Please read this Privacy Notice to understand how we may collect, use and protect your personal data. The Stella McCartney Group is made up of different legal entities - this Privacy Notice is issued on behalf of the Stella McCartney Group and when we refer to "Stella McCartney", "we", "us" or "our", we mean the relevant company in the Stella McCartney Group responsible for processing your personal data. In particular:
(i) Stella McCartney Limited, incorporated in the United Kingdom, with registered office at 3 Olaf Street, W11 4BE, is the data controller and responsible for the website at www.stellamccartney.com.
(ii) Stella McCartney Italia S.r.l. incorporated in Italy, with registered office Stella McCartney Via Morimondo 2/3 - 20143 Milano (Italy), is the joint data controller and responsible for sales and post-sale activities carried out in the European Union and United Kingdom through the website at www.stellamccartney.com or at any Italian Stella McCartney store.
This website is not intended for children. Protecting the safety and privacy of children is very important to us and we will not knowingly collect or use personal data relating to children.
To exercise any of your rights under this Privacy Notice, or if you have any questions regarding your personal data, please contact us at firstname.lastname@example.org.
What kind of Personal Data Do We Collect
Personal data, or personal information, means information about an individual from which that person can be identified. It does not include data which has been anonymised so that an individual cannot be identified.
We collect, use and store various types of personal data about you including:
- your name, surname, title, username or similar identifier, nationality, date of birth, gender and other identifying data;
- your email address, billing address, delivery addresses, telephone number, social media handle and any other personal data that you provide by completing forms on the website;
- details of any transactions made by you;
- website login activity and details of products you have viewed on the website or placed in your basket whilst logged in;
- personal data that may be contained in communications you send to us;
- information you voluntarily provide in surveys that we may, from time to time, conduct on the website or via email for research purposes (only if you choose to participate in them);
- credit/debit card information;
- technical data about your laptop, phone or tablet for example your IP address, browser information, location, operating system and platform;
- your social media handle and other data that you voluntarily publish or share publicly, like your preferences in your social media accounts, for example on social networks (e.g., Facebook, Instagram, etc.) which is collected by third party analytics providers (such as Google Analytics and Facebook Business Manager), advertising networks and search information providers. These third parties have their own privacy and cookies policies which apply to the way they collect and share your personal data with us;
- information relating to your shopping preferences (for example, your size and style preferences), purchasing data (purchased products, location, date and time of purchase) and marketing and communications preferences you have selected.
- in order to offer you Klarna’s payment methods, we might in the checkout pass your personal data in the form of contact and order details to Klarna, in order for Klarna to asses whether you qualify for their payment methods and to tailor those payment methods for you. Your personal data transferred is processed in line with Klarna’s own privacy notice.
What happens if you don't provide your Personal Data?
Providing your personal data to us is voluntary. However, we will need certain personal data to process purchases you make through the website (in particular, your name, email, billing address and delivery address) or to respond to communications you send to us.
Providing data for marketing purpose and profiling purpose is instead optional. Not providing your data for these purposes will not have any negative consequences for you and you can revoke your consent at any time by emailing: email@example.com.
When We Collect Personal Data
We collect personal data that you provide through the website, when you are at a Stella McCartney store or through other media, for example, when you:
- create an account with us, either through the website or in store;
- visit the website, and login to your account to buy products, place products in your shopping basket or otherwise browse the website;
- purchase a product through the website, in store or by phone;
- subscribe to the Stella McCartney newsletter;
- click on Stella McCartney ads or sponsored links;
- contact us through the customer services function or by any other means;
- contact store staff (including where you communicate with store staff through What’sApp, WeChat or other communication apps);
- book a stylist appointment or any other in store appointment;
- request a store to contact you (for example, in connection with alterations or if a product is out of stock); or
- choose to complete any surveys we send you.
Please remember that where you share your personal data through an app or other third party platform, your use of the app or platform and the way in which your personal data may be processed will be subject to the privacy policies of such third party provider and terms and conditions of such app or platform.
