Overview
BYO OneTrust lets enterprise customers use their existing OneTrust consent management platform with Flowcode. This gives your organization full control over cookie compliance, privacy policies, and regulatory requirements, all while still using Flowcode conversion experiences.
With BYO OneTrust, your organization operates as the data controller, and Flowcode operates as a data processor (enabled via a Data Processing Agreement).
Benefits
BYO OneTrust helps enterprise teams:
Maintain control and data ownership by managing consent through your own OneTrust instance
Standardize compliance across branded experiences and custom domains
Reduce operational overhead by keeping privacy governance in one system
Build user trust with transparent, recognizable consent and policy access
Support enterprise compliance needs (SOC 2 Type II, GDPR, CCPA, HIPAA) and SSO environments
Requirements Before You Get Started
Custom Domain
You must have a custom domain (e.g., qr.yourbrand.com) set up in your Flowcode account already
Flowcode-managed domains (like flowsto.com and flowcode.com) are not supported
To configure a custom domain, please follow the instructions here.
Contract & Compliance
A Data Processing Agreement (DPA) must be included in your Flowcode contract
You are the data controller; Flowcode is the data processor
OneTrust Setup
Your custom domain must be configured in your OneTrust account
You must provide the OneTrust domain script snippet that matches your custom domain
Privacy Assets
A link to your Privacy Policy
OneTrust Domain Group ID to consent to your cookie consent policy
How It Works
Step 1: Verify your custom domain
Confirm the Data Processing Agreement (DPA) provided by Flowcode. You’ll submit an owned custom domain for verification and configuration. Once verified, Flowcode can enforce that your organization’s experiences use that custom domain.
Step 2: Configure Cookie Consent Policy in Flowcode
After verification, you’ll see a Cookie Consent Policy tab in your Organization settings. Complete the setup:
Once configured, OneTrust-powered consent banners will be enforced across eligible Flowcode experiences.
Important Notes
Cookie consent banners apply only to Flowcode conversion experiences (Flowcode-hosted pages).
They do not apply to scans that immediately redirect to external websites.
Your organization is responsible for managing cookie consent on any landing page that matches your custom domain.
You are responsible for ensuring your Privacy Policy and Terms & Conditions are included where required across your experiences.
