Personal data protection policy for PrestaShop, Classic offer
October 2023
It is normal to place special emphasis on how your data is obtained, used and shared.
That is why this personal data protection policy (the “Policy”) has been created to help you understand the practices and conditions in which PrestaShop SA (a public limited company entered the Paris company and trade register under no. 497 916 635, having its offices at 198 Av. de France, 75013 Paris (“PrestaShop”) gathers, uses and stores your personal data (the “Data”).
In this document you will find the various Data that we may collect and process or that you may provide to us when you download and use the PrestaShop Edition Classic (the “Solution”) that enables you to create e-commerce websites (the “Merchant Website”). The latter can be personalized by installing Modules and Themes offered on the official marketplace, which can be accessed at http://addons.prestashop.com (the “PrestaShop Addons”) or displayed by default in the Merchant Website Back Office.
Some PrestaShop official Partners identified as such on PrestaShop Addons (the “Partners”) offer third party services that can be used by User who, when required, downloads the interface giving access to those services (the “Connectors”) on PrestaShop Addons or directly via their Back Office.
By downloading the Solution, users of this Solution (the “User”) are subject to this Policy.
Due to the constant evolution of technology and data protection laws and regulations, the Policy may be updated regularly. If you are a User of the Solution , we invite you to consult this page regularly. In addition, you will be notified of substantial changes by email.
If any of the clauses in this Policy should be declared null and void or contrary to regulations, that clause will be deemed nugatory, but will not result in any other clauses in this Policy becoming null and void.
This Policy applies to Data collected during the User’s use of the Solution. The objective of the Policy is to inform Users about our processing of Data, how we use, share and protect that Data, and what rights you have with respect to your Data.
It does not apply to information collected by any third party or through websites managed by the latter, including via applications and content (including advertisements) redirecting users to https://www.prestashop.com where they can download the Solution.
Please read the Policy carefully so that you clearly understand our practices regarding the processing of your Data, and be advised that viewing and using our Services is subject to this Policy. If you do not agree with this Policy, please do not use our Solution.
You are responsible for ensuring any Data provided to PrestaShop is complete and up to date.
1. WHAT DATA DOES PRESTASHOP COLLECT?
Depending on the nature and purpose of your interaction with PrestaShop, namely downloading and using the Solution, we may collect the following Data:
- Data collected when downloading the Solution
Type of data |
Data details |
---|---|
Identity’s data |
Email address |
Navigation data |
URL parameters (the source, the campaign, the ad, the terms, the click identifier on the ad if existing) |
- Data collected from the PrestaShop Solution installer form
Type of data | Data details |
---|---|
Identity’s data | Email address |
Last name | |
Name | |
Phone number | |
Language | |
Country | |
Merchant Website’s data | Business sector |
Statistical data on merchant Website activity | |
Connection data | IP address |
Server address | |
Name of the server | |
Database identifier | |
Table prefixes | |
Data base |
2. HOW IS MY DATA COLLECTED?
Data can be collected through forms when you download the Solution and to create your Merchant Website.
3. WHY IS MY DATA COLLECTED?
The collection and processing of your data must be justified and comply with one of the principles laid down in the European Data Protection Regulation.
The collect of yours data may be necessary:
- It has been the subject of your consent ;
- to respect our contractual commitments ;
- to comply with the laws and regulations in force ;
- for PrestaShop’s legitimate interest in order to develop its activity in order to improve its products and services.
