Hugo Boss USA Privacy Policy

  • Last Updated as of July 1, 2023
  • We at HUGO BOSS USA (including HUGO BOSS FASHIONS, INC., HUGO BOSS RETAIL, INC., and their U.S. affiliates) respect your concerns about privacy. This Privacy Policy describes the type of Personal Information that we collect about our consumers on our U.S. Sites and certain other U.S. Channels (as defined below); how we collect, process, use and share the information; as well as choices that you have regarding such use. For the purposes of this Privacy Policy, “Personal Information” means information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked, directly or indirectly, with a particular consumer or household; “Personal Information” also includes any other information related to a particular individual that constitutes “personal information” or “personal data” under any privacy or data protection law that applies to our consumers. Data that is aggregated or de-identified is not Personal Information.
  • If you are a resident of California, Virginia, Colorado, Connecticut, or Utah, there are additional disclosures, rights and procedures that apply to you or from which you may benefit, in addition to those described in the general Hugo Boss USA Privacy Policy; please see our Privacy Notice for California Residents and Privacy Notice for Residents of VA/CO/CT/UT and Other States, below, for more information.

Summary of Key Policy Provisions

Collection

We collect Personal Information about you that you provide to us while you are using our Sites or other Channels.

Protection

We employ appropriate technical, administrative, and physical safeguards that are designed to prevent unauthorized access, maintain data accuracy, and designed to ensure correct use of Personal Information.

Use By Us

We use Personal Information to provide you with services, to build features that will make the services available on our Sites or Other Channels easier to use; to contact you about these services, to send advertisements, marketing material or other offers that we think might be of interest to you; to perform data analytics; or for other purposes permitted by law.

Marketing

You have control on how we use Personal Information for marketing, including exercising your right to opt-out of further marketing communications.

Sharing

We share your Personal Information with our affiliates, external service providers, third party vendors, agents, and/or other, unaffiliated third parties for marketing; collection and analysis, including for fraud prevention or other lawful services; and/or as may be necessary to perform transactions with you and manage our business.

Cross-Border Data Transfers

Our Sites and Other Channels are operated solely for the United States (“U.S.”) market and are not designed for sales of products to individuals located in foreign jurisdictions. If you are located outside the U.S. and use our Sites, you are advised that your Personal Information will be automatically transferred to the U.S. To the fullest extent permitted by law, you assume all risks relating to any such cross-border data transfer.

Children

Persons under the age of 16 are not eligible to use any services on our Sites.

Changes

We will prominently post any material changes to our Privacy Policy. Any material changes to this Privacy Policy will be effective after posting.

Contact Us

If you have any questions, concerns, or comments, please contact customerservice-us@hugoboss.com. You may also contact us directly at Hugo Boss Fashions, Inc., Attn.: Privacy Office, 55 Water Street, 48th Floor, New York, NY 10041

What information does this Privacy Policy cover?

This Privacy Policy applies to Personal Information that we collect through the following channels (each, a “Channel”) in the United States:

  • hugoboss.com/US or HUGO BOSS related US: websites, mobile applications or other digital communication platforms with a link to this Privacy Policy directed to U.S. shoppers (collectively, “Sites”);
  • your visits to freestanding Retail and Outlet stores operated in the U.S. by Hugo Boss Retail, Inc. or its US affiliates (collectively, “Retail Stores”);
  • other channels associated with such Sites, Retail or Outlet stores that are operated by us or on our behalf, such as when you connect with us via telephone, at our events, through surveys you may choose to complete; sweepstakes or promotions which you may participate in; the HB My Experience iPad or online registration program; or via our official social media pages or similar networks directed to the U.S. market (collectively, “Other Channels”)

This Privacy Policy is effective as of the date that this Privacy Policy is posted. Any links that we provide to third-party websites or services are provided for your convenience and information. We do not own, operate or control such third party properties and this Privacy Policy does not apply to unaffiliated sites or services. If you visit any linked third party sites or services, please review any applicable privacy policies. We are not responsible for the content of unaffiliated sites, any use of such sites or services, or the privacy practices of any third parties.

