Prada S.p.A., with its registered office in Milan (Italy), the operating holding company of the PRADA Group (defined below) and site manager of www.miumiu.com, together with its subsidiary, PRADA USA Corp., with its registered office in New York (USA), (collectively, “PRADA”) is committed to protecting the Personal Data (defined below) that you share with us, and explaining how we collect, process, and share that information. We collect your Personal Data on the Website (defined below), by phone and/or through our stores to enhance the services we offer you, process and fulfil remote, in person or other sales, maintain and improve the Website, protect the security of you and our Website, comply with legal obligations, and inform you about other services and products that may be available through us, our affiliated companies, and our marketing partners.
1. Scope of this Privacy Statement and How We Collect and Use Personal Data
This Privacy Statement applies to Personal Data collected on our websites, mobile applications, cloud-based services, and controlled widgets embedded in communication platforms or other locations, each with a link to this Privacy Statement (collectively, the “Website”). It covers how we collect, use, share, and otherwise process personal information as of the date that this Privacy Statement is posted. This Privacy Statement also applies to the Personal Data collected by phone, email, incoming text messages, or in stores operated by PRADA USA Corp as well as Prada S.p.A and its subsidiaries and/or affiliates (collectively the “PRADA Group”) when you interact with our Client Service team or sales staff, or when you purchase our products or you use our services. It does not apply to any other information collected by PRADA through any other means. “Personal Data” includes information that identifies or can identify you personally, including those listed in the “Categories of Personal Data” outlined below. By using this Website or voluntarily providing personal information to us, you consent to the terms of this Privacy Statement. If you do not agree to the policy, please do not use the Website or provide any Personal Data to our Client Service team or sales staff.
The Website and any “Pay By Link” links we send to you to conduct any sales including any remote sales may contains links to third-party websites, including websites of our business partners. We do not own, operate or control the websites of those third parties. Accordingly, this Privacy Statement does not apply to any websites maintained or operated by third parties for the collection, use, storage, disclosure, or other processing of your Personal Data. When you click on those links, you will go to a third-party website where you will be subject to that website’s privacy statement, and we encourage you to read that policy statement.
Personal Data we may collect and purposes
The tables below explain the categories of Personal Data we may collect and the purposes for the collection and use of this information. Further detail is set out in the “Additional Information on Purposes of Use” below.
Categories of Personal Data
Purposes for Collection and Use
Source of Personal Data: Information you provide to us in our stores or in the course of using or processing online services or remote order/sales services, including chatting online with or otherwise contacting PRADA Client Service:
Identification and contact information: such as your name and surname, title, day and month of birth, location, User id (e-mail address), password, postal address, email address, telephone numbers, or other contact details information you may provide to us
To register into the PRADA Group customer database (e.g. by completing our Customer Card or registering on our Website) to be provided with exclusive services and benefits reserved to registered members;
to manage your online account profile;
to subscribe to our newsletter service;
to book an appointment, participate in other services, or pick-up products, at a PRADA Group store;
to send a request to/contact our Client Service team;
to confirm your identity as a registered member;
to inform you about other services and products that may be available through us, our affiliated companies, and our marketing partners;
to process or fulfil remote or other sales;
to provide and deliver products and services requested;
to send you information related to products and services, including catalogs, invoices, technical notices, updates, security alerts, and support and administrative messages;
to communicate with you about new contests, promotions and rewards, upcoming events, and other news;
to respond to all your requests, and to manage your relationship with the PRADA Group; and
to manage and administer our community features and member programs and services.
Purchase and order information: billing address, shipping address, together with purchase details (products, color, size, quantity, price), methods of payment and/or any communications we have received about your order or purchase
To place your Website and/or remote sales orders;
to perform all management activities connected with your order, including administrative management of the contract, delivery of goods, payment processing, invoicing, management of any claims and litigation, and fraud prevention, and to validate, confirm, verify, deliver, install, and track your order, including to arrange for shipping, handle returns, exchanges and refunds, and maintain a record of the purchases you make;
to service products you purchased from us;
to provide you post-sale services (including repairs service), and
to provide you offers that may be of interest to you.
