FlowConsent
ServicesBlogExtensionSolutionsPricingTry FlowConsent
FlowConsent

FlowConsent is a GDPR-compliant cookie consent management platform.

Product

  • Services
  • Extension
  • Extension support
  • Solutions
  • Pricing
  • FlowConsent App

Legal

  • Privacy Policy
  • Terms of Service
  • Legal notice

© 2026 FlowConsent by BeBranded. All rights reserved.

FrancaisDeutschEspanol

Does your website use third-party services? Get GDPR compliant in minutes.

Try FlowConsent
  1. Home
  2. Services
  3. Marketing
  4. Jotform

Jotform

MarketingWebsite

Related services

6sense

6sense is a digital marketing technology that helps businesses reach, engage, and convert their target audience online. It provides advanced targeting, campaign management, and performance analytics capabilities. 6sense enables marketers to deliver personalized experiences across channels, optimize campaign ROI, and gain actionable insights into customer behavior. With automation features and data-driven optimization, 6sense empowers marketing teams to achieve measurable growth.

Marketing

ActiveCampaign

ActiveCampaign is a digital marketing technology that helps businesses reach, engage, and convert their target audience online. It provides advanced targeting, campaign management, and performance analytics capabilities. ActiveCampaign enables marketers to deliver personalized experiences across channels, optimize campaign ROI, and gain actionable insights into customer behavior. With automation features and data-driven optimization, ActiveCampaign empowers marketing teams to achieve measurable growth.

Marketing

AddEvent

AddEvent is a foundational web service that powers critical website functions and digital experiences. It provides reliable infrastructure, seamless integration capabilities, and consistent performance across all devices and browsers. AddEvent supports modern development practices and scales with growing business needs. With a focus on stability and compatibility, AddEvent ensures your website delivers a smooth, uninterrupted experience to every visitor and search engine crawler.

Marketing

Airform

Airform is a foundational web service that powers critical website functions and digital experiences. It provides reliable infrastructure, seamless integration capabilities, and consistent performance across all devices and browsers. Airform supports modern development practices and scales with growing business needs. With a focus on stability and compatibility, Airform ensures your website delivers a smooth, uninterrupted experience to every visitor and search engine crawler.

Marketing

Apollo

Apollo is a digital marketing technology that helps businesses reach, engage, and convert their target audience online. It provides advanced targeting, campaign management, and performance analytics capabilities. Apollo enables marketers to deliver personalized experiences across channels, optimize campaign ROI, and gain actionable insights into customer behavior. With automation features and data-driven optimization, Apollo empowers marketing teams to achieve measurable growth.

Marketing
A

Autopilot

Autopilot is a digital marketing technology that helps businesses reach, engage, and convert their target audience online. It provides advanced targeting, campaign management, and performance analytics capabilities. Autopilot enables marketers to deliver personalized experiences across channels, optimize campaign ROI, and gain actionable insights into customer behavior. With automation features and data-driven optimization, Autopilot empowers marketing teams to achieve measurable growth.

Marketing
Get compliant — Try FlowConsent free

Free plan · 10-min setup

What does Jotform do?

Jotform is a foundational web service that powers critical website functions and digital experiences. It provides reliable infrastructure, seamless integration capabilities, and consistent performance across all devices and browsers. Jotform supports modern development practices and scales with growing business needs. With a focus on stability and compatibility, Jotform ensures your website delivers a smooth, uninterrupted experience to every visitor and search engine crawler.

Jotform, founded in 2006 by Aytekin Tank in San Francisco, is one of the largest SaaS form builders with more than 25 million users. Forms are created and hosted on jotform.com and embedded into customer websites via iframe or a lightweight JavaScript widget. Submissions are processed and stored by Jotform on behalf of the website operator.

What Jotform does

Jotform offers a drag and drop builder, more than ten thousand templates, conditional logic, payments (Stripe, PayPal, Square, Authorize.Net), e signature, file uploads, approval workflows, PDF generation and a REST API. Forms can be embedded as iframe, JavaScript widget, full page or distributed as link, QR code or kiosk. The service also includes HIPAA, GDPR, PCI DSS Level 1 and SOC 2 Type II compliance options.

Data and cookies set

The embedded widget loads JavaScript from cdn.jotfor.ms and posts to api.jotform.com. Cookies set on the jotform.com third party context include JOTFORM_SESSION, JFcid, _ga (when Jotform analytics is enabled), and __cf_bm (Cloudflare bot management). These cookies require prior consent in the EEA under Art. 5(3) ePrivacy. Submissions, the visitor IP, the user agent and the referring URL are stored on Jotform servers.

GDPR and ePrivacy implications

Jotform acts as a processor under Art. 28 GDPR. The website operator must sign the Jotform Data Processing Addendum, list Jotform as a sub processor in records of processing, and configure the European data residency option if the website serves EU users with sensitive data. Without EU residency, transfers rely on the EU US DPF (Jotform is certified) or on Standard Contractual Clauses.