Disclaimer of Liability for Any Transfer of Personal Information from Other Jurisdictions to the United States

Hugo Boss USA is headquartered in the U.S. and our Sites and Other Channels are operated solely for the U.S. market and are not designed for sales to individuals located in foreign jurisdictions. If you decide to use our Sites or Other Channels, your Personal Information will be automatically transferred to the U.S., and processed according to the terms described in this Privacy Policy. To the fullest extent permitted by law, we disclaim all liability, and you assume all such risk, hold us harmless, and irrevocably waive any claim you may have against us relating to, any cross-border transfer or your Personal Information.

What types of Personal Information do we collect?

If you are a resident of California, Virginia, Colorado, Connecticut, or Utah, please see our Privacy Notice for California Residents and Privacy Notice for Residents of VA/CO/CT/UT and Other States, below.

The Personal Information collected by Hugo Boss USA may include, for example, your:

  1. Contact information (such as name; postal or billing address; email address, mobile or other telephone number);
  2. Username and password for Sites;
  3. Purchase and transaction information;
  4. Photographs, comments and other content you provide;
  5. Information you provide about friends, merchandise recipients, or others;
  6. Social Media account information (username and website);
  7. Customer service and technical support information (e.g., inquiries, comments, incident information, returns information);
  8. Payment card or other related information (such as your payment card number, expiration date, authorization number or security code, and billing address), collected and stored through our third party payment service providers;
  9. Survey response information, such as information regarding personal or professional interests, demographic information, marital status, and experiences with our products or services; and
  10. Birth date for those choosing to provide it as part of HUGO BOSS EXPERIENCE;
  11. Information you submit in connection with a career opportunity at Hugo Boss, including contact details, work history, education, skills, and details about your current employment; and
  12. General activity information as part of our and our third party payment providers’ fraud-prevention programs.

If you can’t or choose not to provide us with the Personal Information we reasonably require, we may be unable to provide you with the information or services you have requested.

How do we collect Personal Information?

Information Submitted by You. We collect Personal Information from you when you:

  1. Register with us online, at a Hugo Boss Retail Store, for the MY HUGO BOSS EXPERIENCE program or through any Other Channels;
  2. Purchase products or services from our Sites, Retail Stores, or Other Channels;
  3. Sign up for our newsletter or to receive other marketing information;
  4. Request we alert you when an item or type of item is back in stock;
  5. Participate in promotions, surveys, rewards or gift card products and programs;
  6. Submit comments, reviews, or other user-generated content;
  7. Connect or interact with us through social networks (e.g., Facebook, WhatsApp, Google+, Twitter);
  8. Request customer or technical support, including but not limited to through our chat or Contact/Customer Service functions of our Sites and Other Channels, 800 number and via e-mail and via text;
  9. Participate in MY HUGO BOSS EXPERIENCE; and
  10. Submit payment information (which we will use, e.g., to process a transaction or prevent fraud and allow for safer e-commerce shopping experiences).

Text Messages. You may elect to receive text messages from us when you visit our Sites, use our services, or visit us in person (such as at a store location). When you sign up to receive text messages, we will send you information about promotional offers and more. These messages may use information automatically collected based on your actions while on our sites and may prompt messaging such as cart abandon messages. To the extent you voluntarily opt to have Text notifications sent directly to your mobile phone, we receive and store the information you provide, including your telephone number or when you read a text message. You may opt out of receiving text messages at any time by texting “STOP” to our text messages. For more information about text messages, see our Terms and Conditions.

Information Collected Through Technology. We also obtain information in other ways through technology. Some of this information may be linked to you personally. This information helps our Sites function correctly and supports the work we do to understand the needs of our customers. Device and activity data may be automatically collected via our Sites, as described below.

  • Device Information. Depending on the permissions you’ve granted and other factors, we may receive information about your location and your mobile device when you download or use apps created by our Sites, including a unique identifier for your device. We may use this information to provide you with location-based services, such as advertising, certain player search results, and other personalized content. Examples of the device information we may collect include:
  • Attributes such as the operating system, hardware version, device settings, file and software names and types, battery and signal strength, and device identifiers.
  • Device locations, including non-specific geolocation data.
  • Connection and device information such as the name of your mobile operator or ISP, browser type, language and time zone, mobile phone number and IP address.

Most mobile devices allow you to turn off location services, and we encourage you to contact your device manufacturer for detailed instructions on how to do that. 

  • Activity and Cookie Data. Your Internet browser has a feature called cookies, which store small amounts of data on your computer or device about your visit to our Sites. We and our service providers use browser and flash cookies and other common online tracking technologies, including electronic images known as “web bugs” (sometimes called transparent GIFs, clear GIFs, or beacons”). We generally refer to such other tracking technologies and cookies as “cookies.” 