We may ask third-party business partners (e.g., social media, co-branding companies, etc.) to send or display our advertisements to their users on the basis of certain criteria/interests. These so-called micro-targeting and/or retargeting activities typically do not lead to the direct collection of personal data by SMC. Instead, they usually allow us to obtain Aggregate Information on the effectiveness of those advertisements or lead to the registration of new users or new followers. In accordance with European legislation, in carrying out these activities both SMC and our business partners make every possible effort to verify the conformity of the data (including joint controllership agreements) before they are used. You can request more information on our list of active commercial partners and the obligations of the respective parties by writing to firstname.lastname@example.org.
How We Use Your Personal Data
We only use or "process" your personal data where permitted by law. In most cases, we rely on one of the following legal grounds for processing personal data:
- processing is necessary to perform a contract with you or take steps that you have requested in order to enter into a contract (for example, the contract for the sale and purchase of products);
- processing is necessary for us to comply with a legal obligation (for example, fraud prevention);
- processing is necessary for the purposes of our legitimate interests, and our interests are not overridden by your interests, fundamental rights or freedoms; or
- your consent, in connection with certain marketing activities
- your consent, in connection with profiling (this is where we analyse your preferences in-store or whilst on the website), for example, in relation to purchased products, viewed products, stores where purchases were made, in order to provide personalized offers that are in line with your interests.
Categories of personal data and how we use it
1. Using your name, gender, date of birth, occupation, nationality, contact information, purchase and browsing history to:
- register you as a new customer and providing you with services as a registered customer such as offering you qualified customer service or sending you notifications when you place a product in your basket and leave the website before completing your checkout or where you add products to a wish list.
- process and track your purchases, send order updates and provide services and information offered through the website (at your request).
- process requests for distant sale appointments, stylist appointments, other store services or in connection with store events.
Performance of a contract or taking steps that you have requested prior to entering into a contract.
2. Using your name, contact information and information voluntarily provided by you to communicate with you in connection with any prize draws and competitions you choose to enter.
Performance of a contract or taking steps that you have requested prior to entering into a contract.
3. Using your name, contact information, credit card details, and billing details to verify and process a purchase you made.
We will only process your credit card details where you purchase products from a store over the phone.
Performance of a contract or taking steps that you have requested prior to entering into a contract.
4. Using information related to your activity on the website or in store and information you voluntarily share with us to improve and customise products, services and our business in general, including by profiling, for example by tracking your product preferences, shopping history and interactions with the website.
Your consent to profiling for these specific purposes and, for non-profiling activities, our legitimate interest in improving our products or services where such interest is not overridden by your own interests or fundamental rights.
5. Using your purchase and browsing history, information relating to your shopping preferences and information you voluntarily share with us for data analytics and market research.
Our legitimate interest in improving our products or services where such interest is not overridden by your own interests or fundamental rights.
Your consent, when you answer surveys or customer satisfaction questions.
6. Using your name, contact information and information voluntarily provided by you to respond to your queries or complaints.
Performance of a contract to which you are a party or taking steps at your request prior to entering into a contract where you contact us in relation to a purchase or potential purchase and in all other cases our legitimate interest in responding to you where such interest is not overridden by your own interests or fundamental rights.
7. Using your purchase and browsing history, information relating to your shopping preferences and information on publicly available social networks or that you voluntarily share with us to carry out data enrichment, such as by analysing your product preferences, shopping history and interactions with the website together with data collected from third parties.
Our legitimate interest in improving our products and services where such interest is not overridden by your own interests or fundamental rights.
8. Using your IP address, browser information, location, operating system and platform and other technical information to maintain and protect the website and our business (for example, troubleshooting, data analysis, system maintenance, hosting data).
Performance of a contract in accordance with the applicable terms and conditions of our website and services or our legitimate interests in effectively running the website and our business where such interest is not overridden by your own interests or fundamental rights.
