Security Policy

Effective Date: August 13, 2026
Last Updated: August 13, 2026

1. Purpose

This Security Policy establishes the security practices and safeguards used to protect this PrestaShop website, its customers, administrative systems, and information processed through the store.

The goal of this policy is to reduce the risk of unauthorized access, data loss, fraud, malicious activity, and disruption of services.

2. Scope

This policy applies to:

  • The PrestaShop installation and associated website files.

  • The store's database and server environment.

  • Administrative accounts and privileged users.

  • Customer and order information.

  • Payment-related information processed through the store or authorized payment providers.

  • Third-party modules, themes, APIs, and integrations used by the store.

  • Employees, contractors, administrators, and other individuals with authorized access.

3. Account Security

Administrative and user accounts must be protected using appropriate security measures.

Administrators are expected to:

  • Use strong, unique passwords.

  • Never share account credentials.

  • Use multi-factor authentication when available.

  • Avoid using administrator credentials on untrusted devices.

  • Remove or disable accounts that are no longer required.

  • Use the minimum privileges necessary to perform assigned duties.

Administrator access should be restricted to authorized individuals only.

4. Password Requirements

Passwords should be sufficiently long and difficult to guess.

Passwords must not be:

  • Reused across unrelated services.

  • Shared with other individuals.

  • Stored in plain text.

  • Included in source code, public configuration files, or publicly accessible documents.

Where supported, password managers and multi-factor authentication should be used.

5. PrestaShop Security

The PrestaShop installation should be maintained using supported and security-patched versions.

Security practices include:

  • Keeping PrestaShop updated.

  • Applying security updates promptly.

  • Keeping PHP and server software supported and patched.

  • Updating third-party modules and themes.

  • Removing unused or abandoned modules.

  • Removing unnecessary administrative accounts.

  • Restricting access to sensitive administrative functions.

  • Preventing unauthorized modification of core files.

  • Using secure configuration settings appropriate to the hosting environment.

Third-party modules should be obtained from reputable sources and reviewed before installation.

6. Server Security

The hosting environment should be configured to minimize unauthorized access.

Where supported, security controls should include:

  • HTTPS/TLS for website communications.

  • A properly configured firewall.

  • Restricted administrative access.

  • Secure file permissions.

  • Protection of configuration files and database credentials.

  • Disabled directory listing where unnecessary.

  • Protection of backup files from public access.

  • Regular operating-system and server-software updates.

  • Monitoring for unusual or unauthorized activity.

Sensitive server files must not be placed in publicly accessible directories unless required for the website to function.

7. Database Security

Database access must be restricted to authorized applications and administrators.

Database credentials should:

  • Be unique to the application where practical.

  • Have only the privileges required by the application.

  • Never be exposed in publicly accessible files.

  • Never be committed to publicly accessible source-code repositories.

Database backups must receive security protections appropriate to the information they contain.

8. Customer Information

Customer information must be accessed only when necessary for legitimate business or administrative purposes.

Reasonable safeguards should be used to protect information such as:

  • Names.

  • Email addresses.

  • Billing and shipping information.

  • Order information.

  • Account credentials.

  • Customer communications.

  • Other information submitted through the store.

Payment-card information should not be stored by the store unless there is a specific legitimate and properly secured requirement to do so. Payment processing should preferably be handled by an appropriate payment provider.

9. Encryption

Sensitive information should be protected during transmission using HTTPS/TLS.

Encryption should also be considered for sensitive information stored on systems, backups, or other storage locations where appropriate.

10. Logging and Monitoring

Security-relevant activity may be logged and monitored to identify suspicious behavior, unauthorized access, technical failures, and potential security incidents.

Logs should be protected from unauthorized modification and access.

Logs containing sensitive information should be retained only for as long as reasonably necessary.

11. Backups

Regular backups should be maintained for critical website, database, and configuration data.

Backups should be:

  • Protected from unauthorized access.

  • Stored separately from the primary system where practical.

  • Tested periodically to verify that restoration is possible.

  • Retained according to operational and legal requirements.

Backup credentials must not be publicly exposed.

12. Malware and Unauthorized Code

The website and server environment should be periodically reviewed for:

  • Malware.

  • Unauthorized scripts.

  • Modified core files.

  • Suspicious administrator accounts.

  • Unauthorized modules.

  • Unexpected changes to website files.

  • Other indicators of compromise.

Unauthorized software or code must not be installed on the server.

13. Security Vulnerabilities

Security vulnerabilities discovered in PrestaShop, PHP, server software, modules, themes, or other components should be evaluated and addressed according to their severity.

Critical vulnerabilities should receive priority treatment.

Where an immediate fix is unavailable, reasonable temporary safeguards should be implemented when practical.

14. Security Incidents

A suspected security incident should be investigated promptly.

Examples include:

  • Unauthorized administrator access.

  • Compromised accounts.

  • Malware infections.

  • Unauthorized database access.

  • Theft or exposure of customer information.

  • Website defacement.

  • Suspicious payment activity.

  • Unauthorized changes to website files.

Appropriate containment, investigation, recovery, and notification procedures should be followed when an incident occurs.

Where legally required, affected individuals, payment providers, authorities, or other relevant parties may be notified.

15. Third-Party Services

The store may rely on third-party services such as payment processors, hosting providers, shipping services, analytics providers, email services, or PrestaShop modules.

Third-party services should be evaluated for security and reliability before being granted access to store systems or information.

Access should be limited to the minimum necessary.

16. Administrative Access

Administrative access should be limited to authorized personnel.

Where technically possible:

  • Administrative interfaces should use HTTPS.

  • Administrative URLs should not be unnecessarily exposed.

  • Administrative access should be protected against brute-force attempts.

  • Unused administrator accounts should be removed.

  • Privileged access should be reviewed periodically.

17. Security Testing

Security controls should be periodically reviewed and tested.

Testing may include:

  • Vulnerability scanning.

  • Review of administrator accounts.

  • Review of file permissions.

  • Review of installed modules.

  • Review of server configuration.

  • Backup restoration testing.

  • Password and authentication reviews.

  • Examination of security logs.

18. Employee and Administrator Responsibilities

Individuals with access to store systems are responsible for protecting their credentials and following established security procedures.

Users must promptly report suspected:

  • Account compromise.

  • Phishing attempts.

  • Malware.

  • Unauthorized access.

  • Suspicious website activity.

  • Lost or stolen devices used to access administrative systems.

19. Policy Review

This Security Policy should be reviewed periodically and whenever significant changes are made to the PrestaShop installation, hosting environment, payment infrastructure, or applicable security requirements.

The policy may be updated as new security threats, technologies, vulnerabilities, and regulatory requirements arise.

20. Disclaimer

This policy describes intended security practices and does not guarantee that the website, server, or associated systems will be completely immune from unauthorized access, vulnerabilities, attacks, or other security incidents.

Security measures are continually evaluated and improved as reasonably practical.