Cookies allow us and our service providers to automatically collect information regarding general user-traffic patterns, and your interactions with our Sites, including managed social media presences, and other unaffiliated sites and mobile applications. In using such technology, we thus collect such automatically transmitted data as the page served, time, source of the request, type of browser making the request, preceding page view, dynamic IP addresses and other such information to understand how our advertising campaigns are performing or how to improve and tailor advertising and the Sites experience for you. Unless you have registered for one of our products or services, the information we gather through the use of tracking technologies cannot be matched with any personally identifiable information about you. Please see below for a description of how our Sites may be impacted by cookie settings on your devices. 

Payment Information. If you purchase any products on our Sites, we will collect payment card information from you, including your name, expiration date, authentication code, and billing address. This information will be transmitted to appropriate third party payment service providers. We may offer you the option to save certain payment card information on our Sites. If you elect to save such information on our Sites, you will be able to add, delete, or modify that information at any time using your account settings. However, we may from time to time request and receive some of your financial, transactional or other information from such third party payment service providers for the purposes of completing transactions you have initiated through the Sites, enrolling you in discount, rebate, and other programs in which you elect to participate, protecting against or identifying possible fraudulent transactions, and otherwise as needed to manage our business.

Social Media Platforms and Networks. If you interact with us on social media or use features, such as plugins, widgets, social media sign-in or other tools made available by social media platforms or networks (such as, but not limited to, Facebook Connect) in connection with our Sites and Other Channels, we may collect information that you share with us on social media or that such platforms share with us. Please review the privacy policies and settings of the social media platforms and networks that you use for more information about their privacy practices.

What are our policies to manage cookies, “Do Not Track” signals and interest-based advertising?

Cookie Policy; Controlling Our Tracking Tools.

You do not need to have cookies turned on to visit our Sites, although active participation in certain areas of our Sites may require cookies. You can set your browser to refuse or delete cookies. Please consult the corresponding instructions of the manufacturer for more detailed information on the actual procedure. If you configure your computer or device to block all cookies, you may disrupt certain features of our sites and limit the functionality we can provide when you visit or use our Sites. If you block or delete cookies, not all of the tracking that we have described in this Privacy Policy will stop.

Responding to “Do Not Track.” Some browsers have a “Do Not Track” (DNT) feature that lets you tell websites that you do not want to have your online activities tracked. These browser features are still not uniform, so we are not currently set up to respond to those signals. However, if you are a resident of California, Colorado, or Connecticut, we treat opt-out preference signals as a means of opting out of the sale or sharing of personal information, or of opting out of the processing of personal information for targeted advertising, as applicable. Please see our Privacy Notice for California Residents and Privacy Notice for Residents of VA/CO/CT/UT and Other States below for more information.

Controlling Online Interest-Based Ads.  We sometimes work with online advertising vendors to provide you with relevant and useful ads, including ads served on or through our Sites or on other companies’ websites. These ads may be based on information collected by us or third parties on our Sites and through third party websites. For example, your postal code may be used to target an ad for people in your area. These ads may also be based on your activities on our Sites or on third party websites.

You may prevent Google’s collection of data generated by your use of the Sites (including your IP address) by downloading and installing a Browser Plugin available at https://tools.google.com/dlpage/gaoptout?hl=en.

To exercise certain opt-out choices you may have regarding Cookies from certain providers, please visit the consumer opt-out pages at the Digital Advertising Alliance and Network Advertising Initiative.

Cookie-based opt-outs are not effective on some mobile devices. Users may opt out of certain ads on mobile applications or reset advertising identifiers via their device settings. To learn how to limit ad tracking or to reset the advertising identifier on your iOS and Android device, click on the following links: 

iOS - https://support.apple.com/en-us/HT202074

Android - https://support.google.com/ads/answer/2662922?hl=en

mobile application(s) available in Google Play or the Apple App stores. More information about opting out on mobile devices is available here - https://www.networkadvertising.org/mobile-choice/

How do we use and share your Personal Information?

If you are a resident of California, Virginia, Colorado, Connecticut, or Utah, please see our Privacy Notice for California Residents and Privacy Notice for Residents of VA/CO/CT/UT and Other States, below.

