Privacy Notice
Welcome to our website Ferrari Store (“ the Website”).
In compliance with applicable privacy laws, including EU Regulation no. 2016/679 (“GDPR”), the California Consumer Privacy Act (“CCPA”) and regulations applicable in your jurisdiction (“National Data Protection Laws”), which, with respect to China, shall include the PRC, Personal Information Protection Law and other applicable PRC laws and regulations, this Privacy Notice explains how Ferrari S.p.A and YOOX NET-A-PORTER GROUP S.p.A. (“we”, “us”, “our”) collect your personal information as you use the Website, how we use this personal information, with whom we share your personal information, and your choices in connection with this.
(1) CONTROLLER AND DATA PROTECTION OFFICER
- YOOX NET-A-PORTER GROUP S.p.A. (“YOOX NET-A-PORTER GROUP”), company with sole shareholder subject to direction and coordination of Compagnie Financière Richemont S.A., with registered office at via Morimondo, 17 – Milan 20143, Italy, as independent Data Controller.
The personal data that YOOX NET-A-PORTER GROUP processes is the data that you provide when you place an order and purchase items, as well as the data we collect as you navigate or you use the services offered on the Website.
For any clarification, request, or requirement connected to your privacy and the processing of your personal data, please contact us at any time by selecting ‘privacy’ and sending a request to our Customer Care or by writing to the registered office of YOOX NET-A-PORTER GROUP S.p.A.. If you so wish, you may also contact our Data Protection Officer (“DPO”), by writing to the aforementioned address, or by sending an email to DPO@ynap.com.
- Ferrari S.p.A. (“Ferrari”), with registered office at via Emilia Est, 1163 - Modena 41122, Italy, as independent Data Controller. Ferrari processes your personal data in order to create your account on the Website, for marketing and profiling activities upon your express consent, and to support you through the Live Chat service. For any clarification, request, or requirement linked to your privacy and the processing of your personal data, please contact us by writing to Ferrari S.p.A., via Abetone Inferiore 4, 41053 Maranello (MO), Italy. If you so wish, you may also contact our Data Protection Officer (DPO) by writing to the aforementioned address, or through the interactive webform.
(2) COLLECTION OF YOUR PERSONAL INFORMATION
We collect personal information, which is information that identifies, relates to, describes, can be associated with, or could reasonably be linked, directly or indirectly, to you.
- Information you provide to us
If you choose to engage in the services offered on the Website, we will collect personal information from you. We collect personal information from you when you:
- Create a Ferrari account. You have the option to create a Ferrari account on the Website for faster purchases, to monitor your orders and returns, and to save your favorite items. To do so, we will collect your personal identifiers (name, email address, date of birth and telephone number) and protected classifications (gender). We use this personal information to create and maintain your account with us and to communicate with you about your account, purchases, and the Website. The legal basis for this is performance of our contract with you (Art. 6, par. 1, let. b of the GDPR), unless the applicable National Data Protection Laws in your jurisdiction state otherwise. Once your account is created, we will store your username and password.
- Contact us. When you send us a question or inquiry, or ask for other support, you will need to provide us with personal identifiers (name and email address), protected classifications (gender), and any other information you choose to provide in your correspondence. We use this personal information to reply to your questions or inquiries, troubleshoot where necessary, and address any issues you experience with the Website or the services offered thereon. The legal basis for this is performance of our contract with you (Article 6, par. 1, let. b of the GDPR), unless the applicable National Data Protection Laws in your jurisdiction state otherwise.
- Make a purchase. To facilitate your shopping experience and to manage the services offered by Ferrari Store, YOOX NET-A-PORTER GROUP will collect personal identifiers (name, email address, shipping address and telephone number) and customer records information (cardholder’s name, payment card number, expiration date, CVV or PayPal account and billing address). YOOX NET-A-PORTER GROUP uses this personal information to manage the services offered by the website, to fulfill orders placed, and complete all activities related thereto, including operations pertaining to administrative and fiscal requirements, to reply to requests via the contact form, and manage any product returns. The legal basis for this is performance of our contract with you (Article 6, par. 1, let. b of the GDPR), unless the applicable National Data Protection Laws in your jurisdiction state otherwise.
- Profiling activities. If you opt in, Ferrari may use the personal data described in this section to analyze your behavior, habits and propensity to consume to enhance products and services provided by Ferrari, to meet your expectations and to send you marketing communications we feel may be of interest to you, if you also have opted in to receive direct and indirect marketing communications. In doing so, Ferrari will analyze your preferences and interests using automated analysis techniques that provide Ferrari with inferences derived from your data, and including profiling. The legal basis for this is your consent (Article 6, par. 1, let. a of the GDPR), unless the applicable National Data Protection Laws in your jurisdiction state otherwise. You may revoke your consent at any time by clicking the ‘unsubscribe’ link provided within each email. This link will redirect you to our consent management page where you can opt out of our newsletters and marketing communications.
