# Cookie Manager Tarteaucitron — Complete guide

> Overview Cookie Manager Tarteaucitron is a cookie consent module for PrestaShop 8.0+ and 9.x. It combines the open-source tarteaucitron.js engine, which genuinely blocks services before consent, with a modern interface:…

- Page: <https://www.datafirefly.com/en/documentation/cookie-manager-tarteaucitron/>
- Language: en
- Last updated: 2026-09-13
- Other languages: [fr](https://www.datafirefly.com/documentation/cookie-manager-tarteaucitron/index.md), [es](https://www.datafirefly.com/es/documentation/cookie-manager-tarteaucitron/index.md), [de](https://www.datafirefly.com/de/documentation/cookie-manager-tarteaucitron/index.md), [it](https://www.datafirefly.com/it/documentation/cookie-manager-tarteaucitron/index.md), [pl](https://www.datafirefly.com/pl/documentation/cookie-manager-tarteaucitron/index.md), [nl](https://www.datafirefly.com/nl/documentation/cookie-manager-tarteaucitron/index.md), [pt](https://www.datafirefly.com/pt/documentation/cookie-manager-tarteaucitron/index.md)
- Index: <https://www.datafirefly.com/en/documentation/llms.txt>

## Overview

Cookie Manager Tarteaucitron is a cookie consent module for PrestaShop 8.0+ and 9.x. It combines the open-source tarteaucitron.js engine, which genuinely blocks services before consent, with a modern interface: an animated floating card, per-category toggles and a reopen pill. The module includes Google Consent Mode v2, a tracker scanner with one-click activation, and an exportable consent log.

Since version 1.2.0 the tarteaucitron files are served from your own domain, so no request is sent to a third-party CDN before the visitor has consented.

## Installation

1. Go to **Modules → Module Manager → Upload a module**.
2. Upload `datafirefly_tarteaucitron.zip`.
3. Click **Install**, then **Configure**.

The configuration screen is reachable two ways, both showing the same page: the **Configure** button in the Module Manager, or the **Cookie Manager** menu entry added on install.

After any module update, clear the PrestaShop cache from **Advanced Parameters → Performance**. The upgrade script also resets the PHP OPcache when it is allowed to.

## Upgrading from an earlier version

Overwrite `/modules/datafirefly_tarteaucitron/` or install the new ZIP from the back office. The upgrade script runs automatically and handles the log table if missing, the new configuration keys, the renamed banner positions (`bottom` becomes `bottom-left`, `middle` and `popup` become `center`) and the menu entry if absent.

If you were using the `middle` or `popup` position, the banner becomes a centred modal with a dimmed backdrop. The behaviour is correct, but the rendering visibly changes: check it before going live.

## General settings

- **Module enabled**: master switch for the banner on the front office.
- **Banner language**: on automatic, it follows the PrestaShop language of the page. You can also force one of the 36 bundled languages.
- **Banner position**: bottom left or right, top left or right, or centred as a modal.
- **tarteaucitron files**: self-hosted, recommended, or the jsDelivr CDN. See the dedicated section below.
- **Consent expiry**: 365 days by default. Regulators recommend staying under 13 months, so 395 days.
- **Cookie name**: `tarteaucitron` by default. Changing it resets the consents already collected, since the old cookie is no longer read.
- **Cookie domain**: leave empty for the current domain, or prefix with a dot to share consent across subdomains.
- **Reopen pill**: shows a small Cookies pill after consent. See the withdrawal section.
- **Close means refuse**: adds a cross that refuses all non-essential cookies. Disabled, the banner requires an explicit choice.

The **Texts & links** tab customises the title, message and button labels; an empty field falls back to the module's own text in the banner language. The **Design** tab controls colours and corner radius, with a live preview and a WCAG contrast check between the button colour and its text.

## Where the tarteaucitron files are served from

A cookie banner that loads its own files from a CDN hands the visitor's IP address to a third party before they have chosen anything. The module therefore bundles tarteaucitron.js 1.30.0 and its 36 language files in `views/vendor/tarteaucitron/`, served from your domain.

The **jsDelivr CDN** option remains available in the General tab. It is not recommended: it hands the visitor's IP address to jsDelivr as soon as the page loads, before any consent.

## Enabling services

The **Services** tab lists the 11 built-in integrations. For each one, turn the switch on and fill in the requested identifier:

- **Google Analytics 4**: Measurement ID, format G-XXXXXXXX
- **Google Tag Manager**: Container ID, format GTM-XXXXXX
- **Google Ads**: Conversion ID
- **Meta Pixel**: numeric Pixel ID
- **Hotjar**: numeric Site ID
- **LinkedIn Insight**: Partner ID
- **TikTok Pixel**: Pixel ID
- **Microsoft Clarity**: Project ID
- **Intercom**: App ID
- **YouTube**: no identifier, enables blocking of embedded videos before consent
- **Stripe**: no identifier, see the dedicated section

A service enabled without its identifier is not loaded on the front office. The module flags it in red in the table and warns on save, but do check your identifiers after using the scanner's one-click activation.

The identifier field locks when its service is switched off. The stored value is kept, so switching the service back on restores it.

## Scanner and automatic detection

1. Click **Scan the site now** in the **Auto detection** tab. The module reads the cookies set on your domain and fetches your front office HTML to parse third-party script tags.
2. Two tables appear: detected cookies with their likely service and category, and identified third-party scripts with their current state in the module.
3. Click **Enable detected services**, then save.
4. Go to the Services tab to fill in the identifiers of the newly enabled services.

The scanner recognises Google Analytics, Google Tag Manager, Google Ads, Meta Pixel, Hotjar, LinkedIn, TikTok, Microsoft Clarity, Intercom, Brevo, Stripe and YouTube, plus the functional PrestaShop cookies.

