Cloudflare

Cloudflare

CDN and network security infrastructure provider used to accelerate and protect websites. Scripts include the Cloudflare Turnstile CAPTCHA widget, Web Analytics (cookieless analytics), and Bot Management signals. Core CDN functionality operates at the network level, but challenge and analytics scripts do execute in the browser.

Overview

Cloudflare is a global CDN, network security, and performance infrastructure provider used by millions of websites. From a browser perspective, Cloudflare manifests in several distinct ways: as the CDN delivering site assets, as Turnstile (its CAPTCHA replacement), as Cloudflare Web Analytics (a privacy-first analytics tool), and as Bot Management challenge scripts. Each of these components has different privacy and consent characteristics.

What This Script Does

Cloudflare Turnstile

Turnstile is Cloudflare's CAPTCHA alternative (challenges.cloudflare.com/turnstile/v0/api.js). It runs a series of non-interactive browser challenges to distinguish humans from bots. Turnstile does not use cookies for tracking and explicitly avoids building behavioral profiles. It collects browser signals (user-agent, execution environment, proof-of-work challenge responses) and sends them to Cloudflare for verification. The challenge result is returned as a one-time token.

Cloudflare Web Analytics

Cloudflare Web Analytics (static.cloudflareinsights.com/beacon.min.js) is a lightweight, privacy-respecting analytics script. It uses no cookies, no fingerprinting, and no cross-site tracking. It collects aggregate page view counts, Core Web Vitals metrics, and geographic breakdowns from IP-derived country data (the IP itself is not stored). Cloudflare Web Analytics is explicitly designed as a GDPR-compliant, cookieless analytics solution.

Bot Management

On sites using Cloudflare's enterprise Bot Management, a challenge script may fire to verify browser legitimacy. This uses JavaScript execution challenges and behavioral signals (timing, event patterns) to score the request.

Cookies Set

  • __cf_bm — First-party cookie (set under the site's own domain by Cloudflare). Bot management cookie used to identify and manage automated traffic. Duration: 30 minutes.
  • cf_clearance — First-party cookie. Set after a visitor passes a Cloudflare security challenge (CAPTCHA or browser check). Duration: 1 day.
  • _cfuvid — First-party cookie. Used by Cloudflare rate limiting to identify a visitor within a rate limit window. Duration: session.

Turnstile and Web Analytics set no persistent tracking cookies.

Domains Contacted

  • challenges.cloudflare.com — Turnstile challenge API and verification endpoint.
  • static.cloudflareinsights.com — Web Analytics beacon endpoint.
  • Cloudflare's CDN operates at the network layer and does not require additional JavaScript for CDN functionality.

Data Collected Per Interaction

  • For Turnstile: browser execution environment signals, user-agent, proof-of-work results, page URL. No persistent user identity.
  • For Web Analytics: page URL, country (from IP, not stored), Core Web Vitals metrics (LCP, FID, CLS), browser and OS type. No IP storage, no cookies, no cross-site tracking.
  • For Bot Management / __cf_bm: browser interaction timing and behavioral signals. Cookie duration is 30 minutes and is strictly functional.

Consent & Compliance

GDPR / ePrivacy: The __cf_bm and cf_clearance cookies are security and anti-abuse cookies, not tracking cookies. Security and fraud prevention cookies can qualify as strictly necessary under the ePrivacy Directive's Article 5(3) exemption. Cloudflare Web Analytics requires no consent as it collects no personal data and sets no cookies. Turnstile is designed to be a consent-free CAPTCHA replacement and explicitly avoids tracking. Most EU DPA guidance supports treating bot management and security cookies as strictly necessary.

CCPA / CPRA: Cloudflare processes data as a service provider under its customer agreement. Security and performance data processing is not a sale of personal information. Cloudflare is certified under the EU-US DPF and maintains comprehensive SCCs.

EU-US Data Privacy Framework: Cloudflare is certified under the EU-US DPF for EU-to-US personal data transfers.

Consent Category: Essential (security and CDN) / Analytics (Web Analytics — cookieless, no consent required).

Should You Block This Without Consent?

No. Cloudflare's security cookies (__cf_bm, cf_clearance) are strictly necessary for protecting the website from bot attacks and fraud. They do not track users across sites or build behavioral profiles. Cloudflare Web Analytics is cookieless and privacy-preserving by design. None of Cloudflare's standard components require prior user consent under GDPR, ePrivacy, or CCPA frameworks.

