Personal data protection policy for PrestaShop, Classic offer

October 2023

It is normal to place special emphasis on how your data is obtained, used and shared.

That is why this personal data protection policy (the “Policy”) has been created to help you understand the practices and conditions in which PrestaShop SA (a public limited company entered the Paris company and trade register under no. 497 916 635, having its offices at 198 Av. de France, 75013 Paris (“PrestaShop”) gathers, uses and stores your personal data (the “Data”).

In this document you will find the various Data that we may collect and process or that you may provide to us when you download and use the PrestaShop Edition Classic (the “Solution”) that enables you to create e-commerce websites (the “Merchant Website”). The latter can be personalized by installing Modules and Themes offered on the official marketplace, which can be accessed at http://addons.prestashop.com  (the “PrestaShop Addons”) or displayed by default in the Merchant Website Back Office.

Some PrestaShop official Partners identified as such on PrestaShop Addons (the “Partners”) offer third party services that can be used by User who, when required, downloads the interface giving access to those services (the “Connectors”) on PrestaShop Addons or directly via their Back Office.

By downloading the Solution, users of this Solution (the “User”) are subject to this Policy.

Due to the constant evolution of technology and data protection laws and regulations, the Policy may be updated regularly. If you are a User of the Solution , we invite you to consult this page regularly. In addition, you will be notified of substantial changes by email.

If any of the clauses in this Policy should be declared null and void or contrary to regulations, that clause will be deemed nugatory, but will not result in any other clauses in this Policy becoming null and void.

This Policy applies to Data collected during the User’s use of the Solution. The objective of the Policy is to inform Users about our processing of Data, how we use, share and protect that Data, and what rights you have with respect to your Data.

It does not apply to information collected by any third party or through websites managed by the latter, including via applications and content (including advertisements) redirecting users to https://www.prestashop.com where they can download the Solution.

Please read the Policy carefully so that you clearly understand our practices regarding the processing of your Data, and be advised that viewing and using our Services is subject to this Policy. If you do not agree with this Policy, please do not use our Solution.

You are responsible for ensuring any Data provided to PrestaShop is complete and up to date.

1. WHAT DATA DOES PRESTASHOP COLLECT?

Depending on the nature and purpose of your interaction with PrestaShop, namely downloading and using the Solution, we may collect the following Data:

  • Data collected when downloading the Solution

Type of data

Data details  

Identity’s data

Email address

Navigation data

URL parameters

(the source, the campaign, the ad, the terms, the click identifier on the ad if existing)

  • Data collected from the PrestaShop Solution installer form
Type of data Data details  
Identity’s data Email address
Last name
Name
Phone number
Language
Country
Merchant Website’s data Business sector
Statistical data on merchant Website activity
Connection data IP address
Server address
Name of the server
Database identifier
Table prefixes
Data base

2. HOW IS MY DATA COLLECTED?

Data can be collected through forms when you download the Solution and to create your Merchant Website.

3. WHY IS MY DATA COLLECTED?

The collection and processing of your data must be justified and comply with one of the principles laid down in the European Data Protection Regulation.

The collect of yours data may be necessary:

  • It has been the subject of your consent ;
  • to respect our contractual commitments ;
  • to comply with the laws and regulations in force ;
  • for PrestaShop’s legitimate interest in order to develop its activity in order to improve its products and services.
  • Data collected when downloading the PrestaShop Solution

Purposes

Data

Legal bases

Downloading the Solution Creating your user account

Identity’s data (mail)

Contractual commitments (T&C)

Your data is collected to allow us to manage our contractual commitment and to allow us to send you the necessary documentation to enable you to create your site.

To determine the source of visitors who have downloaded our Solution Navigation data

(URL parameters)

Legitimate interest
Internal analysis and improvement of our services

PrestaShop business prospecting

Identity’s data (mail)

Legitimate interest
In accordance with the recommendations of the CNIL, PrestaShop may send you information about our services.

You can object at any time to receiving these emails via the registration form or via email.