- Subscribe to direct and indirect marketing communications. If you opt in, Ferrari may also use your personal data (e.g. email address) to send you marketing communications as well as advertising on Ferrari products, services, events, new collections or performing market research (direct marketing) as well as on Ferrari’s commercial partners’ products belonging to different product categories (e.g. companies operating in the oil, automotive, IT sectors, etc.) (indirect marketing). This data may be processed by automated or electronic means including via email, websites and cell apps. In doing so, Ferrari will analyze your preferences and interests using automated analysis techniques that provide Ferrari with inferences derived from your data, and including profiling. The legal basis for this is your consent (Article 6, par. 1, let. a of the GDPR), unless the applicable National Data Protection Laws in your jurisdiction state otherwise. You may revoke your consent at any time by clicking the ‘unsubscribe’ link provided within each email. This link will redirect you to our consent and newsletters management page where you can opt out of our marketing communications.
- Custom and lookalike audiences. If you consent to marketing, Ferrari may share your personal data (such as your first name, last name, email address, phone number) with social media platforms including Facebook, LinkedIn, YouTube and other similar platforms (“Social Networks”) to tailor our marketing content to your interests and/or the interests of like-minded consumers. In order to do so, your personal data will be hashed and encrypted before Social Networks access it for the purpose of creating a “Custom Audience” (which consists of sending targeted promotional ads to Social Networks users who are already Ferrari customers or potential customers). As for “Lookalike Audiences” (where targeted promotional ads are sent to Social Networks users who appear to have shared interests or demographic data similar to Ferrari's existing or potential customers), only data provided by the Social Network in accordance with its privacy policy is collected when users click on the ads displayed on the Social Networks; Ferrari is unable to access the identity of anyone in the “Lookalike Audiences” unless they click on the ads. Note that certain Social Networks may not be available in China, therefore such activity may not be applicable to you if you reside in China. The legal basis for such activities is your consent (Art. 6, par. 1, let. a of the GDPR), unless the applicable National Data Protection Laws in your jurisdiction state otherwise. You can withdraw your consent at any time by following the procedures outlined in sections 4 and 5 below and your personal data will be removed from our Custom Audience list. You can also consult Social Networks to find out more about their privacy policies relating to data and any consent that you may have provided.
- Web Push Notifications. Upon your explicit consent, Ferrari will collect certain categories of your personal data, such as the language you use when browsing the Website and the version of the Website you use (country/region), information about the device and browser you use, the time and date you consented to receive web push notifications, the date of your last visit to the Website. Ferrari will use this information to send you notifications about products and other commercial news regarding the Ferrari Store. In order to send you these notifications, we use a technology similar to cookies (in particular, “HTML5 Local Storage”), which stores the information in the local memory of your browser/device. The legal basis for this is your consent Art. 6, par. 1, let. a of the GDPR), unless the applicable National Data Protection Laws in your jurisdiction state otherwise.
- Live Chat. Upon your request, you will be able to access and use the Live Chat tool available on the Website. For more information about this service, please visit our Privacy Policy. Please note that if you do not provide your personal information when requested, this may prevent you from benefiting from the service in question. The legal basis for this is performance of our contract with you (Article 6, par. 1, let. b of the GDPR), unless the applicable National Data Protection Laws in your jurisdiction state otherwise.
We may also use the personal information we collect as described in this section to improve our products and services, to comply with the law, to efficiently maintain our business, and for other limited circumstances as described in HOW WE SHARE YOUR PERSONAL INFORMATION. This is part of our legitimate interest in the performance of our contractual obligations, protection of legal rights, and compliance with legal obligations. We may also deidentify or aggregate the personal information for benchmarking purposes.
Your personal information may be processed for each of the above purposes using automated or electronic methods and, in particular, by email or any other IT channel (e.g. automated calls, SMS, MMS), fax, or any other IT channel (e.g. websites, cell app).
Sharing your personal information is optional. However, if you opt not to share data that has been marked as mandatory, it will be impossible for us to provide our services. Should you not share the optional data, however, the services will be provided in any case.
- Information collected automatically.