Hugo Boss Business Activities. We process and may disclose your Personal Information to both the HUGO BOSS Group (affiliates and subsidiaries) and to third party vendors, consultants and service providers to:

  • Respond to your questions, complaints, or reviews of our product or services;
  • Administer contests, promotions, surveys or issuing and managing gift cards;
  • Send you communications, including ads, electronic newsletters, or other marketing or promotional offers or opportunities tailored to you, including such communications relating to our products and services or those of affiliated and unaffiliated third parties;
  • Enable our advertisers to provide you with more personalized content, and track the effectiveness of certain advertising campaigns;
  • Help us run our business, including the performance of transactional or support services by us or third parties;
  • For product development and administration of our Sites or Other Channels;
  • Send and receive text messages;
  • Call you for transactional reasons (e.g., to confirm appointment times or if we have an issue with your order); to invite you to events or inform you of new products or sales, to the extent that you consented to receive such calls; or as otherwise permitted by applicable laws; and/or
  • For any other business purpose as permitted by applicable law or with your consent.

Authorized Service Providers. We use other companies and individuals to perform certain functions on our behalf. Those functions include payment card processors, fraud screening providers, shipping vendors, third party logistic providers, call-center or other support providers, e-commerce service providers, analytics providers, data hosting providers, and other companies that help us provide and improve our products and services. We may disclose your Personal Information to these companies and other individuals performing services in the United States or other locations where Hugo Boss or our service providers maintain a facilities or operations. For the purposes of fraud prevention, we may share your Personal Information with Forter, Inc., our third-party provider of fraud screening services, who may use such information in accordance with the Forter privacy policy accessible here: https://www.forter.com/service-privacy-policy/.

Businesses Sales. If we sell all or part of our business as part of a merger, acquisition, bankruptcy or other transaction in which a third party assumes control of all or part of our business, Personal Information may be transferred to the purchaser in connection with that transaction.

Compliance with Laws, Law Enforcement Request and to Protect Others. We may disclose Personal Information to comply with federal, state or local law; or to comply with a civil, criminal or regulatory investigation, inquiry, subpoena or summons by federal, state or local authorities. We may also disclose Personal Information to exercise or defend against legal claims or to cooperate with law enforcement agencies concerning conduct or activity that we or our service providers reasonably and in good faith believe may violate federal, state or local law.

Other Marketing or Permissible Uses. We may also share what we know about you with service providers for our own marketing purposes, or to offer you the products and services of affiliated third parties. To the extent legally permitted, we may combine your information with information collected from third party sources or information we already have. We may also use and disclose certain Personal Information to our corporate affiliates as well as others for any purpose allowed by law.

Non-Personal Information. We may also aggregate information that we gather about you (e.g., online sales, traffic patterns) and provide these statistics to others in aggregate form.

Links to other sites and integration with social media services

We may create links to other websites that we think may be of interest to you, such as providers of various products and services. We do not endorse any other websites, providers, or services by providing such links, and this Privacy Policy applies only to your use of our products and services. We are not responsible for the privacy policies of any websites and services we link to on our Sites and Other Channels, and you should read the privacy policies of each site you visit to determine what data that site may collect about you.

The Sites and Other Channels may also integrate with social media services. We do not control such services and are not liable for the manner in which they operate. While we may provide you with the ability to use such services in connection with our Sites and Other Channels, we are doing so merely as an accommodation and, like you, are relying upon those third-party services to operate properly and fairly.

What choices do you have about the collection, use, and sharing of your Personal Information?

If you are a resident of California, Virginia, Colorado, Connecticut, or Utah, please see our Privacy Notice for California Residents and Privacy Notice for Residents of VA/CO/CT/UT and Other States, below.

If you signed up to receive newsletters or consented to receive other marketing communications from us, you can opt-out any time by clicking the unsubscribe link at the bottom of the message. You can also log-in to your account to opt-out and update your marketing preferences at any time. Even after you opt-out or update your marketing preferences, please allow sufficient time to process your marketing preferences. It may take up to ten (10) days to process your e-mail marketing related requests, and up to thirty (30) days for all other marketing-related requests. And even after you’ve opt-out of receiving marketing communications from us, we may still contact you for transactional or informational purposes. These include, for example, customer service issues, returns or product-related inquiries, surveys or recalls, or any questions regarding a specific order.

