FlowConsent
ServicesBlogExtensionSolutionsPricingTry FlowConsent
FlowConsent

FlowConsent is a GDPR-compliant cookie consent management platform.

Product

  • Services
  • Extension
  • Extension support
  • Solutions
  • Pricing
  • FlowConsent App

Legal

  • Privacy Policy
  • Terms of Service
  • Legal notice

© 2026 FlowConsent by BeBranded. All rights reserved.

FrancaisDeutschEspanol

Does your website use third-party services? Get GDPR compliant in minutes.

Try FlowConsent
  1. Home
  2. Services
  3. Marketing
  4. Formstack

Formstack

MarketingWebsite

Related services

6sense

6sense is a digital marketing technology that helps businesses reach, engage, and convert their target audience online. It provides advanced targeting, campaign management, and performance analytics capabilities. 6sense enables marketers to deliver personalized experiences across channels, optimize campaign ROI, and gain actionable insights into customer behavior. With automation features and data-driven optimization, 6sense empowers marketing teams to achieve measurable growth.

Marketing

ActiveCampaign

ActiveCampaign is a digital marketing technology that helps businesses reach, engage, and convert their target audience online. It provides advanced targeting, campaign management, and performance analytics capabilities. ActiveCampaign enables marketers to deliver personalized experiences across channels, optimize campaign ROI, and gain actionable insights into customer behavior. With automation features and data-driven optimization, ActiveCampaign empowers marketing teams to achieve measurable growth.

Marketing

AddEvent

AddEvent is a foundational web service that powers critical website functions and digital experiences. It provides reliable infrastructure, seamless integration capabilities, and consistent performance across all devices and browsers. AddEvent supports modern development practices and scales with growing business needs. With a focus on stability and compatibility, AddEvent ensures your website delivers a smooth, uninterrupted experience to every visitor and search engine crawler.

Marketing

Airform

Airform is a foundational web service that powers critical website functions and digital experiences. It provides reliable infrastructure, seamless integration capabilities, and consistent performance across all devices and browsers. Airform supports modern development practices and scales with growing business needs. With a focus on stability and compatibility, Airform ensures your website delivers a smooth, uninterrupted experience to every visitor and search engine crawler.

Marketing

Apollo

Apollo is a digital marketing technology that helps businesses reach, engage, and convert their target audience online. It provides advanced targeting, campaign management, and performance analytics capabilities. Apollo enables marketers to deliver personalized experiences across channels, optimize campaign ROI, and gain actionable insights into customer behavior. With automation features and data-driven optimization, Apollo empowers marketing teams to achieve measurable growth.

Marketing
A

Autopilot

Autopilot is a digital marketing technology that helps businesses reach, engage, and convert their target audience online. It provides advanced targeting, campaign management, and performance analytics capabilities. Autopilot enables marketers to deliver personalized experiences across channels, optimize campaign ROI, and gain actionable insights into customer behavior. With automation features and data-driven optimization, Autopilot empowers marketing teams to achieve measurable growth.

Marketing
Get compliant — Try FlowConsent free

Free plan · 10-min setup

What does Formstack do?

Formstack is a web technology service that provides essential functionality for websites and digital platforms. It delivers core capabilities that support site operations, content delivery, and user experience optimization. Formstack integrates seamlessly with modern web architectures, ensuring reliable performance and compatibility across browsers and devices. Trusted by businesses worldwide, Formstack helps organizations maintain robust websites that meet user expectations and technical requirements.

Formstack, founded in 2006 in Indianapolis, has grown from a SaaS form builder into a workplace productivity platform combining online forms, document generation, electronic signature and workflow automation. Used by tens of thousands of businesses including hospitals, banks and universities, it positions itself as a no code alternative to building back office processes.

What Formstack does

Formstack offers four main modules: Forms (drag and drop builder with conditional logic, payments, file uploads), Documents (template based document generation), Sign (electronic signature with full audit trail) and Workflows (multi step approvals). Forms can be embedded as iframe, JavaScript or full page link. Integrations include Salesforce, HubSpot, Stripe, PayPal, Microsoft 365, Workday and Slack.

Data and cookies set

The Formstack embed loads JavaScript from formstack.com and sets third party cookies including ga_session, fs_session, an _ga identifier (when analytics is enabled) and __cf_bm (Cloudflare). Submissions, IP, user agent, referrer and time on form are stored on Formstack servers. The platform offers field level encryption for sensitive data and granular access controls.

GDPR and ePrivacy implications

Formstack acts as a processor under Art. 28 GDPR. Website operators must sign the Formstack DPA, document Formstack as a sub processor and choose the EU data residency option when relevant. The embedded widget sets third party cookies that require prior consent under Art. 5(3) ePrivacy. Formstack is self certified under the EU US Data Privacy Framework.