Cookies and tracking technologies
In addition to the personal information you provide directly, we may also collect information from you automatically as you use the Website. This information includes the following internet or other electronic network activity and location information:
- Usage information. This includes information regarding your interaction with the Website, such as which pages you visit, the frequency of access, how much time you spend on each page, what you click on while on the Website, and referring Website addresses.
- Device information. This includes certain information about the device that you use to access the Website, such as browser type, browser language, hardware model, operating system, and your preferences.
- Location information. This includes information about your location, which may be determined through your IP address.
We collect this information as part of our legitimate interest to improve the functionality and efficiency of the Website and in order to provide the Website to you.
To collect this information, we use cookies and other tracking technologies. Cookies are small pieces of text sent by your browser to your device. Cookies can be persistent (cookies that remain on your device for a set period of time or until you delete them) or session (cookies that are deleted as soon as you close your browser). When you use or access the Website, we and our third party providers may place a number of cookies on your device. These cookies include technical cookies, categorized as:
- Technical. We use essential cookies to authenticate users, prevent fraudulent use of the Website, and to allow the Website and its features to function properly.
- Functional. We use functional cookies to provide enhanced functionality and personalization, to remember your login information, to remember your preferences, to diagnose server and software errors, and, in cases of abuse, to track and mitigate the abuse.
- Analytics. Analytics cookies allow us to recognize and count the number of users to the Website, see how users interact with the Website and its different functions, and when users are using the Website. We use this information to improve the Website.
- Profiling. Performance cookies collect information about how you use the Website and help Ferrari, for example, to identify especially popular areas of the Website. In this way, we can adapt the content of our Website more specifically to your needs and thereby improve what we offer you.
- Advertising Advertising cookies identify and store behaviors of users on the Website. These cookies are used to identify you as a prospect for our services, deliver advertisements that are more relevant to you and your interests, limit the number of times you see an advertisement, and help measure the effectiveness of our advertising campaigns. Such sharing may be deemed a sale under the CCPA. To opt out of sharing through cookies, see our Cookie Policy below.
To control the information collected about you using cookies and other technologies, see our Cookie Policy.
Particular third-party cookies on the Website that should be noted include:
- Google Analytics 4. We use Google Analytics 4 to collect information on your use of the Website in order to improve the Website. In order to collect this information, Google Analytics 4 may set cookies on your browser, or read cookies that are already there. Google Analytics 4 may also receive information about you from applications you have downloaded that partner with Google. We do not combine the information collected through the use of Google Analytics 4 with personally identifiable information. Google’s ability to use and share information collected by Google Analytics 4 about your visits to the Website or to another application which partners with Google is restricted by the Google Analytics 4 Terms of Use and the Google Privacy Policy available here. To prevent your data from being used by Google Analytics 4, you can download the Google Analytics opt-out browser add-on for Google Analytics which can be found here.
- DoubleClick. Ferrari utilizes DoubleClick by Google to serve ads based on a user’s prior visit to the Website. Each visitor to the Website receives a different cookie and the information collected by the cookie is used to generate conversion statistics and allows us to see the total number of individuals who clicked on our ads. DoubleClick cookies are used by Google in ads served on the Website by its partners, such as websites participating in Google certified-ad networks. DoubleClick enables Google and its partners to serve ads to you based on your visit to the Website and other websites on the Internet. Please review Google’s privacy policy for additional information on how Google uses the information collected. Such sharing may be deemed a sale under the CCPA. To opt out of this sharing and targeted advertising by Google, please go to Google’s ad settings. You may also install the DoubleClick opt-out add-on.
- Google Ads. Ferrari uses Google Ads to deliver advertisements to you and to track whether you have interacted with an advertisement we have placed elsewhere on the Internet. Google Ads stores a conversion tracking cookie on your device when you click on our advertisement. The information obtained through the cookie is used to generate statistics and allows us to see the total number of users who clicked on our advertisements. We also use Google Ads to present to users of the Website advertisements across the internet and within the Google advertising network based on their visits to the Website. For more information, please review Google’s privacy policy available here. Such sharing may be deemed a sale under the California Consumer Privacy Act. To opt out of this sharing and targeted advertising by Google, please go to Google’s ad settings.
