Skip to content
Independently verified · Quarterly re-audit
EU VETTED

PrestaShop

VERIFIED
E-commerce · France
Founded 2007 · prestashop.com ↗

French open-source e-commerce with hosted SaaS option; parent group Fortidia is an Oaktree Capital portfolio company.

Why this score?

PrestaShop SA (Paris, 82 Avenue du Maine 75014, SIREN 497 916 635, founded 2007) is French-operating but sold to MBE Worldwide (Italy) November 2021; MBE rebranded as Fortidia in 2024, and Fortidia is a portfolio company of Oaktree Capital Management (US asset manager) — so ultimate beneficial ownership is US, flipping the ownership signal to eu_hq_us_funded and material CLOUD Act exposure; DPA + sub-processors not publicly surfaced caps score at 3/5.

SCORE
3.0/5
CLOUD ACT
OWNERSHIP
SUB-PROCS
not disclosed
JUMP TO
OVERVIEW

About PrestaShop

**PrestaShop** (Paris, est. 2007, **250,000+ live sites** per their homepage) is the historical French Magento-equivalent: a free open-source e-commerce platform plus a paid **PrestaShop Hosted** offering for merchants who want managed hosting. Acquired by **MBE Worldwide** (Italy) in November 2021; MBE rebranded as **Fortidia** in 2024; Fortidia is a **portfolio company of US-based Oaktree Capital Management**. So the operating entity is French and the brand is French, but the ultimate beneficial owner is a US asset manager — relevant for procurement-grade CLOUD Act assessment. Best fit for merchants who want full platform control with French community + ecosystem; PrestaShop Hosted targets those who want the OSS power without the ops burden. Closer to mid-market than to SMB Shopify-Basic class.
SUB-PROCESSORS

Sub-processor map · not disclosed

Vendor does not publish a sub-processors list. Schrems II compliance and CLOUD Act exposure cannot be independently verified without it.
CERTIFICATIONS

Frameworks & certifications · none listed

We checked the vendor's website and standard certification body registries. No active certifications found at the time of last audit (2026-05-12).
FEATURES

Capability matrix

INTEGRATION & ACCESS
REST API Yes
SSO (SAML / OIDC) Yes
COMPLIANCE & GOVERNANCE
Audit log Yes
Self-host / on-prem option Yes
PRICING

Pricing & tiers

FREEMIUM
Custom pricing

Contact vendor for tier or volume pricing.

View pricing page ↗
PUBLIC DOCUMENTS

Public documents

Vendor does not publish a public DPA. Without a publicly accessible Data Processing Addendum, small EU customers cannot self-serve the processor agreement — this caps the compliance score (see How we score).
Vendor does not publish a sub-processors list. Schrems II compliance and CLOUD Act exposure cannot be independently verified without it.
  • Data Processing Addendum (DPA)
    — missing
    missing
  • Sub-processors list
    — missing
    missing
  • Terms of Service
    www.prestashop.com/en…
    Open ↗
ALTERNATIVES

Alternatives in this category