Updated: May 2019
The personal data that you provide may be regarded as jointly controlled by Kering SA, by Gucci and by the Gucci local retail legal entities “Store”.
1. Personal Data We May Collect About You
We will collect various types of personal data about you for the purposes described in this Policy, including:
• Contact information (such as your name, birthday, nationality, email address, postal address, telephone number and any other personal data) that you provide by completing forms on the Website, including if you subscribe to our newsletter and register and create an account on the Website;
• Details of any transactions made by you;
• Personal data that may be contained in communications you send to us, for example to report a problem or to submit queries, concerns or comments regarding the Website or its content;
• Other personal data that you share voluntarily with our store or client services personnel;
• Information from surveys that we may, from time to time, conduct on the Website for research purposes, if you choose to respond to, or participate in, them;
• Credit/debit card information which is considered to be sensitive personal data in certain countries such as Mexico;
• Information about your use and navigation of our Website, such as your IP address and other device identifiers, your operating system and browser type, and information about the Website pages you visit, collected thanks to cookies;
• We may also collect information about how your device has interacted with us, including the pages accessed and links clicked, how you navigate to and from the Gucci sites and Gucci content (such as how you scroll over the Gucci Sites and Gucci Content, which parts you click and how long you spend on each page), your preferences, the products and/or services that you have viewed or searched for, crashes and download errors and response times; and
• Personal information collected from third parties, such as data that you agree to share with us on publicly accessible social networks (e.g., Facebook, Instagram, etc.) and/or that we may collect from other publicly accessible databases.
You are under no obligation to provide any such information. Providing your personal data to us (in particular, your personal details, your email, your address, your credit/debit card numbers and bank code and your telephone number) is necessary for processing your order for the purchase of products on the Website, supplying other services provided on the Website upon your request, or when your personal data is needed to fulfil obligations required by law or regulations. The refusal to provide us with any personal data necessary for performing the above purposes may consequently prevent us from processing your order for the purchase of products sold on the Website or fulfilling obligations required by law and other regulations. Therefore, failure to provide personal data may constitute, in some cases, a legitimate and justified reason for not processing your order for the purchase of products sold on the Website or not providing the Website’s services.
Disclosure of further personal data to us other than that required for fulfilling legal or contractual obligations and to properly browse our services with necessary traffic data is, on the contrary, optional and does not have any effect on the use of the Website and of its services or on the purchase of products on the Website. We will inform you at every step whether disclosing your personal data to us is required or optional by marking with an appropriate symbol (*) the information that is required or data needed for the purchase of products and/or for the provision of requested services on the Website.
2. Minimum Age
Protecting the safety and privacy of children is very important to us. We do not accept registrations or orders submitted by, and will not knowingly collect or use personal data from anyone under the age of thirteen (13). By registering or making any purchase on the Website, you confirm that you have reached the age of majority in your country of residence. If we become aware that we have inadvertently received personal data from anyone under the age of 13 on this Website, we will delete the data from our records.
4. Use Made of Your Personal Data
Whenever we process your personal data, we do so on the basis of a lawful "justification" (or legal basis) for processing. In the majority of cases, the processing of your personal data will be justified on one of the following bases:
• processing is necessary to perform a contract with you or take steps that you have requested in order to enter into a contract (e.g., sale contract);
• processing is necessary for us to comply with a legal obligation;
• processing is in our legitimate interests as a business, and our interests are not overridden by your interests, fundamental rights or freedoms. Our legitimate interests may include our interest in using customer and Website user personal data to conduct and develop our business activities (including by carrying out standard marketing activities), with current and potential customers and Website users; and in establishing, exercising or defending legal claims; or
• processing is based on your prior explicit consent, such as segmented and customized marketing activities.
The purposes for which we process your personal data are the following:
The processing of your personal data is justified by the following legal basis:
Process your purchases and to provide you with the services and information offered through the Website and which you request
Performance of a contract
Administer your account with us
Performance of a contract
Verify and carry out financial transactions in relation to payments you make
Performance of a contract
Audit the downloading of data from the Website
Our legitimate interest to get to know our customers better and improve our services accordingly
Improve and customise our Website, and our products, services and our business in general, such as by tracking your product preferences, shopping history and interactions with the Website
Our legitimate interest to improve our products and services
Identify visitors to the Website
Our legitimate interest to get to know our customers better and improve our services accordingly
Data analytics, market research purposes (surveys, customer satisfaction, etc.) and data enrichment. This includes second party data matching (i.e., the activity of matching and sharing trusted partner data where two individual brands contract together to match their own data through clients unique identifiers and reidentification, i.e., enriching our database with additional client insight gathered through activities on our digital media).