- Data collected when downloading the PrestaShop Solution
Purposes |
Data |
Legal bases |
---|---|---|
Downloading the Solution Creating your user account |
Identity’s data (mail) |
Contractual commitments (T&C) Your data is collected to allow us to manage our contractual commitment and to allow us to send you the necessary documentation to enable you to create your site. |
To determine the source of visitors who have downloaded our Solution | Navigation data
(URL parameters) |
Legitimate interest Internal analysis and improvement of our services |
PrestaShop business prospecting |
Identity’s data (mail) |
Legitimate interest You can object at any time to receiving these emails via the registration form or via email. |
Data transfer to PrestaShop partners whose Addons you download for commercial prospecting purposes |
Identity’s data (mail) |
Contractual commitment (T&C) |
- Purposes and legal bases justifying the processing of your data collected on the PrestaShop Solution installer form
Purposes |
Data |
Legal bases |
---|---|---|
Creating your user account |
Identity’s data Merchant Website’s data Connection data |
Contractual commitments (T&C) |
Personalization of the Merchant Website |
Merchant Website’s data |
Contractual commitments (T&C) |
Support |
Identity’s data Merchant Website’s data Connection data |
Contractual commitments (T&C) |
Statistics analysis |
Merchant Website’s data |
Legitimate interest (analysis and improvement of our services) |
Improve the Solution |
Merchant Website’s data |
Legitimate interest (analysis and improvement of our services) |
4. WHO PROCESSES MY DATA?
-
Internal processing of your data
Your Data are processed by PrestaShop employees tasked with managing the Solution.
-
Processing of your data by our Partners whose Module or Connector you are downloading
Your Data (Connector download date, email, phone number if provided, your website URL, and your full name) will be provided to our Partners so (i) we can track the partnership concluded with PrestaShop and (ii) to allow you to subscribe to the service of the Partner whose Module or Connector you have downloaded and receive customized commercial offers.
The latter are bound by contractual obligations to maintain the confidentiality of the Data and to use it solely for the purposes for which we provide them.
For further information, please consult the PrestaShop Addons Privacy Policy.
-
External processing of your data
Your Data may also, within the scope of our business and for external processing needs, be provided to subcontractors, service providers and other third parties, particularly for hosting your Data.
Your Data may also be sent to any buyer or successor in the event of the merger, transfer, restructuring, reorganization, dissolution or other sale or transfer of some or all of PrestaShop’s assets due to uncertainties, bankruptcy, liquidation or other processes in which the Data of Users of PrestaShop’s various websites is listed among the transferred assets.
Lastly, we may also disclose your Data:
- To comply with legal mandates, laws and legal procedures, including governmental and regulatory requests.
- If we deem that disclosure is required or appropriate within the scope of protecting the rights, ownership or security of PrestaShop, our clients and other stakeholders. This disclosure includes exchanging information with other companies and organizations for the purpose of protecting against fraud and counterfeiting.
5. HOW LONG IS MY DATA STORED FOR?
PrestaShop only stores your Data for the period necessary for the purposes explained in Article 3.
This storage period varies according to the Data in question, as it may be affected by the nature and purpose of the collection. Similarly, certain legal obligations stipulate a specific storage period.
Data is stored for the full duration of your Solution use. Your Data then will be stored for five (5) years from the date our contractual relationship ends.
After that time, they may be anonymised and stored for statistical purposes only.
6. HOW IS MY DATA PROTECTED?
Your Data is stored on secure servers protected by firewalls and antivirus software.
We have implemented technical and organizational measures intended to protect the security and confidentiality of your Data against any accidental loss and any unauthorized access, use, modification or disclosure.
Given the inherent characteristics of the internet, we cannot guarantee the optimal security of information exchanged over this network.
We strive to protect your Data , but cannot guarantee the absolute security of information sent to the Website. You agree that you provide your Data at your own risk.
We cannot be held liable for any failure to comply with privacy settings and security measures implemented on our Websites.
As such, you agree that the security of your information is equally your responsibility. For instance, you are responsible for keeping your Merchant Website back-office password confidential.
Never provide it to any third parties. Similarly, be careful when you share information in the public sections of the Website as they can be viewed by all Website users.
7. WHAT ARE MY RIGHTS?
You can choose how the Data you provide is used:
- It is optional to provide your full name; you may choose not to enter it. In that case, you cannot personalize your Merchant Website with Modules, Themes and Connectors.
- You can decide not to provide your email address in the Solution download form. However, please be aware that you cannot download the Solution or create a Merchant Website in this case.