What kinds of security measures do we take to safeguard your Personal Information?

The security and confidentiality of your Personal Information matters to us. That’s why we have technical, administrative, and physical controls in place that are designed to protect your Personal Information from unauthorized access, use, and disclosure. For example, we use Secure Sockets Layer (“SSL”) technology to help protect information transmitted over the Internet. Even so, despite our reasonable efforts, no security measure is ever perfect or impenetrable. You can check the security of your connection by looking at the URL line of your browser. When accessing a secure site, the first characters of the site address change from “http” to “https.” If your browser or firewall does not allow use of secure sites, you will not be able to make purchases on our Sites.

You are also responsible for keeping your Personal Information secure. We strongly recommend that you keep passwords unique from other identifiers such as user ID to help protect your privacy. In addition, you should make sure you only use trusted wireless connections in transmitting any Personal Information or other sensitive information.

How can you access, update, or block your Personal Information?

You can update the Personal Information you provided to us by logging-in to your profile, and making the appropriate changes or corrections yourself. You can also contact us directly any time at the address below to update your Personal Information. If you wish to de-activate your account, you may do so by contacting our customer support team at customerservice-us@hugoboss.com. Once you do so, your account will then be de- activated on a going-forward basis, although certain Personal Information may still be retained in accordance with our Record Retention Policy or to the extent necessary to comply with applicable law.

You can opt-out of receiving HUGO BOSS marketing e-mails at any time by emailing your unsubscribe request by logging into your MY HUGO BOSS account (if you have one) or e-mailing customerservice-us@hugoboss.com. You can also unsubscribe by using the unsubscribe link in each marketing communication you receive from us.

Minors and Children Under 13

Our Sites are not intended for minors. We do not knowingly collect any Personal Information from children under the age of 16 or knowingly track the use of our Sites by minors. If you believe we might have any Personal Information from or about a child under 16, please contact us at customerservice-us@hugoboss.com or call 1-800-484-6267.

Nevada Privacy Rights

If you are a resident of Nevada, you have the right to opt out of the sale of certain Personal Information that we have collected (or may collect) from you to data brokers or other third parties. To exercise the right to opt out, you (or your authorized representative) may submit a request to us by visiting the following Internet Web page: "Your Privacy Choices."

Financial Incentives

We may at times provide consumers with a financial incentive or loyalty program, such as offering different pricing or services, for providing their personal information such as an email address. These programs include the HUGO BOSS Experience, and you can read the terms of such program here. When we do so, we feel that the value of the different pricing or services you will receive through such programs exceeds the cost of providing such personal information. 

You will always have an option whether or not to partake in such incentive or loyalty programs, and to remove yourself from the program at any time by following the instructions provided in the applicable program terms. You may also withdraw from or opt out of our programs at any time by signing into your MY HUGO BOSS account and opting out or deleting your account.

How can you file a complaint, ask questions, or send us comments about this Privacy Policy?

If you have any questions, have a complaint, or wish to send us comments about this Privacy Policy, e-mail us at customerservice-us@hugoboss.com or call or write to us. We will investigate your complaint, and use reasonable efforts to respond to you as soon as possible.

Our postal address is:

Hugo Boss Fashions, Inc.

Attn.: Privacy Office

55 Water Street, 48th Floor

New York, NY 10041

How will you know if we amend this Privacy Policy?

We may amend this Privacy Policy at any time. If we make any material change to this Privacy Policy, we will prominently post the updated Privacy Policy and indicating at the top of the Privacy Policy when it was updated. If you disagree with our Privacy Policy changes, you may de-activate your account or exercise your right to opt out, if appropriate.

Privacy Notice for California Residents

Updated and Effective as of July 1, 2023

Please note, other sections of the Hugo Boss USA Privacy Policy apply to California residents, please read the Hugo Boss USA Privacy Policy above in its entirety. In particular, you are encouraged to read the following sections: What information does this Privacy Policy cover?, Fraud Prevention Policy, How do we collect Personal Information?, What are our policies to manage cookies, “Do Not Track” signals and interest-based advertising?, What kinds of security measures do we take to safeguard your Personal Information?, How can you access, update, or block your Personal Information?, Minors and Children Under 13, How can you file a complaint, ask questions, or send us comments about this Privacy Policy, and How will you know if we amend this Privacy Policy?. 

