data protection impact assessment is generally not required. The only data flow worth documenting is the visitor IP address sent to a third party CDN when the library is not self hosted. Self hosting removes this transfer entirely.
Sample consent text
Flickity is a functional interface component that displays carousels and sliders without setting cookies or tracking visitors.
Third-party domains contacted
cdn.jsdelivr.netunpkg.comcdnjs.cloudflare.comThis service may collect user data. Ensure GDPR compliance with FlowConsent.
No. Flickity is a front end JavaScript carousel library that sets no cookies and writes nothing identifying to local or session storage. It only renders interactive carousels from existing page markup.
No consent is required for a self hosted Flickity because it stores nothing on the device and processes no personal data. A consent prompt only becomes a consideration if you choose to treat a third party CDN request as non essential.
The legal basis is legitimate interest under Article 6(1)(f) of the GDPR for providing a functional interface component. Consent is only relevant if the library is loaded from a non essential third party CDN.
The library itself transfers nothing. If you load it from a CDN such as jsDelivr, unpkg or cdnjs, the visitor browser sends its IP address to that CDN, whose servers may be in the United States or elsewhere outside the EU.
A dedicated data protection impact assessment is generally not needed because Flickity sets no cookies and processes no personal data. The only point worth documenting is the visitor IP sent to a CDN when the library is not self hosted.
Host the CSS and JavaScript on your own domain so no visitor IP leaves your infrastructure. If you use a CDN, add a Subresource Integrity hash to the tags and record the CDN in your records of processing activities.
Comparable carousel libraries include Swiper, Splide and Glide. Like Flickity, they are front end libraries that set no cookies when self hosted, so the same CDN considerations apply if you load them externally.
You do not need to add a cookie entry because Flickity sets no cookies. If you load it from a CDN, mention the functional carousel and the CDN transfer in your privacy notice rather than in the cookie policy.