On the basis of our legitimate interests in analyzing and learning how customers use and interact with Gucci in order to improve products, services and our business in general.
Correspond with you to resolve your queries or complaints
Your prior explicit consent
Global or local marketing purposes (to communicate with you on Gucci updates about our products and services, invitations and other marketing communications that may be of interest to you by one or several of the following channels: SMS, MMS, e-mail, paper mail, internet, social media or telephone), and (ii) for customizing your experience with us to your interests and shopping habits (e.g., tailored communications) and improving our services, notably via profiling, including conducting lookalike targeting campaigns by the selection of your advertising impressions across our websites
Your express prior written consent, as and to the extent required by applicable law
5. Disclosure of Your Personal Data
We may disclose your personal data to any of our affiliate companies, or to our service providers who have a legitimate interest in receiving your personal data, specifically and exclusively in order to assist us in providing the services we offer, processing transactions, fulfilling requests for information, receiving and sending communications, updating marketing lists, analyzing data, providing support services or in performing other tasks, from time to time.
For the avoidance of doubt, we will get your express opt-in consent before we share your personal data with any third party company other than Gucci and Kering for such third party company’s marketing purposes.
Your personal data will be accessible by authorized personnel of Kering, Gucci and affiliated companies, and service providers acting on our behalf on a need-to-know basis. Transfer of your personal data from your country of residence to third countries where we operate, including France, Italy and Switzerland, will be involved; some of these countries are subject to a data protection and privacy regulations similar to yours, whereas others are not. To ensure the protection of your personal data is consistent with applicable law, such transfers and processing outside your country of residence or the EEA will be made pursuant to the EU Model Clauses, or any similar legal mechanisms acceptable locally.
We may also share your personal data with third parties in connection with potential or actual sale or restructuring of our company or any of our assets, or those of any associated company, in which case personal data held by us about our users may be one of the transferred assets.
We will also respond to requests for personal data where required by to do so by law, or when we believe that disclosure is necessary to protect our rights and/or comply with a judicial proceeding, court order, request from a regulator or any other legal process served on us.
We have adopted security measures to protect personal data against accidental or unlawful destruction, accidental loss, alteration, unauthorized disclosure or access. For the best possible protection of your personal data outside the limits of our control, your device should be protected (such as by updated antivirus systems) and your internet service provider should take appropriate measures for the security of network data transmission (such as, for example, firewalls and anti-spam filtering).
While we take reasonable steps to protect your personal data, we cannot guarantee that the personal data you disclose to us will be 100% secure.
You accept the inherent security implications of dealing on-line over the Internet and will not hold Gucci, Kering or their processors responsible for any data breach unless it is due to our negligence.
7. Retention of Your Personal Data
Our general approach is to retain your personal data only for as long as required to fulfil the purposes for which it was collected. We generally retain your personal data for 5 years from the last contact you initiated with either Gucci or Kering. “Last Contact” shall be defined as the last contact initiated by you and traceable by our systems or our personnel.
Examples of such Last Contact would be the last time a call, sales email, or appointment was proposed to you to which you responded favorably by, for instance, clicking on the link to our website included in the email or attending an appointment in one of our stores. Simply opening an email from Gucci or Kering would not qualify as Last Contact. However, clicking on a link included in an email would constitute Last Contact.
However, in some circumstances we may retain personal data for longer periods of time, for instance where we are required to do so in accordance with legal, tax and accounting requirements.
In specific circumstances we may also retain your personal data for longer periods of time corresponding to the applicable statute of limitations so that we have an accurate record of your dealings with us in the event of any complaints or challenges.
8. Your Rights
You have the following rights with respect to your personal data:
• Right to withdraw consent - where applicable, you have the right to withdraw your consent at any time. For example, if you wish to opt-out of receiving electronic marketing communications, you can change your settings in your account on the Website, use the 'unsubscribe' link provided in our emails or text the STOP number in our SMS, or otherwise contact us directly and we will stop sending you communications.
• Right of access, rectification and erasure - you have the right to request access to and obtain a copy of any of your personal data that we may hold, to request correction of any inaccurate data relating to you and to request the deletion of your personal data under certain circumstances. You can see and update most of this data yourself online, or by contacting directly firstname.lastname@example.org.
• Right of data portability - Under certain conditions, you have the right to receive all such personal data which you have provided to us in a structured, commonly used and machine-readable format, and also to require us to transmit it to another controller where this is technically feasible.
