Is it real to add IP address to cart?

  • Posts: 2293
  • Thank you received: 315
7 years 3 months ago #276730

-- HikaShop version -- : 3.1.1

I am watching the carts of customers and really need to see the IP's of this customers.
I don't know why part of them abandon their carts.
So I need their IP but I can't see it...


Я не явлюсь официальной службой поддержки!
Я здесь добровольно!

Хочешь получить купон на скидку Hikashop? Спроси меня как!
Attachments:

Please Log in or Create an account to join the conversation.

  • Posts: 82863
  • Thank you received: 13372
  • MODERATOR
7 years 3 months ago #276738

Hi,

Thank you for your feedback. That's an interesting feature.
We'll add that.

The following user(s) said Thank You: progreccor, kyratn

Please Log in or Create an account to join the conversation.

  • Posts: 329
  • Thank you received: 94
7 years 3 months ago #276835

I love this idea, but when you add it would you please make it configurable (Store customer IP with cart information, Yes/No, defaulted to No).

Because with the new privacy regulations taking effect next year for all European customers, storing the IP of a casual browser could be an issue for some stores. www.eugdpr.org/the-regulation.html


~ Deb Cinkus, CEO

Polished Geek: more with monday․com
eCommerce Business Process Automation Experts

Please Log in or Create an account to join the conversation.

  • Posts: 82863
  • Thank you received: 13372
  • MODERATOR
7 years 3 months ago #276838

Hi,

Hmm. That's an interesting point you're bringing here.
What about the ip of the user, the IP of the affiliates, the IP of the order ?
HikaShop stores the IP addresses as it is in some countries a legal requirement (for orders, or even user accounts).
I also didn't find any clear information that it would be problematic to store the IP address.
Would you have more information on your end about that ?

Please Log in or Create an account to join the conversation.

  • Posts: 329
  • Thank you received: 94
7 years 3 months ago #276872

Under the FAQ section, it says this (emphasis added):

What constitutes personal data?
Any information related to a natural person or ‘Data Subject’, that can be used to directly or indirectly identify the person. It can be anything from a name, a photo, an email address, bank details, posts on social networking websites, medical information, or a computer IP address.

www.eugdpr.org/gdpr-faqs.html

We're just now starting to examine what this will mean for our own clients, so I'm not an expert on it yet, but it's not good. It's going to affect everything from contact forms storing data in the Joomla database to questions like "should we store the IP of a visitor's cart?"

There's a fairly comprehensive blog post about how this is affecting Wordpress sites here: www.codeinwp.com/blog/complete-wordpress-gdpr-guide/


~ Deb Cinkus, CEO

Polished Geek: more with monday․com
eCommerce Business Process Automation Experts

Please Log in or Create an account to join the conversation.

  • Posts: 329
  • Thank you received: 94
7 years 3 months ago #276873

To add one more comment... I think there's a big difference between storing the IP address of an order, which may be needed to prove the order is legitimate, vs. storing the IP of a visitor who is just shopping around.


~ Deb Cinkus, CEO

Polished Geek: more with monday․com
eCommerce Business Process Automation Experts

Please Log in or Create an account to join the conversation.

  • Posts: 2293
  • Thank you received: 315
7 years 3 months ago #276885

Every web server have log files that writes all IP's of the site visitors. So independently of hikashop and others programs all sites writes and stores IP's of all visitors and there is no other way to work!


Я не явлюсь официальной службой поддержки!
Я здесь добровольно!

Хочешь получить купон на скидку Hikashop? Спроси меня как!

Please Log in or Create an account to join the conversation.

  • Posts: 82863
  • Thank you received: 13372
  • MODERATOR
7 years 2 months ago #276906

Hi,

Thanks for the additional information @PolishedGeek and thank you for the counter argument @progreccor.
It's true that the server logs the IP address for every page request anyways.
However, it's done in the server access logs that a hacker wouldn't normally have access to even if he was able to have a backend / database access (of course, everything is possible if the website / server is not configured properly or if the hacker is able to elevate the user permissions etc).
All in all, it's a matter of how far you want to go.
Some pages online also mentioned the need to encrypt the user data... But I don't see how we could realistically encrypt the user data (email address, IP address, address of the user in an order, etc). That would be so impractical for an ecommerce website and so much overhead for something an attacker would still be able to circumvent.
So I'm not sure if it would be useful to add such an option for the cart user IP address or if other things should be done. The GDPR is for now a big mess as there is no clear cut on anything technical. Of course, they say that the user address should be securized (encrypted, anonymized) but, they don't talk about how impossible this would be for the address of the user in an order on an ecommerce website and what should be done in that case.

Please Log in or Create an account to join the conversation.

Time to create page: 0.071 seconds
Powered by Kunena Forum