Overview
Webflow is a visual web design and hosting platform that allows designers to build custom, responsive websites without traditional coding. Webflow hosts over 200,000 live sites. Sites built and hosted on Webflow load a Webflow runtime script that manages layout animations, interactions, and form submissions — this script is essential infrastructure for any Webflow-hosted site.
What This Script Does
Webflow's client-side presence consists of a core runtime script and optional feature-specific modules.
Script Files and Domains
webflow.js— The primary Webflow runtime. Loaded fromd3e54v103j8qbb.cloudfront.net(Webflow's CloudFront CDN) or directly fromassets.website-files.com. Approximately 80–150KB minified.webflow-js.webflow.com— Alternative CDN domain used for some deployments.- Form submissions POST to
webflow.com/api/v1/form/{form-id}— Webflow's form processing endpoint. - Webflow Ecommerce: additional scripts load from
assets.website-files.comfor cart and checkout functionality.
Cookies Set
.AspNetCore.Antiforgery.*— Anti-CSRF token cookie set on form pages to validate form submission authenticity. Session-scoped. Required for form submissions to succeed.wf_csrf— Webflow CSRF protection cookie for form submissions. Session-scoped.webflow-session— Set on Webflow-hosted sites to maintain session state for authenticated areas (Webflow Memberships). Persists for the configured session duration.
Webflow Ecommerce Cookies
wf_cart— Shopping cart state for Webflow Ecommerce sites. Stores cart item IDs and quantities. Session-scoped or persists for up to 30 days depending on configuration.wf_checkout— Checkout flow state cookie. Session-scoped.
Data Collected Per Interaction
- Form submissions: all user-entered field values are transmitted to Webflow's servers and stored in the Webflow Ecommerce/CMS database. Email notifications are sent to the site owner.
- No behavioral tracking data is collected by Webflow's core runtime — the script does not send pageview events, click events, or user behavior data to Webflow.
- Ecommerce: product views, cart events, and purchase completions are tracked for the site owner's Webflow dashboard.
Webflow Interactions and Animations The Webflow runtime manages CSS transitions, scroll-triggered animations, and mouse-tracking interactions built with Webflow's visual designer. These run entirely in-browser without network calls.
Webflow Memberships (if enabled) Webflow Memberships adds user authentication. Members log in via Webflow's authentication system, which sets JWT-based session cookies. Member data (email, profile fields) is stored in Webflow's CMS.
Consent & Compliance
Consent category: Essential / Functional
- GDPR/ePrivacy: Webflow's core runtime and CSRF cookies are strictly necessary for site functionality. The runtime provides rendering and layout — without it, Webflow-hosted sites would not display correctly. CSRF cookies protect form submissions. Both are exempt from consent requirements under ePrivacy's strictly necessary exemption. Form data submitted by users requires appropriate disclosure in the privacy policy, but the act of loading the form script does not require prior consent.
- CCPA/CPRA: Webflow processes form submission data as a service provider on behalf of the site owner. No independent sale or sharing by Webflow occurs.
- Ecommerce cookies: Cart and checkout cookies are strictly necessary for e-commerce functionality. Users cannot complete a purchase without them, qualifying them for the strictly necessary exemption.
- EU-US Data Privacy Framework: Webflow is a US company. It participates in the DPF and offers SCCs.
Should You Block This Without Consent?
No. Webflow's core scripts and cookies are essential infrastructure for Webflow-hosted websites. Blocking them would break page rendering, interactions, animations, and form submissions. No cross-site tracking, advertising, or behavioral profiling is performed by Webflow's runtime. The ecommerce cookies are strictly necessary for shopping functionality.
Is Webflow GDPR compliant?
Webflow typically loads functional trackers, which are not strictly necessary for your site to work. Under the GDPR and the ePrivacy Directive, non-essential cookies and trackers must stay blocked until a visitor gives clear opt-in consent. So Webflow can be fully GDPR compliant, but only if your site holds its scripts until consent is granted and lets visitors decline just as easily. Compliance depends on how your site loads Webflow, not on Webflow itself.
Consent Categories
Also Known As
Industries
Tracked Domains (1)
Webflow's trackers are occasionally seen, seen on under 1% of the sites ConsentStack has scanned. Scan your own site to see which of these are firing before consent.
website-files.comEssentialwebsite-files.com is an essential domain operated by Webflow, used to keep the site working, including security, load balancing, and sessions. Seen on under 1% of scanned sites.
Frequently Asked Questions
Related Vendors
Manage consent for Webflow
ConsentStack automatically detects and manages Webflow trackers so your site stays compliant with global privacy regulations.