• Right to restriction of processing - you have the right to restrict our processing of your personal data where:
o you contest the accuracy of the personal data until we have taken sufficient steps to correct or verify its accuracy;
o the processing is unlawful but you do not want us to erase the data;
o we no longer need your personal data for the purposes of the processing, but you require such data for the establishment, exercise or defense of legal claims; or
o you have objected to processing justified on legitimate interest grounds (see below) pending verification as to whether we have overriding compelling legitimate grounds to continue processing.
Where personal data is subject to restriction in this way, we will only process it with your consent or for the establishment, exercise or defense of legal claims, in accordance with local legislation.
• Right to object to processing justified on legitimate interest grounds - where we are relying upon legitimate interest to process personal data, then you have the right to object to that processing. If you object, we must stop that processing unless we can either demonstrate compelling legitimate grounds for the processing that override your interests, rights and freedoms or where we need to process the data for the establishment, exercise or defense of legal claims. Where we rely upon legitimate interest as a justification for processing we believe that we can demonstrate such compelling legitimate grounds, but we will consider each case on an individual basis.
• Information for California Residents – If you are a California resident, you may request a list of certain categories of personal data that we have disclosed to third parties for their own direct marketing purposes during the immediately preceding calendar year, as well as the identity of those third parties. You may make one request per calendar year. In your request, please attest to the fact that you are a California resident and provide a current California address for your response. You may request this information in writing by contacting us at: email@example.com. Please allow up to thirty (30) days for a response.
You also have the right to lodge a complaint with your local supervisory authority if you consider that the processing of your personal data infringes applicable law or the CNIL, as Kering Lead Supervisory Authority under the GDPR: COMMISSION NATIONALE DE L'INFORMATIQUE ET DES LIBERTÉS, 3 Place de Fontenoy - TSA 80715 - 75334 PARIS CEDEX 07, Tel: +331 53 73 22 22.
For further information regarding your rights, to exercise any of your rights, or if you have any complaints or questions regarding the processing of your personal data please contact firstname.lastname@example.org.
Please note that we may request proof of identity, and where permissible under applicable law, we reserve the right to charge a fee where permitted by law, for instance if your request is manifestly unfounded or excessive. We will endeavour to respond to your request as soon as possible and in any case within the applicable timeframes.
9. Changes to this Policy
We may occasionally change this Policy, for example, to comply with new requirements imposed by the applicable laws or technical requirements. We will post the updated Policy on the Website. We may also notify you in case of material changes and seek your consent to those changes, where required by applicable law. You are thus encouraged to periodically review this page.
Last Updated October 2015
What is a cookie?
Cookies are text files containing small amounts of information that a user’s device (computer, tablet or mobile) downloads when it visits a website. They allow the site to “remember” your computer, but not specifically who is using it, and improve your user experience. By associating the identification numbers in the cookies with other customer information when, for example, you log-in to the site, then we know that the cookie information relates to you.
What is the scope of cookies?
Cookies are used generally for different purposes, such as letting the user navigate between pages efficiently, implementing the user's preferences and generally improving their browsing experience, by customizing the website according to their navigation and user profile. They can also help ensure that the adverts that the user sees online are more relevant to them and their interests.
What cookies do we use?
Our website uses several type of cookies for different purposes as better explained below in section 4 “Categories of cookies on Gucci.com”.
In particular we use:
Session cookies, which only last for the duration of a browsing session. They are usually used to facilitate the access to the services on our website, to authenticate you when you are a registered member, and to remember what a user has put in their shopping basket, and
Persistent cookies, which last for more than one visit. They are used to remember a user’s preferences and actions within the website. In this case, when a user returns to our website, or visits sites that use the same cookies, the site reads the cookies and identifies the user’s browser.
Among these cookies it is possible to refer to:
First party cookies, which are supplied by the website you are visiting, i.e., Gucci.com and can be read only by such site. For example the cookies that maintain products in the shopping bag of a user who is in the meantime still surfing the site. First party cookies can be either session or permanent cookies.
Third party cookies, which are meant to collect data in an anonymous way, for example analytics information, including browsing statistics. Other third party cookies are meant to track our visitors’ response to our online promotional activities. This technology uses information about your visits to our website and third parties' sites on which we advertise, to deliver relevant advertisements. We also use this to learn which banner adverts bring users to our website. Also third party cookies can be either session or permanent cookies.
The type of cookie used on our website can fall under one of the categories below.
A - Technical Cookies
Based on the Guidelines of the Italian Data Protection Authority (Garante) on simplification of procedure to release the data protection notice and to collect the consent for cookies (dated 8 May 2014), technical cookies include navigation or session cookies, cookies analytics and functionality cookies.