Marketing and profiling
We will only send you marketing communications with your consent and we will respect any contact preferences you select (text message, email, telephone and/or mail). These communications include news, information and updates about our products and services, offers, gifts, promotions, special events, projects Stella McCartney is supporting and other communications that we think may be of interest to you.
With your consent, we use your data, in particular data inferred by your activities, Information about your location and data collected by the browser and the device, to improve our services (e.g., our Pages, our Events), our promotional communications and to show content that may be useful to you. For example, we may display a specific product according to your clicks, views, follows, tags.
Content that may be useful to you may also be visible on websites and mobile applications other than our pages once uploaded to programmatic advertising or social media platforms to the extent that you have authorised us to do so.
If you have given your consent to profiling, we may process your personal data through automated decision-making tools, so that we can customise your experience with us to your interests and shopping habits and to improve our services and products. We explain below the logic involved in our profiling activities, their significance and effects:
Logic involved and description of the processing
- logic involved: viewed products, purchase data and purchase frequency are used to create clusters of customers (explorer, fan, classic, connoisseur and elite). Customers will be addressed profiled marketing communications promoting our products which are sold at certain prices based on the cluster they fall into;
- information processed: name, date of birth, address, data concerning hobbies, job, interests, purchase data (e.g. purchased products, location of purchase, date and time of purchase, delivery data), viewed products;
- source of the information: where you give your consent to be profiled, we process the data you provide when you register, use our website and purchase products as a registered customer;
- how the information provided impacts the decision made by profiling: the profiling is based solely on the data you provide, therefore the outcome depends totally on it.
Processing significance and envisaged consequences of such processing
Visits on our website and purchase habits as a registered customer will influence the types of products that we promote to you.
For example, if you view or purchase products that are:
- at a lower price range, for example small accessories, you will receive targeted marketing communications for other accessories or similarly priced products;
- at a higher price range, for example, coats and outerwear, you will receive targeted marketing communications for products in a similar category or price point.
You can withdraw your consent to receiving marketing communications at any time by following the unsubscribe link in emails we send you.
You can also withdraw your consent to profiling at any time. If you have created an account with us you can change your preferences for marketing communications and profiling through your account on the website. If you prefer (or if you don't have a Stella McCartney account), you can contact us directly at email@example.com.
Who We Share Your Personal Data With
In connection with the activities set out above, we may disclose your personal data to:
(i) our group companies, in particular, our group companies that operate Stella McCartney stores that act as data controller or data processors on our behalf depending on the purposes of processing (for example, if you have an account with us and visit a Stella McCartney store in another country, your account may be accessed by the sales staff in the store you are visiting) both in and outside your country of residence and both in and outside the EEA (a list of Stella McCartney subsidiaries can be found here);
(ii) service providers who provide our business with support services, IT services, customer care support, logistics or courier services as data processors, including:
a. DROP (https://www.drop.it/en/) who manage purchases through the website on our behalf (including billing and/or invoicing activities);
b. T.W.S. (www.twsonline.it) who provide warehousing services; and
c. G SUITE (gsuite.google.it/intl/it//) who provide certain cloud computing services;
(iii) service providers who are involved in our marketing and profiling activity, such as media agencies working for us.
When you make a purchase through the website, the payment card details you provide are processed exclusively by our external payment processing provider, ADYEN (www.adyen.com), which processes your data as a data processor on our behalf for the purposes of completing the electronic payment transaction and to undertake identity verification, fraud and anti money laundering checks, and risk management and solvency assessments.
We may transfer your personal data from your country of residence to third countries. Some of these countries are subject to a data protection adequacy decision of the European Commission, but others are not, such as the USA. To ensure the protection of your personal data, transfers outside your country of residence or the EEA to a third party processing your personal data on our behalf will be made pursuant to the EU Model Clauses or other acceptable legal mechanisms. For more information, please contact firstname.lastname@example.org.
We may also share personal data with third parties in connection with a potential or actual sale of our business or assets and, where relevant, we will respond to requests for personal data where required to do so by law, or when we believe that disclosure is necessary to protect our legal rights and/or comply with a judicial proceeding, court order, request from a regulator or any other legal process served on us.