- You can decide to no longer receive personalized offers from our Partners. In this case, you will be able to oppose their solicitation by all means made available by them.
- You can decide to no longer receive personalized offers from PrestaShop. You can unsubscribe through a link provided in the email.
- Your IP address must be collected to secure your Merchant Website back-office connection.
In any case, you can access your Merchant Website back-office at any time to view and update your Data.
In accordance with the provisions of the applicable regulations regarding the GDPR you have the right to access and correct your Data. You also have the right to stipulate directives relating to the fate of your Data in the event of your death.
Furthermore, subject to the conditions of the aforementioned regulation for exercising your rights, you have :
- The right to erasure of your Data.
- The right to limit processing of your Data.
- The right to object to the processing of your Data on legitimate grounds, in accordance with article 21 of the GDPR.
- The right to portability for the Data you have provided.
- The right to withdraw consent, when it has been asked.
However, in accordance with Article 12.6 of the GDPR, when you exercise these rights, PrestaShop, as the controller, reserves the right to require proof of your identity. Please be aware that the data required to prove your identity will be deleted once we have responded to your request.
You can exercise your rights by sending an email in French, English or Spanish to [email protected] or writing to:
PrestaShop S.A – Service Réclamation
Données Personnelles
198 Av. de France, 75013 Paris
We are required to reply within one (1) month to all requests regarding the exercising of these rights. This timeframe may be extended to two (2) months for complex requests and large request volumes.
Lastly, you also have the right to lodge a complaint with CNIL (the French National Commission for Information Technology and Civil Liberties), namely via its website at www.cnil.fr.
8. DOES PRESTASHOP TRANSFER MY DATA OUTSIDE THE EUROPEAN UNION?
- Hosting
Data collected within the scope of Solution use are hosted by Jaguar Network, 71 avenue André Roussin, BP 50067, 13321 Marseille, Cedex 16, France, whose servers are located in the European Union. As such, your Data won’t be transferred outside of the European Union for hosting purposes.
By using the Solution, you agree to your Data being transferred to those servers.
- Management of PrestaShop Partners
Lastly, within the scope of managing the partnership with our Partners, PrestaShop will provide the Data (Connector download date, email address, phone number if provided, your website URL, and your full name) of our Users who have downloaded the Connectors enabling them to use Partner services.
By downloading the Connectors, you agree to your Data being transferred to the aforementioned Partners.
The latter are bound by contractual obligations to protect and maintain the confidentiality of the Data and to use them solely for the purposes for which we provide them.
For further information, please consult the PrestaShop Addons Privacy Policy.
9. WHICH COOKIES ARE INTEGRATED?
When downloading and using PrestaShop Edition Classic, cookies have been integrated to ensure the proper functioning of your website. These cookies are necessary.
Cookies used to ensure the functioning of the Back Office:
- Prestashop-<hash>
(hash is a unique identification number to each shop of the type PrestaShop-e21862e60cb58f40ff6789b8bbc85a18 type)
Storage: 20 days
Objective: Remember information about the current employee, such as language, workshop context, preferences, etc.
- last_position
Storage: 1 week
Objective: Store the last position in the file manager
- username_addons
Storage: the duration of the session
Objective: Retain identification information to connect to the Addons market.
- password_addons
Storage: the duration of the session
Objective: Retain identification information to connect to the Addons market.
- is_contributor :
Conservation: the duration of the session.
Objective: Retain identification information to connect to the Addons market.
- PHPSESSID :
Conservation : the duration of the session
Objective : PHP functionality to keep the connection status.
Cookies are also used to ensure the functioning of the Front Office:
- Prestashop-<hash>
Conservation: 20 days
Objective: To memorize information about the customer such as language, shopping cart, customer account, etc.
- Notice
Conservation: the duration of the session
Objective: Display notifications after the redirection.
Cookies used to ensure operation during an update:
- PHPSESSID
Conservation : the duration of the session
Objective : PHP functionality to keep the connection status