These cookies are strictly necessary session cookies essential to enable you to move around the website and use its essential features, such as accessing secure areas of the website. These cookies include session authentication cookies. Without these cookies, necessary services such as shopping baskets or e-billing cannot be provided.
We are able to identify you as being logged in to Gucci.com and to ensure that you are able to access the appropriate features on our site.
If you choose to disable these cookies, you will be unable to use our site for ordering our products, but only for browsing.
These cookies are also known as performance cookies and collect information about how you use our website, so that we can improve the quality of our site and services. Some examples include which pages you visit most often, whether you get error messages from web pages, and your choices about receiving cookies or not. Performance cookies allow us to implement these choices and optimise the way our site works. All the information that these cookies collect is aggregated and therefore they do not collect personal identification information. These type of cookies may be first party or third party.
These cookies include analytics that allow us to obtain statistics about website access and browsing, monitor which website our users arrive from, help us improve the site by measuring usage information and any errors which occur during our users browsing experience, as well as the effectiveness of advertising campaigns, using aggregated information.
A.3: Functionality Cookies
Functionality cookies allow the website to remember your online settings (such as your user name, language or location) and provide enhanced, more personalised features.
These cookies can also be used to remember changes you made to text size, fonts and other parts of a web page that you can customize. They may also be used to provide services you have asked for or to prevent you from receiving services you have already refused.
These types of cookies may be first party or third party. Presently we only use first party cookies, and they can be session or permanent.
When you choose functionalities and services, you agree to our use of the related functionality cookie.
B - Profiling Cookies
Among the many types of advertising or targeting cookies, we may use Flash Cookies and Pixel Tags:
At any time you can manage your preferences for advertising or targeting cookies through your browser settings as per section 6 below, or by enabling/disabling all third party cookies as per section 7 below.
Most browser applications automatically accept cookies but you can set it to receive an alert each time an operator tries to send you cookies/pixel tags, and/or prevent it from accepting them. On most browsers, the “Help” portion of the toolbar will tell you how to prevent it from accepting cookies, how to change your tracking settings, how to have it notify you when you receive cookies/pixel tags, or how to disable cookies/pixel tags altogether.
Below are pages describing these settings in more detail for each browser:
If you use multiple browsers (e.g., Internet Explorer, Google Chrome, Firefox, etc.) you must repeat this procedure with each one, and if you connect to the web from multiple devices (e.g., from work and at home), then you will need to set your preferences on each browser on each device.
Please note that if you disable completely cookies from the browser, then it is possible that some parts of our website will not function properly such as the normal surfing or the purchase activity, and finally you may also lose any personalized activity, and the advertising you receive when you visit this website will not be tailored to your interests.
You may learn how to disable third party cookies and advertising or targeting cookies on your computer by checking youronlinechoices.com
How to contact us
If you want to know more about cookies, have any question or want to send us suggestions, please contact us at Guccio Gucci S.p.A., Via Tornabuoni 73r, 50123 Florence (Italy), or at email@example.com.
A full overview of the cookies we use on our websites gucci.com, equilibrium.gucci.com, gift.gucci.com, spring.gucci.com, decor.gucci.com, finejewelry.gucci.com, dapperdan.gucci.com, prefall.gucci.com, zumi.gucci.com, chinesenewyear.gucci.com, yukohiguchi.gucci.com, acquadifiori.gucci.com zumi.gucci.com, springkids.gucci.com and chime.gucci.com, and their respective names and purposes can be found hereunder:
|Cookie name||Purpose / Supplier|
|__troruid||Cookie for marketing profiling|
|__trosync||Cookie for marketing profiling|
|_session_id||User Session Cookie|
|ggbackurl||URL type "Back" in current page|
|ggcategoryurl||URL type "Category" in current page|
|gghomeurl||URL type "home" in current page|
|site_abbreviation||ID for Country / language|
|cookie-policy||Acceptance for the cookies policy|
|ide||Cookie for marketing profiling form doubleclick.net|
|__sonar||Cookie for marketing profiling form doubleclick.net|
|__utma||Cookies for user statistics|
|__utmb||Cookies for user statistics|
|__utmc||Cookies for user statistics|
|__utmz||Cookies for user statistics|
|_utmt_ua_xxxxxxxx-y||Cookies for user statistics|
|_drt_||Cookie for marketing profiling form doubleclick.net|
|id||Cookie for marketing profiling form doubleclick.net|
|_ga||Anonymized third-party analytical cookie used for statistical purposes|
|_gat||Anonymized third-party analytical cookie used for statistical purposes|
|_gid||Anonymized third-party analytical cookie used for statistical purposes|
|UATMParameters||Anonymized third-party analytical cookie used for statistical purposes|