Webflow

Webflow

Website design and hosting platform used by designers and development teams to build and host custom sites. Webflow scripts manage responsive layout rendering and form submissions on Webflow-hosted sites. Webflow's Ecommerce feature adds cart and checkout tracking scripts.

Overview

Webflow is a visual web design and hosting platform that allows designers to build custom, responsive websites without traditional coding. Webflow hosts over 200,000 live sites. Sites built and hosted on Webflow load a Webflow runtime script that manages layout animations, interactions, and form submissions — this script is essential infrastructure for any Webflow-hosted site.

What This Script Does

Webflow's client-side presence consists of a core runtime script and optional feature-specific modules.

Script Files and Domains

  • webflow.js — The primary Webflow runtime. Loaded from d3e54v103j8qbb.cloudfront.net (Webflow's CloudFront CDN) or directly from assets.website-files.com. Approximately 80–150KB minified.
  • webflow-js.webflow.com — Alternative CDN domain used for some deployments.
  • Form submissions POST to webflow.com/api/v1/form/{form-id} — Webflow's form processing endpoint.
  • Webflow Ecommerce: additional scripts load from assets.website-files.com for cart and checkout functionality.

Cookies Set

  • .AspNetCore.Antiforgery.* — Anti-CSRF token cookie set on form pages to validate form submission authenticity. Session-scoped. Required for form submissions to succeed.
  • wf_csrf — Webflow CSRF protection cookie for form submissions. Session-scoped.
  • webflow-session — Set on Webflow-hosted sites to maintain session state for authenticated areas (Webflow Memberships). Persists for the configured session duration.

Webflow Ecommerce Cookies

  • wf_cart — Shopping cart state for Webflow Ecommerce sites. Stores cart item IDs and quantities. Session-scoped or persists for up to 30 days depending on configuration.
  • wf_checkout — Checkout flow state cookie. Session-scoped.

Data Collected Per Interaction

  • Form submissions: all user-entered field values are transmitted to Webflow's servers and stored in the Webflow Ecommerce/CMS database. Email notifications are sent to the site owner.
  • No behavioral tracking data is collected by Webflow's core runtime — the script does not send pageview events, click events, or user behavior data to Webflow.
  • Ecommerce: product views, cart events, and purchase completions are tracked for the site owner's Webflow dashboard.

Webflow Interactions and Animations The Webflow runtime manages CSS transitions, scroll-triggered animations, and mouse-tracking interactions built with Webflow's visual designer. These run entirely in-browser without network calls.

Webflow Memberships (if enabled) Webflow Memberships adds user authentication. Members log in via Webflow's authentication system, which sets JWT-based session cookies. Member data (email, profile fields) is stored in Webflow's CMS.

Consent & Compliance

Consent category: Essential / Functional

  • GDPR/ePrivacy: Webflow's core runtime and CSRF cookies are strictly necessary for site functionality. The runtime provides rendering and layout — without it, Webflow-hosted sites would not display correctly. CSRF cookies protect form submissions. Both are exempt from consent requirements under ePrivacy's strictly necessary exemption. Form data submitted by users requires appropriate disclosure in the privacy policy, but the act of loading the form script does not require prior consent.
  • CCPA/CPRA: Webflow processes form submission data as a service provider on behalf of the site owner. No independent sale or sharing by Webflow occurs.
  • Ecommerce cookies: Cart and checkout cookies are strictly necessary for e-commerce functionality. Users cannot complete a purchase without them, qualifying them for the strictly necessary exemption.
  • EU-US Data Privacy Framework: Webflow is a US company. It participates in the DPF and offers SCCs.

Should You Block This Without Consent?

No. Webflow's core scripts and cookies are essential infrastructure for Webflow-hosted websites. Blocking them would break page rendering, interactions, animations, and form submissions. No cross-site tracking, advertising, or behavioral profiling is performed by Webflow's runtime. The ecommerce cookies are strictly necessary for shopping functionality.

Is Webflow GDPR compliant?

Webflow typically loads functional trackers, which are not strictly necessary for your site to work. Under the GDPR and the ePrivacy Directive, non-essential cookies and trackers must stay blocked until a visitor gives clear opt-in consent. So Webflow can be fully GDPR compliant, but only if your site holds its scripts until consent is granted and lets visitors decline just as easily. Compliance depends on how your site loads Webflow, not on Webflow itself.

Visit website

Consent Categories

Also Known As

WebflowWebflow CMSWebflow Ecommercewebsite builder cookiesWebflow scriptno-code platform

Industries

Computers Electronics and TechnologyProgramming and Developer Software

Tracked Domains (1)

Webflow's trackers are occasionally seen, seen on under 1% of the sites ConsentStack has scanned. Scan your own site to see which of these are firing before consent.

website-files.comEssential

website-files.com is an essential domain operated by Webflow, used to keep the site working, including security, load balancing, and sessions. Seen on under 1% of scanned sites.

Frequently Asked Questions

Related Vendors

Instagram
Instagram
Instagram tracking scripts support conversion measurement for Meta advertising campaigns running on Instagram. Scripts fire on advertiser websites to capture click-through and view-through conversions from Instagram ad placements. Collected data flows into Meta Ads Manager for attribution reporting and audience building.
Intuit
Intuit
Intuit provides small business financial software including QuickBooks and TurboTax. Intuit scripts appear on Intuit-hosted product pages and on partner sites via affiliate tracking pixels that attribute signups and subscriptions to referring sources.
Ad Lightning
Ad Lightning
Ad quality and security platform that detects and blocks malicious ads (malvertising) before they render. Ad Lightning's script scans ad creative for code that attempts to redirect users, mine cryptocurrency, or deploy malware. Used by publishers to protect their visitors from bad ads.
Human Security
Human Security
Human Security (formerly White Ops) is a cybersecurity company protecting websites from bot attacks, ad fraud, and account takeover. Scripts collect browser integrity signals and behavioral telemetry to distinguish human visitors from automated traffic.
DigitalOcean
DigitalOcean
Developer-centric cloud infrastructure provider. DigitalOcean hostnames in network requests reflect assets or API endpoints hosted on DigitalOcean infrastructure by the site operator. DigitalOcean does not inject client-side tracking scripts.
Zebrafish Labs
Zebrafish Labs
Open-source image optimization and transformation CDN used by developers to serve responsive images at scale. The imgix script is typically used server-side via URL-based image transforms; client-side scripts are rare and do not involve behavioral tracking.

Manage consent for Webflow

ConsentStack automatically detects and manages Webflow trackers so your site stays compliant with global privacy regulations.