(iv) Rakuten Advertising may collect personal information when you interact with our digital property, including IP addresses, digital identifiers, information about your web browsing and app usage and how you interact with our properties and ads for a variety of purposes, such as personalization of offers or advertisements, analytics about how you engage with websites or ads and other commercial purposes. For more information about the collection, use and sale of your personal data and your rights, please use the below links.
Your Rights/Opt Out : https://rakutenadvertising.com/legal-notices/services-privacy-rights-request-form/
Third Party Website Links
How your personal data are processed and protected?
Your personal data may be processed, either electronically or in hard copy form. We have a range of security measures in place to prevent your personal data from being accidentally lost, used or accessed in an unauthorised way, altered or disclosed. For example, purchases you make through the website are protected by SSL encryption.
We have put in place procedures to deal with any suspected personal data breach and will notify you and any applicable regulator of a breach where appropriate.
However, no data transmission over the Internet or data storage system can be guaranteed to be 100 percent secure, so please do not send us information you consider confidential via e-mail. It is your personal responsibility to protect your log in details and password for the website.
How long do we keep your personal data?
We retain your personal data to comply with a legal obligation and to perform a contract to which you are a party only for as long as we need it to fulfil the purposes we collected it for and/or for legal, tax, accounting or reporting requirements in any case not exceeding 10 years after termination of the contract. After that time, your data will be destroyed or rendered unusable or made anonymous.
Your personal data collected for marketing and profiling purposes may be kept for a period of 7 years from your last interaction with us (for example, a purchase, clicking a link in a newsletter or making changes to your website account), after which your personal data will be deleted or anonymised. We may retain your personal data for a longer period in the event of a complaint or if we reasonably believe there is a prospect of a complaint or litigation.
We may continue to use anonymised data aggregated with other data.
You have a number of rights in relation to your personal data including the right:
- to be informed about how we use your personal data (as we have explained in this Privacy Notice);
- to request access to and receive a copy of the personal data we hold about you (this is also known as a "data subject access request");
- to request that we correct any inaccuracies in your personal data;
- to request that we delete your personal data or restrict processing of your personal data;
- in certain circumstances, to move, copy or transfer personal information you have provided to us (this is also known as the right to data portability);
- where we are using your personal data with your consent, withdraw your consent at any time (for example, you can opt-out of marketing communications by changing your settings in your account on the website, or using the 'unsubscribe' link provided in our emails or contacting us directly);
- to object to use of your personal data based on our legitimate interests;
- make a complaint to the Information Commissioner’s Office (or if you are based outside of the UK, the relevant data protection regulator in your country of residence, such as for Italy, the Autorità garante per la protezione dei dati personali).
In the UK, the website of the Information Commissioner’s Office (available at www.ico.org.uk) has lots of information to help you understand your rights in relation to your personal data. The same for Italy at www.garanteprivacy.it
If you have any questions or would like to exercise any of your rights under this Privacy Notice, please contact us at email@example.com or third parties who shared your data with us (e.g., business partners, data brokers) via their e-mail address or your account settings on their platforms.
Please note that to protect the confidentiality of your information, we may request proof of your identity before proceeding with any request you make in connection with this Privacy Notice.
Changes to this Privacy Notice
We keep this Privacy Notice under review and occasionally will update this Privacy Notice, for example, if we change the way we use your personal data or if there are new legal or technical requirements. We will post the updated Privacy Notice on the website so please review this page regularly.
What is not covered by this notice
The Notice does not cover processing carried out by parties other than SMC and in particular does not cover:
- the processing carried out by our business partners as autonomous data controllers including those carried out by social media platforms within Our Pages;
- the further processing carried out by our Affiliates as autonomous data controllers for purposes other than those described in this Notice.
With respect to such hypotheses, we do not assume any responsibility for the processing of your Data not covered by this Notice.