Payment information: name, card issuer and card type, credit or debit card number, expiration date, CVV code and/or billing address
To check that the right person is using the right card or account;
to meet the requirements of the card brands or account issuers; and
to make sure we are paid for what you buy.
Information you provide about a third party: name, surname, address and contact details of recipient for delivery of goods or services (such as sending a gift or virtual gift card), if different from yours
To deliver to, or communicate with, the person at the address which you have requested.
Preference information: your account settings including preferred store, your wishlist, contact channel and types of services/offers that interest you
To personalize your experience and to enhance the services we offer you.
Other voluntary information: Other voluntary information: any voluntary information you may provide us within the course of your interactions with us (such as by sending an e-mail through our Website and/or to the addresses indicated in our Website or by calling, e-mailing or texting our Client Service team and/or store staff or by responding to surveys or competitions)
To handle your requests, and to contact you when necessary or requested, including to respond to your comments and questions and provide customer service; and to know you better, make our communications with you more personal, learn and improve from your survey feedback, organize events, and/or pick competition winners.
Please note that we may record calls to and chats with our Client Service team for quality assurance and internal training purposes.
Source of Personal Data: Information we may collect automatically from you and/or your device:
Sensitive personal information: such as your driver's license number, state identification card, precise geolocation (if you permit us to obtain your precise geolocation) and your racial and ethnic origin; combination of email address, financial account, debit card, or credit card with security or access code, password, or other credentials allowing access to your account
To confirm your identity;
to provide you offers that may be of interest to you;
to personalize your experience and to enhance the services we offer you;
for analytical and demographic purposes and to provide offers that may be of interest to you.
Your sensitive personal information will not be used for any additional purposes that are incompatible with the purposes listed above, unless we provide you with notice of those additional purposes.
Device information: IP address, internet provider, operating system and browser used, domain names of the computers you use to visit our Website, type of device, such as laptop or smart phone, log files, URIs (Uniform Resource Identifiers) of the resources requested, the time of the request, the method used to submit the request to the server, the size of the file obtained in reply, the numerical status code of the server reply (successful, error, etc.) and other parameters concerning the user's operating system and computer environment, and/or device cookie settings and other device details, such as MAC address
To obtain anonymous statistical information on the use of our Website and to guarantee its correct operation, to make sure our Website works properly with your device and make sure you can see and use our intended Website on the device you are using, and for analytical and demographic purposes and to provide offers that may be of interest to you.
We also will use this information to protect the security and/or integrity of the Website and our business, such as by protecting against and preventing fraud, unauthorized transactions, and managing risk exposure, including by identifying potential hackers and other unauthorized users.
Information automatically collected from your browser: when you use the Website, some data is automatically transferred from your browser to our server, including your browser type, operating system type or mobile device model, viewed webpages, links that are clicked, IP address, mobile device identifier or other unique identifier, sites or apps visited before coming to our Website, the amount of time you spend viewing or using the Website, the number of times you return, or other click-stream or site usage data, and emails we send that you open, forward, or click through to our Website
We will use this information in an aggregated non-specific format for analytical and demographic purposes.
To protect the security or integrity of the Website and our business, such as by protecting against and preventing fraud, unauthorized transactions, and managing risk exposure, including by identifying potential hackers and other unauthorized users.
Source of Personal Data: Information we may collect from third parties
Legal information: fraud checks or flags raised about your transactions, payment card refusals, suspected crimes, complaints and/or claims
To protect you, other customers and our business against criminal activities and risks, and to make sure we understand and can meet our legal obligations to you and others, and can defend ourselves.
Social Media Information: if you interact with us through a social media service or log in using social media credentials, depending on your social media settings, we may have access to your information from that social network such as your name, email address, age, gender, and location
To allow you to register on our Website through social media login, and
to personalize your experience and to enhance the services we offer you.