Data transfer to PrestaShop partners whose Addons you download for commercial prospecting purposes

Identity’s data (mail)

Contractual commitment (T&C)
PrestaShop acts as an intermediary. Your Data may be transferred to PrestaShop partners with whom you contract by downloading a module, a connector or subscribing to a third party service.

  • Purposes and legal bases justifying the processing of your data collected on the PrestaShop Solution installer form

Purposes

Data

Legal bases

Creating your user account

Identity’s data

Merchant Website’s data

Connection data

Contractual commitments (T&C)

Personalization of the Merchant Website

Merchant Website’s data

Contractual commitments (T&C)

Support

Identity’s data

Merchant Website’s data

Connection data

Contractual commitments (T&C)

Statistics analysis

Merchant Website’s data

Legitimate interest (analysis and improvement of our services)

Improve the Solution

Merchant Website’s data

Legitimate interest (analysis and improvement of our services)

4. WHO PROCESSES MY DATA?

  • Internal processing of your data

Your Data are processed by PrestaShop employees tasked with managing the Solution.

  • Processing of your data by our Partners whose Module or Connector you are downloading

Your Data (Connector download date, email, phone number if provided, your website URL, and your full name) will be provided to our Partners so (i) we can track the partnership concluded with PrestaShop and (ii) to allow you to subscribe to the service of the Partner whose Module or Connector you have downloaded and receive customized commercial offers.

The latter are bound by contractual obligations to maintain the confidentiality of the Data and to use it solely for the purposes for which we provide them.

For further information, please consult the PrestaShop Addons Privacy Policy.

  • External processing of your data

Your Data may also, within the scope of our business and for external processing needs, be provided to subcontractors, service providers and other third parties, particularly for hosting your Data.

Your Data may also be sent to any buyer or successor in the event of the merger, transfer, restructuring, reorganization, dissolution or other sale or transfer of some or all of PrestaShop’s assets due to uncertainties, bankruptcy, liquidation or other processes in which the Data of Users of PrestaShop’s various websites is listed among the transferred assets.

Lastly, we may also disclose your Data:

  • To comply with legal mandates, laws and legal procedures, including governmental and regulatory requests.
  • If we deem that disclosure is required or appropriate within the scope of protecting the rights, ownership or security of PrestaShop, our clients and other stakeholders. This disclosure includes exchanging information with other companies and organizations for the purpose of protecting against fraud and counterfeiting.

5. HOW LONG IS MY DATA STORED FOR?

PrestaShop only stores your Data for the period necessary for the purposes explained in Article 3.

This storage period varies according to the Data in question, as it may be affected by the nature and purpose of the collection. Similarly, certain legal obligations stipulate a specific storage period.

Data is stored for the full duration of your Solution use. Your Data then will be stored for five (5) years from the date our contractual relationship ends.

After that time, they may be anonymised and stored for statistical purposes only.

6. HOW IS MY DATA PROTECTED?

Your Data is stored on secure servers protected by firewalls and antivirus software.

We have implemented technical and organizational measures intended to protect the security and confidentiality of your Data against any accidental loss and any unauthorized access, use, modification or disclosure.

Given the inherent characteristics of the internet, we cannot guarantee the optimal security of information exchanged over this network.

We strive to protect your Data , but cannot guarantee the absolute security of information sent to the Website. You agree that you provide your Data at your own risk.

We cannot be held liable for any failure to comply with privacy settings and security measures implemented on our Websites.

As such, you agree that the security of your information is equally your responsibility. For instance, you are responsible for keeping your Merchant Website back-office password confidential.

Never provide it to any third parties. Similarly, be careful when you share information in the public sections of the Website as they can be viewed by all Website users.

7. WHAT ARE MY RIGHTS?

You can choose how the Data you provide is used:

  • It is optional to provide your full name; you may choose not to enter it. In that case, you cannot personalize your Merchant Website with Modules, Themes and Connectors.
  • You can decide not to provide your email address in the Solution download form. However, please be aware that you cannot download the Solution or create a Merchant Website in this case.
  • You can decide to no longer receive personalized offers from our Partners. In this case, you will be able to oppose their solicitation by all means made available by them.
  • You can decide to no longer receive personalized offers from PrestaShop. You can unsubscribe through a link provided in the email.
  • Your IP address must be collected to secure your Merchant Website back-office connection.