- Facebook Pixel/TikTok Pixel. Ferrari uses Facebook Pixel and TikTok Pixel (jointly “Pixels”) to customize our advertising and to serve you ads on your social media based on your browsing behavior. This allows your behavior to be tracked after you have been redirected to the Website by clicking on the Facebook and/or TikTok ad. The Pixels store a cookie on your device to enable us to measure the effectiveness of Facebook and/or TikTok ads for statistical and market research purposes. Ferrari does not have access to the information collected through the Pixels. However, the information collected via the Pixels, on the Website as well as other websites on which the Pixels are installed, is also stored and processed by Facebook and/or by TikTok. Facebook and TikTok may link this information to your Facebook/TikTok account and also use it for its own promotional purposes in accordance with Facebook's Data Usage Policy as well as with TikTok’s Privacy Policy. The Pixels also allow Facebook and TikTok and its partners to show you advertisements on and outside of Facebook and TikTok. To opt out of this sharing and displaying of Facebook ads, visit your Ad Settings, where you can clear and control the information third parties share with Facebook in your Off-Facebook Activity page. To opt out of this sharing and displaying of TikTok ads, visit its Privacy Policy and Web Cookies Policy. If you do not have a Facebook/TikTok account, you can opt out of Facebook and Tik Tok ads through the Digital Advertising Alliance here.
- Bing Ads. Bing Ads is a remarketing service provided by Microsoft. Ferrari uses Bing Ads to serve you advertisements based on your past visits to the Website. You can learn more about the privacy practices of Microsoft here. Such sharing may be deemed a sale under the CCPA. To opt out of this sharing of Bing Ads, you can follow the instructions found here.
- Criteo. Ferrari, through its own providers, places tags on its properties for Criteo to collect browsing information and create customized ads to serve to users. Criteo creates the ads, decides which ad to serve and where. Such sharing may be deemed a sale under the CCPA. You can learn more about the privacy practices of Criteo and opt out of this sharing here.
- Hotjar. We use Hotjar in order to better understand user experience and to optimize the Website. Hotjar allows us to better understand users’ experience and this enables us to build and maintain the Website. For further details, please see the ‘about Hotjar’ section of Hotjar’s support services. You can opt-out of Hotjar here.
- Information collected through other sources.
Social media listening (“SML”). From time to time, Ferrari may use SML tools to extract information (e.g. users’ comments concerning Ferrari, username, etc.) from web sources (e.g. blogs, forums, etc.) and social media channels. This activity is based on Ferrari’s legitimate interest to find insights into Ferrari brand's visibility on social media channels as well as to assess the impact of our web campaigns (Article 6, par. 1, let. f of the GDPR), unless the applicable National Data Protection Laws in your jurisdiction state otherwise. For this purpose, Ferrari may process only publicly available information and derive statistical analysis from it.
Social networks. If you interact with Ferrari through social network platforms including Facebook, LinkedIn, YouTube and any other similar platforms (“Social Networks”) when you complete specific forms (e.g. request of information, etc.) and/or when you interact with Ferrari’s official Social Network pages/profiles, Social Networks may provide us with your personal data (e.g. email, name, surname, country of origin, address, street number, town, postcode, city, telephone number), data relating to your vehicle (e.g. current model brand, next vehicle purchase), your interactions on Social Networks (e.g. posts that you like, private messages you may send to Ferrari, etc.). According to the settings you have chosen on your Social Networks profile, Ferrari may be able to receive additional data such as your age, groups you have joined, etc., which in certain cases may lead Ferrari to identify you. Ferrari may process your data to reply to your posts, requests and queries, to perform statistical analyses and market research on the users who interact with Ferrari pages and/or Ferrari websites as well as, if you opt in, for marketing activities as described in section (A).
Furthermore, in the event that you choose to register on Ferrari websites through your Social Network account, we will receive some personal data (e.g. email, password, name, surname, date of birth, gender, job role, country, citizenship, address, telephone) from the Social Networks of your choice. The legal basis for this processing is the execution of our contract with you (Article 6, par. 1, let. b of the GDPR), unless the applicable National Data Protection Laws in your jurisdiction state otherwise.
Please note that this section (C) only refers to Ferrari’s data processing. Ferrari is not liable in the event of any unauthorized disclosure of your information by third-party social media channels in breach of the options you have selected thereto and/or any consents you have provided. You may refer to such third-party social media channels websites and Social Networks to know more about their privacy policies relating to the data and consents you may have provided to them.
Please note that certain Social Networks may not be available in China, therefore such activity may not be applicable to you if you reside in China.
Ferrari partners. In the event that you take part in initiatives or events organized by Ferrari’s commercial partners and/or request the latter to provide a service to you, Ferrari may receive your personal data in order to follow up on the requested service and/or the activities included in the scope of the initiative or event (e.g. Ferrari could reward the winners of a competition organized by our commercial partners, etc.). The legal basis for this processing is the execution of our contract with you (Article 6, par. 1, let. b of the GDPR), unless the applicable National Data Protection Laws in your jurisdiction state otherwise.