Online payment account information: if you choose to pay your online purchase by using your online payment account (e.g. Apple Pay or Paypal) we may have access to your information from that payment system such as your name, email and address.
to process or fulfil your order and perform all management activities connected with it including administrative management of the contract, arrange for shipping, handle returns, exchanges and refunds, and maintain a record of the purchases you make; and
to provide and deliver products and services requested
Additional Information on Purposes of Use
Registration to PRADA Group Customer Database
If you register to the PRADA Group customer database (e.g. as a result of your registration to the Website or your completion of the Customer Card), your Personal Data will be managed by PRADA S.p.A. and shared with all PRADA Group stores globally, and may be processed, together with the details of your purchases online and/or in stores, for the following purposes:
(1) to confirm your identity as a registered PRADA Group customer and, consequently, to provide a customized global customer care service and post-sales assistance, and allow you to access exclusive services and benefits reserved for registered members (e.g.: preservation of your purchase order history, faster online checkout, simplified procedures for product repair and warranty, invitation to events, pre-sale and other promotional initiatives and special projects, etc.);
(2) to offer you a personalized and tailored experience with regards to your preferences for MIU MIU and the other brands, products and services of the PRADA Group, including by performing statistics, market research and surveys; and/or
(3) to contact you and/or send you (by post, telephone, e-mail and any other form of electronic communication or digital means including social network platforms and other instant messaging applications) information and promotions, including commercial information, newsletters, direct marketing material, advertising, catalogues concerning MIU MIU and other brands, products and services of the PRADA Group.
You may revoke your consent to receive our commercial communication and modify your communication preferences and/or opt-out from specific electronic communications at any time free of charge by notifying us via email at email@example.com or clicking “unsubscribe” in an electronic message and/or by logging into your online account.
You also can withdraw from or cancel your registration in the PRADA Group customer data base at any time by contacting us at firstname.lastname@example.org and/or by logging into your online account.
3. Controlling Our Tracking Tools
Your browser may give you the ability to control cookies. How you do so, however, depends on your browser and the type of cookie. Certain browsers or browser plugins can be set to reject all browser cookies. If you configure your computer to block all cookies, you may disrupt certain web page features, and limit the functionality we can provide when you visit or use our Website (e.g., we will not be able to provide you with searches that you have asked us to save). You can change your cookie settings at any time.
4. Controlling Online Interest-Based Ads.
We sometimes work with online advertising vendors to provide you with relevant and useful ads. This may include ads served on or through our Website. This may also include ads served on other companies’ websites. These ads may be based on information collected by us or third parties, including demographic information that will allow us to better communicate with you and enhance our customer service and your shopping experience. For example, your postal code may be used to target an ad for people in your area. These ads may also be based on your activities on our Website or on third-party websites.
5. Personal Data of Minors
You must be at least 16 years old (depending on the state of residence) in order to provide us with Personal Data, and at least 18 years old to purchase products from our Website. We do not have actual knowledge about selling or sharing PI of consumers under the age of 16. If you become aware of any selling or sharing information from children under 16, please call us at 1-888-964-8648 or email us at email@example.com.
Under Age 13
PRADA complies with the Children’s Online Privacy Protection Act of 1998, which prohibits collecting personal information from children under the age of 13 without verifiable parental consent. If it comes to our attention that we have unknowingly collected information from a child under the age of 13, we will take all reasonable measures to delete it as soon as possible and will not use such information for any purpose (except where necessary to protect the safety of the child or others as required or allowed by law). If you become aware of any personally identifiable information we have collected from children under 13, please call us at 1-888-964-8648 or email us at firstname.lastname@example.org.
Under Age 18
Minors under 18 years of age may have the personal information that they provide to us deleted by sending an email to email@example.com requesting deletion. Please note that, while we make reasonable efforts to comply with such requests, deletion of your personal information does not ensure complete and comprehensive removal of that data from all systems.
6. Security of Your Personal Data
Your Personal Data will be processed by suitable electronic or automated means and computerized tools, or manually and on hard copy, exclusively for the purposes for which they have been collected and according to criteria of lawfulness and correctness and protecting the security and confidentiality of Personal Data through the adoption of appropriate measures to prevent loss, alteration, cancellation, destruction, unauthorized access or not allowed processing or not in accordance with the purpose of collection. However, while we strive to protect your Personal Data, we cannot ensure the security of the information you transmit to us. In this regard, we urge you to take every precaution to protect your Personal Data while you are on the Internet. At a minimum, we encourage you to make sure that you are using a secure browser as you surf the Internet.
Your Personal Data will be processed by the PRADA Group’s internal staff who are duly authorized to do so in accordance with their respective job duties. Your Personal Data may also be processed by third parties to the extent necessary and/or instrumental for the above purposes. These third parties will act on behalf of PRADA as data processors and are under a contractual obligation of confidentiality in regards to the relevant personal information.
