PS PrestaShop Beginner

Form builder for PrestaShop 8 and 9: documentation

Install the module, build a form, set up logic, steps, emails and the webhook, then manage and export submissions.

Updated Module version 1.2.2

DataFirefly Form Builder adds a drag and drop form builder to PrestaShop 8 and 9. Each form is displayed in theme positions, in a CMS page, in a popup window or on its own page. Submissions are stored in the back office, sent by email and exportable to CSV.

Installation

  1. In Modules > Module Manager, click Upload a module and drop the dfformbuilder.zip file.
  2. Two menus appear under Customer Service: Forms and Form submissions.
  3. The module’s Configure button opens the general settings (see below) and shows the number of forms and unread submissions.

Requirements: PrestaShop 8.0.0 to 9.x, PHP 7.2 or later. Files sent by visitors are stored in /upload/dfformbuilder/, which must be writable. The module uses no override.

Updating: install the new ZIP over the old one. Forms and submissions are kept, and the upgrade scripts add the new tables.

Creating a form

In Customer Service > Forms, click New form and choose a starting point:

  • Contact form: name, email, subject and message. The Order reference field only appears when the subject is about an order.
  • Quote request: individual or company (the Company and VAT fields only appear for a company), quantity, budget, deadline, attachments. On a product page, the product name is filled in automatically.
  • Job application: three steps (contact details, position, documents), required resume attached to the email.
  • Blank form.

The form list also offers Duplicate, Export (JSON file) and, in the toolbar, Import. An imported form is created disabled and without display positions.

The builder

The top bar holds the internal name of the form, the Enabled box, the editing language, the Undo and Redo buttons, Preview and Save. Below are four tabs: Fields, Settings, Emails, Display and integration.

Fields tab

  • Left column: the field types. A click adds the field below the selected one, a drag drops it where you want.
  • Center: the form as it will be displayed, with the real widths. Fields are moved by drag and drop or with the arrows on each card, and can be duplicated or deleted.
  • Right column: the settings of the selected field.

Shortcuts: Enter selects a field, Alt + arrows moves it, Delete removes it, Ctrl+Z undoes, Ctrl+Y redoes, Ctrl+S saves. The browser warns you if you leave the page with unsaved changes.

Languages

All texts (labels, help texts, options, messages, emails, URL) are entered in the language chosen at the top. A text left empty falls back to the shop’s default language, shown in grey in the input. Switch through each language before publishing.

Field key

Each input field has a technical key generated from its label (for example email, order_reference). It is the column name in the CSV export and a placeholder in emails: {email}. It must be unique within the form.

Field types

  • Text, Email, Phone, Website: placeholder, maximum length, prefill. A web address typed without https:// is completed automatically.
  • Number: minimum, maximum and step.
  • Paragraph text: height in rows, maximum length with a character counter for the visitor.
  • Date: earliest and latest date, as YYYY-MM-DD or with the word today.
  • Dropdown, Radio buttons, Checkboxes: options with a label per language and a value. The value is stored and used by the logic; left empty, it reuses the label. The Add several options at once link accepts one option per line, as label|value when needed.
  • Consent: a checkbox with a text that accepts links (privacy policy).
  • Star rating: 3 to 10 stars, stored as 4/5.
  • File upload: allowed extensions, maximum size per file (capped by the global setting), several files up to 10.
  • Hidden field: fixed or prefilled value, invisible to the visitor.
  • Heading, Text block, Separator: layout only, nothing is stored.
  • New step: splits the form into steps (see below).

Each field has a width: full, two thirds, half or one third. Narrower fields sit side by side on large screens and stack on mobile.

Prefill

Text, Email, Phone and Hidden fields can be filled with the email, first name, last name, full name or company of the signed-in customer, the product name or reference (on a product page), the page URL, or a URL parameter. Example: a hidden field prefilled with the utm_source parameter, and a link to /contact?utm_source=newsletter, stores newsletter with the submission.

Reply-to address

Tick Use as reply-to address on an Email field: replying to the notification email will write to the visitor directly.

Conditional logic

In a field’s panel, tick Show or hide this field depending on other answers, then choose:

  • Show or Hide this field;
  • if all or at least one of the conditions are met;
  • each condition: a field, an operator (is, is not, contains, does not contain, is empty, is filled in, is greater than, is less than) and a value.

For a dropdown, radio buttons or checkboxes, the value is picked from the options. A hidden field is not validated, stored or sent. The same logic is computed again on the server on submission.

Multi-step forms

Add a New step element (Layout group) where a step must start and give it a title. Fields placed before the first marker form the first step. For the visitor:

  • a progress bar and the step titles are displayed (can be turned off in Settings > Multi-step form);
  • the Next and Previous buttons have a text you set per language;
  • each step is checked before moving on;
  • a step whose fields are all hidden by the logic is skipped.

Settings tab

  • Title and introduction: title shown to visitors and introduction text.
  • Sending: submit button text, confirmation message, or redirect to a URL after sending.
  • Access: form restricted to signed-in customers (others see a link to the login page), CSS class.
  • Availability and limits: opening and closing date (shop time zone), maximum number of submissions, one submission per person (checked on the customer account and on the email typed), closing message.
  • Draft: keeps the answers for 30 days in the visitor’s browser until the form is sent. Nothing is transmitted to the shop before submission, and files are not kept.

Emails tab

Notification to the shop

Sent in the shop’s default language. Recipients are separated by commas; when the field is empty, the default recipients of the module configuration are used, then the shop email. The subject accepts the placeholders {form_name} and {field_key}, which you click to copy. The Attach the uploaded files option adds files up to 15 MB in total.