(3) HOW WE SHARE YOUR PERSONAL INFORMATION
General Sharing
Ferrari may need to make the personal information identified in this Privacy Notice available within Ferrari, with service providers, or with other third parties. These instances include:
Within Ferrari. Ferrari may share your personal information with Ferrari subsidiaries for legitimate business purposes and general business management. The legal basis for this is Ferrari’s legitimate interest in carrying out our business efficiently.
With Service Providers. Ferrari may share your personal information with our service providers that assist us in providing the Website. The legal basis is our legitimate interest in providing the Website efficiently. These service providers include communication providers, web-hosting providers, IT support, our customer management platform, shipping providers, payment processors, call center providers, marketing providers, and e-commerce providers. This also includes sharing of personal information with our service provider YOOX NET-A-PORTER GROUP that manages the Website on Ferrari's behalf. We may also share your personal data with Social Networks for marketing purposes.
With Third Parties. We may need to disclose your personal information to third parties, such as legal advisors, law enforcement agencies, or governmental/regulatory bodies in order to protect our legal interests and other rights, protect against fraud or other illegal activities, prevent harm, for risk management purposes, and to comply with our legal obligations. The legal basis for this is compliance with the law, compliance with legal obligations, and our legitimate interest in the protection of the rights of others.
In the Event of a Corporate Reorganization. In the event that we enter into, or intend to enter into, a transaction that alters the structure of our business, such as a reorganization, merger, acquisition, sale, joint venture, assignment, consolidation, transfer, change of control, or other disposition of all or any portion of our business, assets or stock, Ferrari would share personal information with third parties, including the buyer or target (and their agents and advisors) for the purpose of facilitating and completing the transaction. Ferrari would also share personal information with third parties if we undergo bankruptcy or liquidation, in the course of such proceedings. The legal basis for this is our legitimate interest in carrying out business operations.
With Your Consent. Apart from the reasons identified above, we may request your permission to share your personal information for a specific purpose. We will notify you and request consent before you provide the Personal Information or before the personal information you have already provided is shared for such purpose. You may revoke your consent at any time.
(4) YOUR PERSONAL INFORMATION CHOICES AND THE POSSIBLE CONSEQUENCES OF FAILURE TO PROVIDE YOUR DATA
Correct or view your information. You may access your Ferrari account to correct or view certain personal information you have provided to us and that is associated with your account.
Cookies. All session cookies are temporary and expire after you close your web browser. Persistent cookies can be removed by following your web browser’s directions. To find out how to see which cookies have been set on your computer or device, and how to reject and delete the cookies, please visit: https://www.aboutcookies.org/ or our Cookie Policy. Please note that each web browser is different. For information on reviewing or deleting cookies from specific browsers, click on the appropriate browser: Firefox, Firefox IOS, Firefox Android, Safari, Safari Mobile, Chrome, Internet Explorer, Microsoft Edge, Opera. To find information relating to other browsers, visit the browser developer’s website. If you reset your web browser to refuse all cookies or to indicate when a cookie is being sent, some features of the Website may not function properly. If you choose to opt out, we will place an “opt-out cookie” on your computer. The “opt-out cookie” is browser specific and device specific and only lasts until cookies are cleared from your browser or device. The opt-out cookie will not apply to essential cookies. If the cookie is removed or deleted, if you upgrade your browser or if you visit us from a different device, you will need to return and update your preferences.
Online advertising. To opt out of interest-based advertising generally or to learn more about the use of this information by our service providers, please visit the Network Advertising Initiative or the Digital Advertising Alliance.
Marketing emails. You may opt out of receiving marketing emails from Ferrari by clicking the ‘unsubscribe’ link provided withing each email. Please note that we will continue to send you notifications necessary to the Website, your account, or requested products or services.
For more information on cookies and to manage your preferences for third-party profiling cookies, please visit our Cookie Policy.
This processing of your personal data has been the subject of a contract between CRITEO SA and Ferrari S.p.A. (“Contract”), and joint controllers within the meaning of Article 26 of the General Data Protection Regulations of April 27, 2016, which came into force on May 25, 2018. Under the terms of this Contract, we are responsible for informing you and collecting your consent so that Criteo can show you personalized advertisements based on your interests. To learn more about Criteo's commitment to protecting your data, we invite you to read their privacy policy. The essence of the Contract is made available to you upon written request.
Providing your personal data is optional. However, if you do not provide personal data that has been marked as mandatory, it will not be possible for us to provide our services.
Should you not provide the remaining and optional personal data, our services will nevertheless be able to be provided.