Is Cloudflare GDPR compliant?

Cloudflare typically loads analytics trackers, which are not strictly necessary for your site to work. Under the GDPR and the ePrivacy Directive, non-essential cookies and trackers must stay blocked until a visitor gives clear opt-in consent. So Cloudflare can be fully GDPR compliant, but only if your site holds its scripts until consent is granted and lets visitors decline just as easily. Compliance depends on how your site loads Cloudflare, not on Cloudflare itself.

Visit website

Products (3)

Consent Categories

Also Known As

Cloudflare Turnstilecf_clearance cookieCloudflare Web AnalyticsCloudflare bot managementCloudflare CAPTCHACloudflare WAF scriptTurnstile widget

Industries

Computer SecurityComputers Electronics and Technology

Tracked Domains (2)

Cloudflare's trackers are very common, seen on about 19% of the sites ConsentStack has scanned. Scan your own site to see which of these are firing before consent.

cloudflare.comAnalytics

cloudflare.com is an analytics domain operated by Cloudflare, used to measure visits, sessions, and on-site behavior. Seen on about 19% of scanned sites.

cloudflarestream.comEssential

cloudflarestream.com is an essential domain operated by Cloudflare, used to keep the site working, including security, load balancing, and sessions. Seen on a small share of scanned sites.

Cookies Cloudflare Sets (8)

__cf_bm

Cloudflare bot-management cookie set on the customer apex when a request transits Cloudflare. 30-minute expiration; required for bot scoring.

cf_clearance

Cloudflare cookie indicating the visitor has passed a managed challenge (CAPTCHA / Turnstile). 30-minute expiration.

__cflb

Cloudflare Load Balancer session-affinity cookie pinning the visitor to a backend pool.

__cfruid

Cloudflare legacy rate-limiting identifier. Set by the edge proxy when the site uses the older Rate Limiting product, to track per-visitor request counts within a rolling window.

_cfuvid

Cloudflare Rate Limiting Rules visitor identifier. Set when the site has explicitly configured rate-limit rules that need to distinguish individual users sharing a single NAT IP address.

cf_use_ob

Cloudflare Always Online routing instruction cookie. Tells the edge to fetch the resource from the Always Online cache rather than the live origin. Expires after 30 seconds.

__cf_waitingroom

Cloudflare Waiting Room cookie tracking the visitor's position in a queue during peak traffic.

cf_ob_info

Cloudflare Always Online metadata cookie. Records HTTP status, originating data center, and Ray ID when the edge served a cached copy because the origin was unreachable. Expires after 30 seconds.

Frequently Asked Questions

Related Vendors

BigID
BigID
BigID is an enterprise data intelligence platform for privacy, security, and compliance management. It operates as backend SaaS with no scripts loading in end-user browsers or on customer-facing websites. No direct browser presence for site visitors.
DataDome
DataDome
Bot detection and protection platform that operates as a client-side signal collector. The DataDome script runs behavioral checks in the browser — mouse movement patterns, keystroke timing, JS environment fingerprinting — and submits signals to DataDome's servers to classify traffic as human or automated in real time.
Google Fonts
Google Fonts
Google Fonts is a free font hosting service that serves hundreds of typeface families via a global CDN. Stylesheets and font files load from fonts.googleapis.com and fonts.gstatic.com to deliver web fonts to visitors. No advertising or tracking functionality is included.
OneTrust
OneTrust
Consent management and privacy compliance platform. The OneTrust script serves the cookie consent banner, records consent decisions, and conditionally blocks or allows other scripts based on user preferences. Also powers cookie audits, privacy preference centers, and data subject access request workflows.
Google Tag Manager
Google Tag Manager
Google Tag Manager is a tag management system that lets marketers deploy and update analytics and marketing scripts without code changes. The GTM container script loads synchronously in the page head and injects configured tags, triggers, and variables on behalf of other vendors. No data collection of its own — acts as a loader for other scripts.
OpenJS Foundation
OpenJS Foundation
Open-source JavaScript module hosting CDN provided by the OpenJS Foundation. The jsDelivr and similar CDNs serve JavaScript packages globally. No behavioral tracking or advertising cookies are set by the CDN itself.

Manage consent for Cloudflare

ConsentStack automatically detects and manages Cloudflare trackers so your site stays compliant with global privacy regulations.