7. Transfer and Disclosure of Personal Data
Whenever necessary and/or instrumental to the above-mentioned purposes, your Personal Data may be processed on behalf of PRADA by other entities acting as data processor, with a contractual obligation to maintain the confidentiality of the personal information shared with them, including:
• Related Companies: PRADA Group companies and franchisees that operate PRADA Group stores;
• Service Providers: third party service providers, consultants, or firms engaged by PRADA to perform business purposes including website analytic services, hosting, transaction and payment processing, promotional campaign management, fraud prevention, shipping of goods, IT maintenance, etc.
As PRADA is part of an international network, your Personal Data may be transferred abroad in accordance with applicable legislation, including to countries outside the United States and the European Union, where PRADA pursues its interests, by adopting all appropriate security measures and safeguards to ensure an appropriate level of data protection and security.
Your Personal Data will not be used for third-party advertising purposes or for the promotion of products, services or initiatives by entities other than the PRADA Group, nor shall they be disclosed to unknown persons under any circumstances.
Communication of data to the other PRADA Group companies
As we operate globally, please also note that if you register on the PRADA Group customer database, the Personal Data of your membership account will be automatically visible to, and securely shared with, all PRADA Group stores globally in order to provide you with the same quality of service wherever you choose to interact with us around the world (i.e. when you travel and purchase our products or visit our stores). PRADA will take all appropriate security and confidentiality measures as required by applicable legislation to ensure an adequate standard of data protection.
Click here to see the Prada Group retail and affiliated companies and the jurisdictions in which we operate.
In Connection with Business Transfers
In the event that a division, a portion, or all of PRADA is bought, sold or otherwise transferred, or is in the process of a potential transaction, customer Personal Data will likely be shared for evaluation purposes and be included among the transferred business assets.
To Comply with Laws
PRADA may also disclose specific information when such disclosure appears necessary to comply with the law, a subpoena or other litigation process or to protect the interests or safety of its visitors and customers, PRADA employees or others.
8. Retention Period
Your Personal Data will be processed and stored for: (a) as long as required to carry out the purposes for which the Personal Data was collected; (b) in accordance with the storage periods required by applicable laws; or (c) until you revoke your consent to the processing/storage of your Personal Data, if applicable. After the conclusion of such period(s), and where there is no legal or business purpose for retaining your Personal Data, it will be automatically and permanently erased or made anonymous.
In particular, regarding the data processing of registered members into the PRADA Group customer database:
• Personal Data of your membership account are kept for a period of 7 years from the date of the interaction with the PRADA Group, or otherwise until you withdraw from or cancel your registration in the PRADA Group customer data base; and
• Purchase details are kept for a period of 7 years from the date of purchase.
9. Your Rights
Please note that you may exercise your rights under applicable privacy laws, including the right to request information as to whether your Personal Data is being processed, and as to the characteristics of the processing, the right to rectification and erasure of your Personal Data, and/or the right to have such Personal Data transmitted to another controller.
You also have the right to withdraw your consent for the collection and processing of your Personal Data by PRADA at any time, without charge. The withdrawal of your consent will not affect the lawfulness of PRADA’s processing of your Personal Data based on your consent before its withdrawal.
If you have any requests regarding your Personal Data, have any inquiries regarding this Privacy Statement, or you would like to exercise your rights or receive any information about your rights, please contact (free of charge) the Data Controller or the Group Data Protection Officer (“DPO”) by writing to the addresses/email addresses listed below.
10. Your California and Other State Privacy Rights
If you are a resident of California or Virginia (starting Jan. 1, 2023), Colorado or Connecticut (starting July 1, 2023), or Utah (starting Dec. 31, 2023), the law in those states provides you with the following rights with respect to your Personal Data:
Your California Privacy Rights
• The right to know what personal information we have collected, used, disclosed and sold about you, including the categories of personal information, the categories of sources from which the personal information is collected, the business or commercial purpose for collecting, selling, or sharing personal information, the categories of third parties to whom PRADA discloses personal information, and the specific pieces of personal information PRADA has collected about you.