Get GDPR compliant in 10 minutes

Free plan available · No credit card required

Try FlowConsent free

Data transfers and residency options

Default Jotform plans store data in the US. The Jotform Enterprise EU data residency option stores submissions in Frankfurt (AWS eu central 1) and serves the form widgets from a European CDN. HIPAA accounts are isolated in a US healthcare environment. Document which residency you use, the corresponding transfer mechanism, and the encryption at rest and in transit.

Practical compliance steps

Block the Jotform widget behind the marketing or statistics consent category until the visitor accepts. Sign the Jotform DPA. Enable EU data residency when relevant. Set encryption on form fields with personal data. Configure a submission retention policy in Jotform. Document Jotform as a sub processor and the relevant US transfer mechanism in your records of processing and your privacy notice.

GDPR consent category

Marketing

Websites using Jotform must obtain user consent under GDPR regulations.

Legal basisConsent (Art. 6(1)(a) GDPR and Art. 5(3) ePrivacy Directive) for the third party cookies set by the embedded widget. Performance of a contract (Art. 6(1)(b)) for the submitted data, processed by Jotform as a processor on behalf of the website operator.
Risk levelmedium
Applicable regulationsGDPR, ePrivacy Directive, TDDDG, LSSI CE, CCPA/CPRA, HIPAA (US healthcare), EU US Data Privacy Framework

Technical details

Tracking methodSaaS form builder embedded via iframe or JavaScript widget. Forms are hosted on jotform.com servers; submissions are sent directly to Jotform and stored on Jotform infrastructure. The embedding website only loads the form widget and an optional CDN tracker.
Server locationJotform Inc., San Francisco, United States. EU customers can opt for the European data residency option (Frankfurt, AWS eu central 1) for an additional fee. HIPAA customers use a separate isolated environment.
Data transferred outside the EUBy default, all form submissions and visitor metadata are stored on Jotform US servers in San Francisco. EU customers can activate the EU data residency (Frankfurt) to keep data inside the EEA. Without that option, transfers require the EU US Data Privacy Framework, Standard Contractual Clauses or other Chapter V GDPR safeguards.

Third-party domains contacted

jotform.comjotfor.mscdn.jotfor.msapi.jotform.comsubmit.jotform.comeu.jotform.com

Cookies placed

NameTypeDurationPurpose
JOTFORM_SESSIONthird_partySessionSession identifier used by the Jotform widget to keep track of the current form instance.
JFcidthird_party1 yearUnique visitor identifier used by Jotform for analytics and conversion attribution.
__cf_bmthird_party30 minutesCloudflare bot management cookie used to distinguish humans from automated traffic on jotform.com.
_gathird_party2 yearsGoogle Analytics identifier set on jotform.com when Jotform Analytics is enabled on the account.

Jotform places tracking cookies for advertising — comply with GDPR using FlowConsent.

Get started freeScan your site

Frequently asked questions

Which cookies does Jotform set?

In the third party context jotform.com the widget sets JOTFORM_SESSION (session), JFcid (visitor identifier, one year), _ga and _gid (if Jotform Analytics is on) and __cf_bm (Cloudflare bot management, 30 minutes). All require prior consent in the EEA except __cf_bm which is sometimes claimed as strictly necessary.

Is consent required to use Jotform?

Yes. The Jotform widget loads third party JavaScript and sets third party cookies, so prior consent is required under Art. 5(3) ePrivacy. Submission data itself is processed under Art. 6(1)(b) GDPR (pre contractual) plus consent for marketing fields.

What is the legal basis for processing Jotform data?

For the form submission, Art. 6(1)(b) GDPR (pre contractual). For the third party cookies and the embedded widget, Art. 6(1)(a) consent. Sensitive data (Art. 9) requires explicit consent and an additional contractual safeguard (e.g., HIPAA BAA for healthcare).

Is data transferred to the United States?

By default, yes: Jotform stores forms and submissions in the US. Enable EU Data Residency on Jotform Enterprise to store data in Frankfurt. Without EU residency, transfers rely on the EU US DPF (Jotform is certified) or on SCCs plus Transfer Impact Assessment.

Do I need a DPIA for Jotform?

A DPIA is recommended when Jotform is used to collect special categories of data (health, biometrics, financial), in recruitment with automated screening, or at large scale. The DPIA covers the residency choice, the transfer mechanism, the embedded cookies and the retention policy.

How do I implement Jotform correctly?

Block the widget until consent. Sign the Jotform DPA. Activate EU residency if relevant. Encrypt sensitive fields. Set a submission retention rule. Add an opt in checkbox to marketing fields. Use Jotform anti spam and reCAPTCHA alternatives such as Cloudflare Turnstile. Document Jotform as a sub processor.

Which alternatives to Jotform should I consider?

EU first SaaS: Tally (Belgium), Typeform (Spain), Formbricks (open source, EU hosting). US SaaS: SurveyMonkey, Wufoo, Google Forms, Microsoft Forms. Self hosted WordPress: Gravity Forms, WPForms, Ninja Forms, Fluent Forms, Contact Form 7.

How do I update the cookie policy when Jotform changes?

Track the Jotform sub processor list and certification status (EU US DPF). When Jotform updates its DPA, residency offering or sub processors, update your cookie table, privacy notice and records of processing, and bump the consent banner version.