PrestaShop GDPR & Legal ★ 5.0 · 1 review

DataFirefly Cookie Manager — powered by the open-source tarteaucitron.js engine

The GDPR-compliant cookie banner without giving up measurement.

Data protection authorities have multiplied sanctions on non-compliant cookie banners. Cookie Manager Tarteaucitron brings your PrestaShop store up to date with the latest requirements: modern Axeptio-style banner, Google Consent Mode v2 pre-integrated, consent audit log, automatic third-party service scanner, and 11 major services (GA4, GTM, Meta Pixel, TikTok, Hotjar, Microsoft Clarity, etc.) ready to use. The module uses the open-source tarteaucitron.js engine with a modern UX layer and a complete audit system for DPA inspections.

At a glance
  • Consent banner built on the open-source tarteaucitron.js engine
  • tarteaucitron files served from your own domain: no third-party CDN call before consent
  • Google Consent Mode v2, with the default state derived from the existing cookie
  • Timestamped consent log, CSV export, IP never stored in clear text
  • 11 ready-to-use services plus an automatic tracker scanner
PrestaShop 8 + 9 Consent Mode v2 Self-hosted Consent log Multistore Auto scanner
  • 30-day refund
  • 12 months updates
  • 24h support
www.datafirefly.com/en/
tarteaucitron cookie consent banner on PrestaShop
v1.3.0 · updated 2026-09-13
What it does

The short version.

01

GDPR compliance without the busywork

A banner that follows CNIL guidance: refusing is as easy as accepting, and no non-essential service loads before the visitor has chosen.

02

Nothing reaches a third party before consent

The tarteaucitron files are served from your own domain, in 36 languages. The visitor's IP address is never handed to an external CDN when the page loads.

03

Google Consent Mode v2

Granted and denied signals sent automatically to GA4, Google Ads and GTM. The default state is derived from the existing cookie, so there is no transient denied window eating your conversions on every page reload.

04

Proof of consent you can actually produce

A timestamped log with an anonymous visitor ID and a salted IP fingerprint, exportable to CSV and purged automatically beyond the retention period you set.

The long version

Everything you'd want to know before you install.

A detailed look at how DataFirefly Cookie Manager — powered by the open-source tarteaucitron.js engine works, why we built it the way we did, and the thinking behind the features above.

§ 01

Why a dedicated GDPR module

The French data protection authority has been actively auditing cookie banners since 2022, and other European regulators have followed. The findings are consistently the same three: refusing is harder than accepting, third-party cookies are dropped before consent, and the merchant cannot prove consent was ever collected. Cookie Manager Tarteaucitron addresses all three.

§ 02

The tarteaucitron engine, with a current interface

tarteaucitron.js is the most established open-source consent manager in France, used by government sites. It is technically solid, but its interface has aged. The module keeps the engine, which is what makes it reliable, and wraps it in an animated floating card with per-category toggles, fully configurable from the back office.

§ 03

The detail that matters: where the files are served from

A cookie banner that loads its own files from a CDN hands the visitor's IP address to a third party before they have chosen anything. That single detail undermines the whole banner. The module bundles tarteaucitron and its 36 languages, served from your domain. The CDN remains available as an option, but it is not the default.

§ 04

Consent Mode v2 without losing measurement

Many merchants assume compliance means losing half their analytics. With Consent Mode v2, your tags keep sending anonymised signals that feed modelled conversions. The module goes further: the default state is derived from the existing consent cookie, which removes the transient denied window that eats conversions on every page reload for visitors who already accepted.

§ 05

A log you can actually hand over

Article 7 of the GDPR requires you to demonstrate that consent was given. Every action is recorded with its timestamp, an anonymous visitor ID, the accepted categories and the per-service detail. The IP address is never stored in clear text: only an HMAC-SHA256 fingerprint salted with a shop-specific key. The log exports to CSV, purges itself beyond the retention period you set, and survives uninstalling the module.

§ 06

Stripe and strictly necessary cookies

Stripe drops cookies required for payment fraud prevention, which fall under the exemption for strictly necessary trackers. Blocking them would break checkout. The module loads them without asking, while showing them in the Always on category of the preferences panel so the visitor is informed.