• The right to correct inaccuracies in your personal information, taking into account the nature of the personal information and the purposes of the processing.
• The right to request that we delete any personal information we have collected about you.
• The right to opt-out of the selling or sharing of your personal information, which you can exercise through the contact form available on our website or by modifying your privacy preferences (e.g., Global Privacy Control), available through certain internet browsers and extensions, that signal to websites you visit your preference to opt out. Please note that clearing your cookies at any time will remove the signal of your selected privacy preferences.
To submit any of the above requests under your California privacy rights, you may contact us at 1-888-964-8648 or use the contact form available on our website or email us at firstname.lastname@example.org with the subject “Consumer Privacy Request”. You may also designate an authorized agent to make a request for correction on your behalf on our website through our contact form. When you exercise these rights and submit a request to us, we will verify your identity by asking you to provide us with additional information such us your email address, order numbers of previous orders of our products and services, or the last four digits of a credit or debit card used to make a purchase. We also may use a third-party verification provider to verify your identity. We will endeavor to honor such requests unless such a request conflicts with certain lawful exemptions under California’s consumer privacy law. Please note that we are only required to honor requests to know twice in a 12-month period.
We do not discriminate against California residents who exercise any of their rights described in our Privacy Statement. Your exercise of these rights will have no adverse effect on the price and quality of our goods or services.
In addition, and as set forth below, California law requires us to identify, for the 12-month period prior to the date of this Privacy Statement, what information we may have “sold” or “shared” about you. For the 12-month period prior to the date of this Privacy Statement, PRADA has not sold any personal information about its customers. For the 12-month period prior to the date of this Privacy Statement, PRADA has only shared personal information about its customers as described above. PRADA does not use or disclose sensitive personal information, as defined in applicable laws, for any purposes other than those permitted by applicable law.
This Privacy Statement describes how we may share your information for marketing purposes, as described above. If you are a California resident, the Shine the Light law permits you to request and obtain from us once per calendar year information about any of your personal information shared with third parties for their own direct marketing purposes, including the categories of information and the names and addresses of those businesses with which we have shared such information. To request this information and for any other questions about our privacy practices and compliance with California law, please contact us through our website contact form.
Your Virginia (starting Jan. 1, 2023), Colorado (starting July 1, 2023), and Connecticut (starting July 1, 2023) Privacy Rights
• The right to confirm whether we process your personal information and access your personal information.
• The right to correct inaccuracies in your personal information, taking into account the nature of the personal information and the purposes of the processing.
• The right to delete personal information we have obtained about you.
• The right to opt out of the processing of your personal information for purposes of targeted advertising, the sale of personal information, and/or profiling in furtherance of decisions that produce legal or similarly significant effects.
• The right to obtain a copy of personal information we have obtained about you in a portable and, to the extent technically feasible, readily usable format.
• If we deny your request, the right to appeal our decision.
To submit any of the above requests, you may call us at 1-888-964-8648 or use the contact form available on our Website or email us at email@example.com with the subject “Consumer Privacy Request”. When you exercise these rights and submit a request to us, we may need to verify your identity by asking to provide additional information that we can verify. We may also use a third-party verification provider to verify your identity. We will endeavor to honor such requests unless such a request conflicts with certain lawful exemptions under your state’s consumer privacy law.
The fact that you have elected to exercise these rights will have no adverse effect on the price and quality of our products or services.
To appeal a decision we have made regarding your request, you may call us at 1-888-964-8648 or use the contact form available on our Website or email us at firstname.lastname@example.org. We will respond to appeals from Virginia and Connecticut residents within 60 days. We will respond to appeals from Colorado residents within 45 days.
11. Data controllers and Contacts
If you have any questions about this Privacy Statement or to request this Privacy Statement in another format, please contact us at:
PRADA USA Corp.
610 West 52nd Street, New York, New York 10019
Via Antonio Fogazzaro 28, Milan (Italy)
Group Data Protection Officer
e-mail address: email@example.com
12. Effective Date, Amendments
The Privacy Statement is currently in force is the one published on our Website. We may amend it from time to time, and if we make material changes, we will prominently post a revised version on the Website. Where required to do so by law, we may seek your prior consent to any material changes we make to this Privacy Statement.
Last updated: December 28, 2022