Please note that if you do not provide your personal data when requested, this may prevent you from benefiting from our Live Chat service.
Providing Data for the purposes of marketing and profiling activities is always optional.
(5) RIGHTS OF INDIVIDUALS UNDER THE GDPR
If our processing of your personal information is subject to the GDPR, you have the following rights concerning your personal information that has been processed:
- Right to access. You have the right to ask us for copies of your personal data. This right entails some exceptions, which means you may not always receive all personal data we process.
- Right to rectification. You have the right to ask us to rectify personal data you think is inaccurate. You also have the right to ask us to complete information you think is incomplete.
- Right to erasure. Under certain circumstances, you have the right to ask us to erase your personal data.
- Right to restrict processing. Under certain circumstances, you have the right to ask us to restrict the processing of your personal data. Please see YOUR PERSONAL INFORMATION CHOICES AND THE POSSIBLE CONSEQUENCES OF FAILURE TO PROVIDE YOUR DATA for additional ways in which you can restrict the processing of your personal data.
- Right to object to processing. You have the right to object, at any time, for reasons arising from your particular situation, to the processing of your personal data, which is carried out on the basis of our legitimate interests. See YOUR PERSONAL INFORMATION CHOICES AND THE POSSIBLE CONSEQUENCES OF FAILURE TO PROVIDE YOUR DATA for additional ways in which you can object to the processing of your personal data.
- Right to data portability. You have the right to ask that we transfer the personal data you gave us from one organization to another, or give it to you, in a structured, ordinarily used, and readable format.
- Right to lodge a complaint. You have the right to lodge a complaint with a supervisory authority.
To exercise these rights, please contact Ferrari through the interactive webform or by writing to Ferrari S.p.A, via Abetone Inf. 4; I-41053, Maranello, (MO), Italy. You may also contact YOOX NET-A-PORTER GROUP’s Customer Care.
a. Personal data transfer outside of the European Economic Area
Within our contractual relations, we may transfer personal data to countries outside of the European Economic Area (“EEA”). In the event that personal data is transferred outside of the EEA, we will use appropriate contractual measures to guarantee an adequate protection of personal data, including implementation of agreements based on the standard contractual clauses adopted by the EU Commission.
(6) CALIFORNIA RESIDENTS
This section supplements the other portions of this policy and applies solely to the personal information collected online about California consumers. This section is intended to address the relevant notice requirements of the CCPA, and uses certain terms that have the meaning given to them in the CCPA.
• Your information, sources and purposes: Please refer to the sections headed “Collection of Your Personal Data” and our Cookie Policy for a description of the personal information we may collect about you (or have collected in the preceding 12 months) and the sources of such information (such as directly from you and your device). These sections also describe the purposes for which we may use or have used such information. We do not collect or process sensitive personal information for any reason other than those permitted by California Civil Code section 1798.121(a) and the associated regulations. To the extent we process deidentified information, we will maintain and use the information in deidentified form and will not attempt to reidentify the information unless permitted by applicable law.
• Definition of “third parties”: under privacy regulations other than CCPA, service providers might be defined as ‘third parties’, albeit with a different meaning than that accorded to them by CCPA. In other sections of this privacy policy, the term “third parties” might have the meaning of service provider with regard to CCPA.
• Disclosing your information: We have not disclosed your personal information to any third parties in the last twelve (12) months, except as described below in connection with selling or sharing information. Please note that under privacy regulations other than CCPA, the term “sharing” might have a different meaning than the one accorded by CCPA. In other sections of this privacy policy, the term “sharing” might have the meaning of 'disclosure' with regard to CCPA.
• Selling your information/sharing your information for cross-context behavioral advertising: We do not sell or share your personal information in exchange for monetary compensation. As described in our Cookie Policy, we may allow certain third parties (such as certain advertising partners) to collect your personal information via automated technologies on our platforms in an effort to serve you content and advertisements that may be of interest to you. We also may disclose your personal information, such as your email address, with third parties to help support our marketing activities. In the preceding twelve (12) months, we have disclosed your internet or other electronic network activity information collected via cookies to data analytics providers and ad networks. This may be considered a sale or sharing for cross-context behavioral advertising under the CCPA. You have the right to opt out of this disclosure of your information, as described below. Ferrari does not have actual knowledge that it sells or shares personal information of minors under the age of sixteen (16) years.
To the extent the CCPA applies to the processing of your personal information you would be entitled to the rights listed below.
