howsafeismyapp

Security & GDPR · Webflow

Is my Webflow app GDPR compliant?

Webflow gives you pixel control over a site — and with it, every third-party default you add: Google Fonts, analytics and marketing embeds that send visitor data to US servers before consent, plus the legal pages nobody generates for you. EU visitors make that your obligation as operator (Art. 3(2) GDPR).

passive · no login · no page contents stored

01

What we typically find on Webflow apps

All checks, explained →

02

Common questions

Does Webflow make my site GDPR compliant by default?

No — hosting and transport are handled well, but fonts, tracking scripts, consent and legal pages are on you, and the usual setup leaks visitor data before consent.

What does the scan check on a Webflow site?

Whether fonts load from Google, third-party tracking and US transfers, consent timing, an imprint and privacy policy, and transport security headers.

Will the scan touch my site or my data?

No. The free check is passive: it loads your site like a normal visitor (GET requests only) and observes what it sends out. No login attempts or active testing. We retain only a limited result digest, not page contents.