PrestaOne Module License Agreement

Effective date: 2026-08-06

This Module License Agreement ("Agreement") governs the installation and use of the PrestaOne module for PrestaShop (the "Module"), provided by MB "Elevio", company code 306653242, VAT code LT100016572716, Šilutės pl. 35G-36, LT-94105 Klaipėda, Lithuania ("PrestaOne", "we"). By installing the Module you ("Merchant", "you") accept this Agreement. If you use the PrestaOne app and subscription service, the Terms of Service also apply.

1. License grant

We grant you a free-of-charge, non-exclusive, non-transferable, non-sublicensable license to install and use the Module on PrestaShop stores that you own or operate with authorization, for your internal business purposes, for the term of this Agreement. Development, staging and test installations are permitted without restriction.

2. Restrictions

You must not: (a) sell, rent, redistribute or offer the Module to third parties as a product or service; (b) remove or alter copyright, license or attribution notices; (c) modify the Module to circumvent its security, pairing, token-validation or consent-gating features (see §5); (d) use the Module to introduce malicious code into any system. Modifications for your own store's compatibility are permitted at your own risk; modified code is unsupported and may be overwritten by updates (§6).

3. How the Module works: division of responsibility

The Module runs entirely on your server, under your control. It stores its data (including any visitor analytics) in your store's database. PrestaOne has no access to your server, your database or your visitors' data. The Module exposes a secured API that the PrestaOne app calls directly from your paired devices; that business data likewise never passes through PrestaOne's infrastructure. Only minimal event signals (internal store ID, event type, object reference and, for orders, amount/currency) are sent by the Module to PrestaOne's backend to trigger push notifications, as described in the DPA. These signals contain no buyer name, email, address or message content, but an internal reference or order amount may be indirectly personal data when linked to your Store's records.

The Module itself works without a paid subscription. Connecting the mobile app requires an active seat subscription under the Terms of Service; if the subscription lapses, app connectivity ends but the Module, your store and all data on your server remain intact.

4. Your infrastructure

You are responsible for your server, PrestaShop installation, HTTPS configuration, backups and general security of your environment. The Module requires HTTPS and refuses unencrypted connections; you must not disable this.

5. Merchant privacy obligations (visitor analytics)

The Module includes visitor analytics for your storefront. You are the data controller for all data the Module collects from your store's visitors; PrestaOne is a software supplier and does not process this data.

5.1 The privacy mode you select decides what is stored on your visitors' devices. The Module offers three storefront privacy modes, configured in the module's back office. The default for a new installation is Balanced, which writes browser storage before any consent signal. Read this section before you go live.

ModeBefore a consent signalAfter an analytics-consent signal
Consent-firstNo cookie and no browser storage is written or read. The page still sends one anonymous request that increments aggregate counters (page and product views) with no visitor or session identifier.Full mode behaviour
Balanced (default)A 30-minute session cookie (prestaone_session_id) is written, plus sessionStorage keys used to avoid counting the same product view twice. A session row is created in your database holding referrer, entry page, UTM and click identifiers, country code, device type and traffic source. No cross-visit identifier is created. Declining consent keeps this ephemeral session; it does not switch the mode off.Full mode behaviour
FullTreats an absent consent signal as permission: a first-party visitor_id cookie valid for 365 days, a 30-day country cache cookie, sessions and new/returning attribution, and a country lookup that sends the visitor's IP address to our geolocation endpoint.Unchanged

Withdrawing consent immediately deletes the visitor_id and country cookies and stops persistent identification. In Balanced mode the 30-minute session key is kept, because session continuity is not a persistent identity.

5.2 What this means for your obligations. Storing or reading information on a visitor's terminal equipment requires consent under Article 5(3) of the ePrivacy Directive and its national implementations, subject to the strictly-necessary exemption. Analytics storage is not generally treated as strictly necessary. In Balanced and Full modes the Module writes browser storage before consent, so you must obtain valid consent or switch the Module to Consent-first mode. We make no representation that any particular mode is lawful for your store; that assessment depends on your jurisdiction, your consent solution and your own advice.

5.3 What the Module stores in your database. Visitor sessions are retained for 30 days and cart-funnel events for 395 days, after which the Module deletes them automatically. Visitor IP addresses are never written to your database: the country code is resolved during the request and the address is discarded. The referring URL is reduced to its scheme and host before storage, and the entry page keeps only its path plus recognised campaign parameters. All of this data stays on your server; PrestaOne has no access to it.

5.4 Your commitments. You agree that you will: (a) maintain a privacy policy for your store that accurately discloses your use of analytics, including the Module, the privacy mode you have selected and the storage it writes; (b) deploy a consent management solution and obtain valid visitor consent where required by applicable law (GDPR, ePrivacy and national implementations) before any non-exempt storage is written or read; (c) not modify, configure or instruct the Module so as to bypass its consent gating; (d) honor visitor and buyer data-subject rights in your store, using PrestaShop's GDPR tooling with which the Module integrates (export and erasure cover the Module's tables); (e) comply with all laws applicable to your processing of visitor and buyer data.

6. Updates and support

We may provide Module updates including security fixes; keeping the Module updated is your responsibility. Updates may overwrite local modifications. Support is provided for current Module versions on supported PrestaShop versions (1.7.x, 8.x, 9.x) via [email protected].

7. Intellectual property

The Module is licensed, not sold. We retain all rights, title and interest in the Module. PrestaOne is an independent product, not affiliated with, endorsed by or sponsored by PrestaShop SA. "PrestaShop" is a trademark of its respective owner.

8. Warranty disclaimer

The Module is provided "as is" and "as available", without warranties of any kind, to the maximum extent permitted by law. We do not warrant compatibility with every theme, module, override or hosting environment, or uninterrupted or error-free operation.

9. Limitation of liability

To the maximum extent permitted by law, we are not liable for indirect, incidental or consequential damages, lost profits, lost revenue or lost data arising from the Module. Our total aggregate liability under this Agreement is limited to the fees you paid for the PrestaOne Service in the 12 months preceding the claim (or €100 if you paid none). These limits do not apply where liability cannot be limited by law or in case of our gross negligence or willful misconduct.

10. Indemnification

You will indemnify and hold PrestaOne harmless from third-party claims (including claims by your store's visitors or buyers and measures by supervisory authorities) arising from: (a) your failure to obtain legally required consents or provide legally required notices for data collected on your store; (b) your modification or configuration of the Module in breach of §2 or §5; (c) your violation of applicable law in operating your store.

11. Termination

This Agreement applies for as long as you use the Module. It terminates automatically if you materially breach it and do not cure within 30 days of notice. Upon termination you must uninstall the Module; uninstalling removes the Module's database tables and configuration (including stored secrets) from your server. Sections 7–10 survive termination.

12. Governing law

This Agreement is governed by the laws of the Republic of Lithuania; disputes are subject to the exclusive jurisdiction of the competent courts of Vilnius, Lithuania.

Contact: [email protected]