• Right to Access. You have the right to request we provide you the categories or specific pieces of personal information we collected; the purpose why we collected, shared, or sold that information; the categories of sources from which we collected your personal information; the categories of third parties to whom we disclosed your personal information; the categories of personal information we sold or shared; the categories of third parties to whom we sold or shared your information; and the categories of personal information we disclosed for a business purpose.
• Correction. You have the right to request that we correct the personal information we maintain about you, if that information is inaccurate.
• Right to Deletion. You have the right to request the deletion of your personal information that we collect or maintain, subject to certain exceptions.
• Right to Opt-Out. You have the right to opt-out of the sale of your personal information or sharing of your personal information for cross-context behavioral advertising. You can opt-out of cookie-based selling/sharing by clicking here or broadcasting the Global Privacy Control signal. For more information about how to use the Global Privacy Control signal, please see https://globalprivacycontrol.org/. In addition, you can opt out of other types of selling/sharing as further described in the CCPA Opt-out Page. Your opt-out will be specific to the browser and device you are using and will apply to the website domain on which you submit the request. If you clear your cookies or use a new browser or device to access the site, please submit a new request to re-apply your opt-out choice. You may opt-out of the cookies by following the instructions in our Cookie Policy.
• Right to Non-Discrimination. You have the right to not receive discriminatory treatment if and when you exercise your rights to access, correct, delete, or opt-out under the CCPA.
To exercise your rights, described above, you can:
For Ferrari you may submit a verifiable consumer request (i) by email at privacy2@ferrari.com; (ii) by telephone at 1-877-933-7727 or (iii) through the CCPA interactive webform.
For YOOX NET A PORTER GROUP:
• call the toll-free number 1-833-873-2288 from Monday to Friday from 9 a.m. to 11 p.m., excluding public holidays; or
• write to Customer Care by selecting the "privacy" topic in the relevant webform in the "Contact us" section of the Website; or
• contact us directly at the address indicated above. If you exercise your rights, we may require you to provide certain information to verify your identity (such as your name, email address, phone number and/or address).
You may make a verifiable consumer request for access twice within a twelve (12) month period.
To opt-out of the sale of your personal information via cookies, please visit our Cookie Policy or submit a request through the CCPA interactive webform.
Except for requests to opt out, you must provide us with sufficient information (i.e. name, surname and e-mail address) that allows us to reasonably verify you are the person about whom we collected the personal data and describe your request with sufficient detail to allow us to properly evaluate and respond to it. If we are not able to verify your identity with the information provided, we may ask you for additional pieces of information. The interactive webform contains the information that Ferrari needs to verify your identity and review your request.
Only you, or a person registered with the California Secretary of State that you authorize to act on your behalf, may make a request related to your personal data. If you are an authorized agent making a request on behalf of another individual, you must provide us with signed documentation that you are authorized to act on behalf of that individual.
(7)NEVADA RESIDENTS
If you are a consumer in the State of Nevada, you may request to opt out of the current or future sale of certain of your personal data. We do not currently sell any of your personal data under Nevada law, nor do we plan to do so in the future. If you have any questions regarding our data privacy practices, or would like to opt out of the future sale of your personal data, please contact Ferrari at privacy2@ferrari.com and/or YOOX NET A PORTER GROUP’s Customer Care
(8)RIGHTS OF INDIVIDUALS UNDER THE APPLICABLE NATIONAL DATA PROTECTION LAWS IN CHINA
To the extent of which the National Data Protection Laws in China apply to the processing of your personal data, you are entitled to the rights listed below.
- Right to access. You have the right to ask Ferrari for copies of your personal data. To the extent permissible by applicable National Data Protection Laws in China, some exceptions apply to this right, which means you may not always receive all personal data we process.
- Right to rectification. You have the right to ask Ferrari to rectify personal data you think is inaccurate. You also have the right to ask us to complete information you think is incomplete.
You may request us to delete your personal information if:
(1)we process your personal data in violation of applicable laws and regulations;
(2)we collect and use your personal data without obtaining your consent;
(3)we process your personal data in a way that seriously violates our agreement with you;
(4)you no longer use our products or services;
(5)we terminate our services and operations, or the retention period has expired.
For avoidance of doubt, we may reject your request for erasure if: (A) we have other legal grounds for continuing to process your personal data; (B) the legal retention period has not yet expired; or (C) it is technically impossible or difficult to achieve the deletion of the applicable personal data (in which case, we will cease processing activities other than storing and taking necessary safeguard measures in respect of the applicable data).
- Right to restrict or to Object to processing. You have the right to ask Ferrari to restrict, or you can object to, the processing of your personal data as provided for under the applicable National Data Protection Laws in China.