Browse your front office in the same browser first, then run the scan: the cookies dropped by your trackers will be visible and detection will be more complete. If the back office and the front are on different domains, only script analysis works.

## Statistics and A/B testing

Since version 1.3.0, the **Statistics & A/B** tab measures what the banner actually achieves. The module counts impressions, not just answers, which is what makes the acceptance rate computable.

- **Metrics**: impressions, response rate, “accept all” rate, refusal rate, custom-choice share, opt-in per category, desktop / mobile split and daily trend, over 7, 30, 90 or 365 days, or the whole history.
- **Privacy**: counters are aggregated per day, variant and device type in the `dftac_banner_stats` table. No personal data, no visitor identifier, no cookie. An impression is counted once per visit through a local session marker.
- **Bots**: a server-side user-agent filter rejects search engines and audit tools, and an impression is only counted on the visitor's first gesture (pointer, key, scroll or answer). Without that filter, bots that run JavaScript inflate the denominator without ever answering, dragging the rate down.
- **Export and reset**: CSV export of the counters and a reset button, both independent from the GDPR log.

### Running an A/B test

1. Enable the test and set the share of traffic sent to variant B. 50% gives a readable result fastest.
2. Fill in only the fields you want to test: title, message, the three button labels, position. Empty fields fall back to variant A.
3. Let it run. The draw stays stable for the whole visit.
4. Read the verdict: the module compares both rates with a two-proportion z-test and only announces a winner beyond 100 impressions per variant and a gap significant at 95%.
5. Copy the winning wording into variant A, then switch the test off.

The setting that moves the acceptance rate most is the position: compare the centred modal against the corner card before fine-tuning wording.

## Google Consent Mode v2

Mandatory since March 2024 for European advertisers, Consent Mode v2 lets Google model conversions even when consent is refused. The module emits the seven required signals (`ad_storage`, `ad_user_data`, `ad_personalization`, `analytics_storage`, `functionality_storage`, `personalization_storage`, `security_storage`) as _default_ in the ``, before any tag, then updates them as soon as the visitor answers. Each default state is configurable, with `denied` recommended in the EEA.

One specific point: the default state is **derived from the existing consent cookie** when there is one. A visitor who already accepted gets `granted` on the first frame, with no transient `denied` window eating your Google Ads conversions on every page reload. The same service-to-signal mapping is used server side and browser side, so the default and the update always agree.

**wait_for_update** sets how long Google waits for the banner before sending data. 500 ms is the recommended value.

## Stripe and strictly necessary cookies

The Stripe cookies (`__stripe_mid`, `__stripe_sid`) are required for payment fraud prevention and fall under the exemption for strictly necessary trackers: blocking them would break checkout. When the Stripe service is enabled it loads without asking for consent and appears in the preferences panel under **Essentials and payment** with an Always on badge. The visitor is informed, and no payment is ever blocked.

## Withdrawing consent

The GDPR requires withdrawing consent to be as easy as giving it. Three ways are available and can be combined:

- the **floating pill** shown after the choice, enabled in the General tab;
- a footer link: `[Manage my cookies](#tarteaucitron)`;
- a JavaScript call: `dftacOpenPreferences()`, from any element of your theme.

If you disable the pill, put one of the other two in place. Without it, the visitor can no longer revisit their choice.

## Custom services

The **Custom services** tab adds any third-party script missing from the list: a unique lowercase key, a display name, a category (`analytic`, `ads`, `social`, `video`, `support`, `api` or `other`), the JS executed only after consent, the cookie names it drops, and a privacy policy URL. Custom services appear in the banner under their own category with their own toggle, and their category determines the associated Consent Mode signal.

The code entered here runs as-is on the front office. Only paste code whose origin you control.

## Consent log

Article 7 of the GDPR requires you to demonstrate that consent was given. The **GDPR log** tab shows the records page by page, each with its date and time, the anonymous visitor ID, the accepted categories and the per-service detail.

- The IP address is **never stored in clear text**: only an HMAC-SHA256 fingerprint salted with a shop-specific key. A plain unsalted SHA-256 would be recoverable by brute force over the IPv4 space.
- The visitor ID comes from a dedicated technical cookie and holds no personal data.
- Server-side deduplication ignores a second identical submission from the same visitor within 5 seconds, which neutralises double clicks.
- The consent beacon uses `keepalive`, so it completes even if the visitor navigates away immediately after choosing.
- An automatic purge removes entries beyond the retention period you set. It runs when the configuration page is opened, at most once a day.
- **Export to CSV** produces a timestamped file, UTF-8 with a BOM so it opens correctly in Excel.
- The log is **kept if the module is uninstalled**, preserving your audit trail.
- Logging can be switched off if you do not want to keep this record.

## Multistore

Each shop has its own configuration: enabled services, texts, colours, position and Consent Mode settings. The banner at the top of the configuration screen reminds you which shop you are editing.

## Troubleshooting

- **The banner does not appear**: check that the module is enabled in the General tab, clear the PrestaShop cache, and make sure no other consent module is running in parallel.
- **Choices are not remembered**: delete the old consent cookie in your browser before testing again, and check that the cookie name has not changed since the last consent.
- **A service does not load after acceptance**: check that its identifier is filled in. An empty identifier on an enabled service is flagged in red in the table.
- **The scan finds nothing**: browse the front office in the same browser first, then run the scan again.
- **Nothing in the log**: check that logging is enabled in the GDPR log tab, then consent again from the front office in a private window.
- **A module change has no effect**: clear the PrestaShop cache and, if your host uses OPcache, reload PHP. The upgrade script resets OPcache automatically when it can.

Need help? Contact DataFireFly support from your customer account, reply within 24 business hours.