Conditional recipients

Each rule links a condition to addresses: for example, if Subject is Quote, send to sales@your-shop.com. The When a condition matches setting adds these addresses to the recipients or replaces them.

Confirmation to the visitor

Requires an Email field in the form. The email is sent in the language the visitor used, with the subject and message of your choice (placeholders accepted) and, optionally, a summary of the answers.

Webhook

Enter a URL (Zapier, Make, n8n, CRM) to receive each submission as JSON through a POST request. Example body:

{
  "event": "submission.created",
  "form": { "id": 3, "name": "Contact" },
  "submission": { "id": 128, "date": "2026-09-30T10:12:00+02:00", "language": "en",
    "shop_id": 1, "customer_id": 0, "product_id": 0, "page_url": "https://..." },
  "fields": {
    "email": { "label": "Email", "type": "email", "value": "john@example.com", "display": "john@example.com" }
  }
}

With a signing secret, the X-DFFB-Signature header contains sha256= followed by the HMAC-SHA256 of the body. Checking it in PHP:

$body = file_get_contents('php://input');
$expected = 'sha256=' . hash_hmac('sha256', $body, 'YOUR_SECRET');
$valid = hash_equals($expected, $_SERVER['HTTP_X_DFFB_SIGNATURE'] ?? '');

The call waits 5 seconds at most. Its result (delivered, refused with the HTTP code, no response) is shown on each submission page.

Display and integration tab

Display mode

Directly in the page or behind a button, in a popup window, with the button text per language. This mode applies to the positions, the shortcode and the widget.

Automatic positions

Tick the theme positions: home page (displayHome), contact page (displayContactContent, displayContactRightColumn), product page (displayProductAdditionalInfo, displayFooterProduct), reassurance (displayReassurance), cart (displayShoppingCartFooter), CMS pages (displayCMSDisputeInformation), columns (displayLeftColumn, displayRightColumn), above the footer (displayFooterBefore), bottom of the content (displayWrapperBottom). A position shows nothing if the theme does not call it.

Dedicated page

Each form can have its own page, for example /forms/3-quote-request, with a friendly URL per language. The Preview link works even while the form is disabled; submissions are refused there until it is enabled.

Integration codes

  • CMS page shortcode: [dfform id=3]
  • Smarty widget in a template: {widget name='dfformbuilder' id_form=3}
  • Custom hook: {hook h='displayDfForm' id_form=3}

Statistics

Over 30 days: views (form displayed or popup opened), starts (click in a field), submissions, conversion and abandonment rates. Visitors without JavaScript and most bots are not counted. Views and the conversion rate also appear in the form list.

Managing submissions

Customer Service > Form submissions lists submissions with the form, a summary, the status and the date, all filterable. Bulk actions: mark as read, processed, archive, export to CSV, delete (files are deleted too).

Opening a submission sets it to Read and shows:

  • every answer and the files to download;
  • the status and an internal note;
  • the customer (if signed in), the product, the page it was sent from, the language, the IP address, the email and webhook result;
  • the Print, Reply by email, previous and next submission buttons.

Replying to the visitor

The Reply to the visitor panel sends your message to the address of the Email field (the one marked as reply-to first), in the language the visitor used, with the shop’s email layout. The reply is kept in the history and the submission can be set to Processed at the same time.

CSV export

The panel below the list exports by form, status and period. Choosing a form gives one column per field. The file is UTF-8 with a semicolon separator and opens directly in Excel, LibreOffice and Google Sheets.

General module settings

  • Default recipients: used when a form has no recipient of its own.
  • Maximum file size (10 MB by default): global limit per file. It cannot exceed PHP’s upload_max_filesize and post_max_size.
  • Keep submissions for (days): after that, submissions and their files are deleted automatically. 0 keeps them forever.
  • Store the IP address: when disabled, only a hashed version is kept for the submission limit.
  • Minimum filling time (3 seconds) and submissions per hour and per visitor (10): anti-bot protections.
  • reCAPTCHA v3: site key, secret key and minimum score (0.5 recommended). The Google script only loads when the visitor starts filling in the form.

Security and GDPR

  • Each form contains an invisible trap field and a timestamped signature; a submission sent too fast or beyond the limit is refused.
  • Scripts, HTML pages and executables are always refused and file content is checked. Files are renamed randomly in a protected folder and can only be downloaded from the back office.
  • With the official psgdpr module, a customer’s submissions (account or email typed) are included in their data export and deleted with their account.

Translations

The module interface is available in English and French; other back office languages display it in English. The module’s email templates exist in English, French, German, Spanish, Italian, Dutch, Polish and Portuguese. The texts of the forms themselves are entered in every shop language.

Troubleshooting

The form does not appear

Check that the form is enabled, that the chosen position is called by your theme, and that the opening dates do not close it. If in doubt, test the shortcode in a CMS page or the dedicated page.

Emails do not arrive

The submission page shows whether the notification was sent. Check Advanced Parameters > E-mail and send a test email from PrestaShop.

A file is refused

Check the allowed extensions on the field, the maximum size of the field and of the module, and PHP’s upload_max_filesize and post_max_size limits.

The form is blocked by the anti-spam protection

A page left open for several weeks has an expired signature: the visitor must reload the page. If you use reCAPTCHA, check that the domain is declared in the Google console and lower the minimum score if real customers are blocked.

Was this page helpful?

Still stuck? Contact support