- Right to data portability. You have the right to ask that we transfer the personal data from us to another organization subject to the conditions set forth by the applicable PRC data protection authority.
- Right to lodge a complaint. You have the right to lodge a complaint with a supervisory authority in China.
- Right to explanation. You have the right to request an explanation of our rules (including this Privacy Policy) regarding the processing of your personal data.
- Any other right that you may have under the applicable National Data Protection Laws in China.
You may ask Ferrari and/or YOOX NET- A-PORTER GROUP for further information or clarification with respect to personal data processing activities, this Privacy Notice or your rights as the data subject by contacting us as per the following means:
- Ferrari S.p.A., with registered office in via Emilia Est, n. 1163, Modena, Italy, headquartered in via Abetone Inferiore, n. 4, Maranello, Italy. Data Protection Officer: privacy2@ferrari.com.
- YOOX NET-A-PORTER GROUP S.p.A., company with sole shareholder subject to direction and coordination of Compagnie Financière Richemont S.A., with registered office at via Morimondo, 17 – Milan 20143, Italy. You may contact us at any time by selecting ‘privacy’ and sending a request to our Customer Care, or by writing to the address of the registered office of YOOX NET-A-PORTER GROUP S.p.A.. If you so wish, you may also contact our Data Protection Officer (“DPO”), by writing to the aforementioned address, or by sending an email to DPO@ynap.com.
We will normally respond to your request or question within thirty (30) days after verifying your identity unless the applicable National Data Protection Laws in China state otherwise.
a. Personal data transfer outside of your jurisdiction.
In order to centralize the storage and processing of personal data within Ferrari Group and for efficiency and security, we will store your personal data at data centers within the EEA, and we will ensure that your personal data is protected in accordance with the requirements and standards under the GDPR, and, in any event, at such level no lower than the requirements under the applicable National Data Protection Laws in your jurisdiction.
(9)RETENTION
We keep your personal information for a limited period of time depending on the purpose for which it was collected. After such period, your personal information will be deleted or otherwise rendered anonymous in an irreversible way. The retention period is different depending on the purpose of the processing. For example, the personal information collected when items are purchased on the Website is processed until all administrative and accounting formalities have been completed. Therefore, it is kept on file in conformity with the local tax legislation, while the personal information used to send you our newsletter is kept until you request that we stop sending it. Ferrari retains the personal information for ten years from the time it was provided for marketing and profiling purposes unless consent is revoked. If consent is revoked, your personal information may not be processed for the aforementioned purposes, but may still be kept to manage any objections and/or disputes. The data used to manage Web Push Notifications will be retained up to the point in which consent is revoked by the data subject or up to 365 days from the last visit made to the Website by the data subject. Hashed data used for Custom and Lookalike Audiences is deleted once Social Networks have completed the matching process.
You can revoke your consent to receive these personalized commercial notifications (depending on your browser) at any moment. As part of the Live Chat service, text messages sent by the user, including attachments, will be stored for 6 months on the server of the external service provider we use, while the images taken during a video call are not stored. The Data processed for the purposes of registering to Live Chat will be kept for the time necessary to provide the service, except in the case in which the cancellation of the registration is requested.
(10) DO NOT TRACK
We do not respond to Do Not Track (“DNT”) requests. Do Not Track is a preference you can set in your web browser to inform the Website that you do not want to be tracked. You can enable or disable Do Not Track by visiting the Preferences or Settings page of your web browser. For further details, please click here
(11)INFORMATION SECURITY
The processing of your personal data takes place using IT and manual tools, with logic strictly related to the purposes of the processing indicated above and, in any case, in order to guarantee the protection, confidentiality and security of the data. We implement and maintain reasonable security measures to protect the personal information we collect and maintain from unauthorized access, destruction, use, modification, or disclosure. However, no security measure or modality of data transmission is 100% secure and we are unable to guarantee the absolute security of the personal information we have collected from you.
(12)CHILDREN’S PRIVACY
The Website and the services offered thereon are not intended for individuals under the age of eighteen (18) years.
(13) LINK TO THIRD-PARTY WEBSITES
Third-party websites accessible from this Website are under the third party responsibility.
We decline all responsibility concerning requests and/or provision of personal data to third-party websites.
(14) AMENDMENT OF THIS PRIVACY NOTICE
This Privacy Notice is subject to change. Changes to the Privacy Notice will be posted on this page and will indicate the date on which changes go into effect. Please check back frequently and review the Privacy Notice for any changes. If we make any changes that materially affect your privacy rights, we will notify you via email or by prominent posting on the Website.
This Privacy Policy was last updated on July 31, 2023.