Get GDPR compliant in 10 minutes

Free plan available · No credit card required

Try FlowConsent free

Data transfers and residency

Standard plans store data in AWS us east 2 (Ohio). Enterprise customers can request the EU Data Region (AWS eu west 1, Dublin). Healthcare customers can request a HIPAA isolated environment with Business Associate Agreement. Transfers to the US rely on the EU US DPF or on Standard Contractual Clauses with supplementary measures.

Practical compliance steps

Block the Formstack widget until consent. Sign the DPA and request EU data residency when handling EU resident data. Enable field level encryption for sensitive fields. Configure retention policies. Add a privacy notice and consent checkbox to every form. Document Formstack as a sub processor in your records of processing and your privacy notice with the US transfer mechanism.

GDPR consent category

Marketing

Websites using Formstack must obtain user consent under GDPR regulations.

Legal basisConsent (Art. 6(1)(a) GDPR and Art. 5(3) ePrivacy Directive) for the third party cookies set by the embedded widget. Performance of a contract (Art. 6(1)(b)) for the submitted data, processed by Formstack as a processor on behalf of the website operator.
Risk levelmedium
Applicable regulationsGDPR, ePrivacy Directive, TDDDG, LSSI CE, CCPA/CPRA, HIPAA, EU US Data Privacy Framework, PCI DSS (payment forms)

Technical details

Tracking methodSaaS form, document and signature platform. Forms are hosted on formstack.com and embedded via iframe or JavaScript snippet. Submissions are stored on Formstack servers; the embedding website only loads the form widget.
Server locationOperated by Formstack LLC, headquartered in Fishers, Indiana, United States. EU customers can opt for the Formstack EU data centre hosted in Dublin (AWS eu west 1). HIPAA workloads run on isolated US healthcare infrastructure.
Data transferred outside the EUBy default, all form data is stored on US servers operated by Formstack LLC. EU residency in Dublin can be enabled on enterprise plans. Transfers from EU to US rely on the EU US Data Privacy Framework (Formstack is certified) or on Standard Contractual Clauses with supplementary measures.

Third-party domains contacted

formstack.comwww.formstack.comcdn.formstack.comsubmit.formstack.io

Cookies placed

NameTypeDurationPurpose
fs_sessionthird_partySessionSession identifier set by formstack.com to track the current form submission state.
ga_sessionthird_partySessionInternal session cookie used by Formstack for form analytics and submission attribution.
_gathird_party2 yearsGoogle Analytics identifier set on formstack.com when Formstack analytics is enabled.
__cf_bmthird_party30 minutesCloudflare bot management cookie used to distinguish humans from bots on formstack.com.

Formstack places tracking cookies for advertising — comply with GDPR using FlowConsent.

Get started freeScan your site

Frequently asked questions

Which cookies does Formstack set?

The embedded Formstack widget sets third party cookies on formstack.com: ga_session, fs_session, _ga (when analytics is enabled) and __cf_bm (Cloudflare). All require prior consent in the EEA except __cf_bm which is often claimed as strictly necessary for bot protection.

Is consent required to use Formstack?

Yes for the embedded widget. The third party cookies require consent under Art. 5(3) ePrivacy. The submission data itself can be processed under Art. 6(1)(b) GDPR (pre contractual) with marketing fields under consent.

What is the legal basis for processing Formstack data?

Contract or pre contractual measures (Art. 6(1)(b)) for contact and quote forms. Consent (Art. 6(1)(a)) for cookies and marketing fields. Healthcare data is processed under HIPAA with a BAA in the US. Sensitive data (Art. 9 GDPR) needs explicit consent.

Is data transferred to the United States?

By default yes. Enterprise customers can activate the EU Data Region (Dublin). Otherwise transfers rely on the EU US Data Privacy Framework (Formstack is certified) or on Standard Contractual Clauses with supplementary measures and a TIA.

Do I need a DPIA for Formstack?

A DPIA is recommended when Formstack collects special categories of data, employee data, financial data or is connected to payments and signatures. The DPIA documents the residency choice, the transfer mechanism, the encryption, and the rights workflow.

How do I implement Formstack correctly?

Block the widget until consent. Sign the DPA. Activate EU Data Region for EU resident data. Enable field level encryption for sensitive fields. Add a privacy notice and consent checkbox. Set retention policies. Document Formstack as a sub processor.

Which alternatives to Formstack should I consider?

EU based SaaS: Tally (Belgium), Typeform (Spain), Formbricks (open source). US SaaS: Jotform (with EU residency), SurveyMonkey, Wufoo. WordPress self hosted: Gravity Forms, WPForms, Ninja Forms, Fluent Forms.

How do I update the cookie policy when Formstack changes?

Track the Formstack sub processor list and trust centre. When sub processors, certifications or residency options change, update your cookie table, privacy notice and records of processing, and bump the consent banner version.