PrestaShop Marketing & Promotions

Private Shop and Hidden Prices for PrestaShop 8 & 9

A shop reserved for members, prices hidden from visitors, a polished sign-in page with image or video and Google, Facebook, Apple or Instagram login.

You sell to trade customers, you run private sales, or you simply do not want your prices to be public. This module closes your shop to visitors without an account, either entirely or only on the categories, products, brands and pages you pick. Access requests are approved one by one in the back office, with follow-up emails. The sign-in page is a real page, full screen or split in two, with an image, a slideshow or a video, and Google, Facebook, Apple and Instagram buttons. Third mode: the catalog stays public and indexable, and only prices and the add to cart button are reserved for members.

At a glance
  • Whole shop private, or only the chosen categories, products, brands, suppliers, CMS pages and URLs
  • Members-only pricing mode: public indexable catalog, prices and cart hidden from visitors
  • Full screen or split sign-in page, image, slideshow or video background, three card styles
  • Google, Facebook, Apple and Instagram sign-in, with no external SDK
  • Access request approval in the back office, invitation codes, IP whitelist
PrestaShop 8 & 9 B2B Social login Private sales
  • 30-day refund
  • 12 months updates
  • 24h support
www.datafirefly.com/en/
Private Shop and Hidden Prices for PrestaShop 8 & 9
v1.2.1 · updated 2026-09-22
What it does

The short version.

01

Three ways to close the shop

The whole shop behind a sign-in page, only the parts you select, or an open catalog with hidden prices. The CMS pages you want public and the contact page stay reachable in every case.

02

A sign-in page that looks like your brand

Full screen with the card on the left, centre or right, or a split layout with media on one side and the form on the other. Image background, three-image slideshow, self-hosted video, YouTube or Vimeo, with an overlay, an accent colour, your logo and three card styles including frosted glass.

03

Google, Facebook, Apple and Instagram

Four social logins implemented in plain OAuth 2.0 and OpenID Connect with no third party SDK: PKCE for Google, appsecret_proof for Facebook, an ES256 signed client secret JWT for Apple. A customer signing in with an email already in use links both accounts after entering the password once.

04

No private product leaking elsewhere

In selected parts mode, private products also disappear from listings, search, autocomplete, faceted filters and home page product blocks. Pages rendered for members are sent with headers that forbid caching.

The long version

Everything you'd want to know before you install.

A detailed look at how Private Shop and Hidden Prices for PrestaShop 8 & 9 works, why we built it the way we did, and the thinking behind the features above.

§ 01

Closing the shop without losing your rankings

Closing everything suits a B2B shop or a private club, but it costs Google visibility. The module therefore offers three levels. Whole shop: every page requires an account, except the CMS pages and the contact page you keep public. Selected parts: only the categories, products, brands, suppliers, CMS pages or URL patterns you designate are protected. Members-only pricing: the catalog stays public and indexable, but prices and the add to cart button only appear for approved customers.

§ 02

A private page, not a blunt redirect

The private page is standalone: it loads no menu, no search and no cart, so nothing of the catalog shows through. It displays your texts, your logo, the language switcher and up to three tabs: sign in, request access and invitation code. The background accepts an image, a three-image slideshow, a video hosted on the shop, a YouTube video in enhanced privacy mode or a Vimeo video. The video loads neither on phones by default, nor when the visitor has data saver on or asked for reduced motion.

§ 03

Account approval and request tracking

Each access request creates an inactive account and a row in the Customers > Access requests screen. You approve or reject, one by one or in bulk, and the customer gets the matching email. Addresses from your trusted domains can be approved automatically. The customer page recalls the request and the linked social accounts. Activating a customer from the back office also approves their request and sends the email, with nothing else to do.

§ 04

Social login with no SDK and no dependency

The four providers are implemented directly in OAuth 2.0 and OpenID Connect: PKCE S256 for Google, appsecret_proof for Facebook, a client secret signed in ES256 from the .p8 key for Apple, and Business Login for Instagram. No third party library, no Composer. The back office shows the exact redirect URI to declare with each provider, and you only enable the providers you want. Since Instagram never returns an email address, the customer types it in a short form after signing in.

§ 05

What other modules let through

Protecting a product page is not enough: its name, image and price stay visible in search, home blocks and filters. Here, private products are removed from listings, search, autocomplete, facets and the product blocks of any module, even when their HTML comes from the cache. Pages rendered for a member, an invitation code, a whitelisted IP or a bot are sent with no-store headers, including for LiteSpeed and CDN caches, so a cache never serves them to an anonymous visitor.