In any case, you can access your Merchant Website back-office at any time to view and update your Data.

In accordance with the provisions of the applicable regulations regarding the GDPR you have the right to access and correct your Data. You also have the right to stipulate directives relating to the fate of your Data in the event of your death.

Furthermore, subject to the conditions of the aforementioned regulation for exercising your rights, you have :

  • The right to erasure of your Data.
  • The right to limit processing of your Data.
  • The right to object to the processing of your Data on legitimate grounds, in accordance with article 21 of the GDPR.
  • The right to portability for the Data you have provided.
  • The right to withdraw consent, when it has been asked.

However, in accordance with Article 12.6 of the GDPR, when you exercise these rights, PrestaShop, as the controller, reserves the right to require proof of your identity. Please be aware that the data required to prove your identity will be deleted once we have responded to your request.

You can exercise your rights by sending an email in French, English or Spanish to [email protected] or writing to:

 

PrestaShop S.A – Service Réclamation

Données Personnelles

198 Av. de France, 75013 Paris

 

We are required to reply within one (1) month to all requests regarding the exercising of these rights. This timeframe may be extended to two (2) months for complex requests and large request volumes.

Lastly, you also have the right to lodge a complaint with CNIL (the French National Commission for Information Technology and Civil Liberties), namely via its website at www.cnil.fr.

8. DOES PRESTASHOP TRANSFER MY DATA OUTSIDE THE EUROPEAN UNION?

  • Hosting

Data collected within the scope of Solution use are hosted by Jaguar Network, 71 avenue André Roussin, BP 50067, 13321 Marseille, Cedex 16, France, whose servers are located in the European Union. As such, your Data won’t be transferred outside of the European Union for hosting purposes.

By using the Solution, you agree to your Data being transferred to those servers.

  • Management of PrestaShop Partners

Lastly, within the scope of managing the partnership with our Partners, PrestaShop will provide the Data (Connector download date, email address, phone number if provided, your website URL, and your full name) of our Users who have downloaded the Connectors enabling them to use Partner services.

By downloading the Connectors, you agree to your Data being transferred to the aforementioned Partners.

The latter are bound by contractual obligations to protect and maintain the confidentiality of the Data and to use them solely for the purposes for which we provide them.

For further information, please consult the PrestaShop Addons Privacy Policy.

9. WHICH COOKIES ARE INTEGRATED?

When downloading and using PrestaShop Edition Classic, cookies have been integrated to ensure the proper functioning of your website. These cookies are necessary.

Cookies used to ensure the functioning of the Back Office:

  • Prestashop-<hash>

(hash is a unique identification number to each shop of the type PrestaShop-e21862e60cb58f40ff6789b8bbc85a18 type)

Storage: 20 days
Objective: Remember information about the current employee, such as language, workshop context, preferences, etc.

  • last_position

Storage: 1 week
Objective: Store the last position in the file manager

  • username_addons

Storage: the duration of the session
Objective: Retain identification information to connect to the Addons market.

  • password_addons

Storage: the duration of the session
Objective: Retain identification information to connect to the Addons market.

  • is_contributor :

Conservation: the duration of the session.
Objective: Retain identification information to connect to the Addons market.

  • PHPSESSID :   

Conservation : the duration of the session
Objective : PHP functionality to keep the connection status.

Cookies are also used to ensure the functioning of the Front Office:

  • Prestashop-<hash>

Conservation: 20 days
Objective: To memorize information about the customer such as language, shopping cart, customer account, etc.

  • Notice

Conservation: the duration of the session
Objective: Display notifications after the redirection.

Cookies used to ensure operation during an update:

  • PHPSESSID 

Conservation : the duration of the session
Objective : PHP functionality to keep the connection status