Personal Information,” as used in this Privacy Notice for California Residents, means information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked, directly or indirectly, with a particular consumer or household.

Our Personal Information Handling Practices in the Preceding 12 Months

The chart below describes, for the preceding 12 months, the categories of Personal Information we have collected from California residents, the categories of sources of the information, the business or commercial purposes for collection and, for each such category, the categories of third parties to whom we have disclosed such personal information:

  • Personal information we collected during the preceding 12 months
  • Identifiers (such as real name, alias, birth date, telephone and mobile phone numbers, postal addresses, unique personal identifiers, including, but not limited to online identifiers, Internet Protocol addresses, account names, signatures or other similar identifiers);
  • Personal information covered by the California Customer Records statute (Cal. Civ. Code § 1798.80(e)) (such as a name, physical characteristics or description, address, telephone number, credit card number, debit card number, or any other financial or medical information (some information included in this category may overlap with other categories));
  • Financial Transaction Information (such as credit card numbers, debit card numbers and other financial information, such as card type, expiration date, and tender type);
  • Commercial information (such as records of personal property, products or services purchased, obtained or considered or other purchasing or consuming histories or tendencies);
  • Non-precise/general location data (such as consumers’ physical location);
  • Internet or other electronic network activity information (such as consumers’ browsing histories, search histories, and information regarding consumers’ interactions with Internet websites, applications or advertisements);
  • Professional or employment-related information (such as employer, employment history, resumes and CVs, background checks, and other employment-related information);
    • Characteristics of protected classifications under California or federal law (such as gender, age and marital status); and
  • Inferences drawn from any of the above information to create a profile about a consumer reflecting the consumer’s preferences, characteristics, predispositions, behavior, and attitudes (such as homeowner status, presence of children or working women in the home, estimated household income, mail order purchaser status or length of residence)
  • Sources of information we have collected personal information from during the preceding 12 months:
    • You directly (including from your device or when you choose to provide personal information to us, such as through the Contact and Customer Service portions of our Sites and Other Channels);
    • Our service providers; and
    • Our data analytics providers.
  • Purposes for which we will use such personal information collected during the preceding 12 months
  • Performing internal operations necessary to run our business and provide excellent services to you;
  • Consulting order-related information and addressing customer service inquiries;
  • Managing customer information;
  • Providing order management information and fulfillment;
  • Performing analytics;
  • Enabling transactions and logistical fulfillment for e-commerce, orders from or shipments to stores, and payment processing;
  • Enabling and providing fraud prevention mechanisms;
  • Improving digital advertising and marketing; and
  • Facilitating integration of customer loyalty platform.

Categories of Personal Information Disclosed For a Business Purpose During the Preceding 12 Months

Categories of Third Parties to Whom We Disclosed Such Information During the Preceding 12 Months

The Specific Business or Commercial Purposes for Disclosing Such Personal Information

Identifiers

· Names and aliases

· Birth date

· Postal address

· Email address

· IP address

· Account ID

· Telephone and mobile phone numbers

· Signature

Advertising networks

Internet service providers

Data analytics providers

Payment card processors

Anti-fraud protection providers

Operating systems and platforms

Social media platforms

Auditing related to ad impressions

Helping to ensure security and integrity

Debugging to identify and repair errors

Short-term, transient use, including non-personalized advertising

Performing services on behalf of our business, including maintaining or servicing accounts, providing customer service, processing or fulfilling orders and transactions, verifying customer information, processing payments, providing financing, providing analytic services, providing storage, or providing similar services

Providing advertising and marketing services

Internal research for technological development and demonstration

Activities to verify or maintain the quality or safety of our services or devices

Personal information covered by the California Customer Records statute (Cal. Civ. Code § 1798.80(e))

· Names

· Postal address

· Email address

· Telephone and mobile phone numbers

· Payment card information

Advertising networks

Internet service providers

Data analytics providers

Payment card processors

Anti-fraud protection providers

Operating systems and platforms

Social media platforms

Auditing related to ad impressions

Helping to ensure security and integrity

Debugging to identify and repair errors

Short-term, transient use, including nonpersonalized advertising

Performing services on behalf of our business, including maintaining or servicing accounts, providing customer service, processing or fulfilling orders and transactions, verifying customer information, processing payments, providing financing, providing analytic services, providing storage, or providing similar services

Providing advertising and marketing services

Internal research for technological development and demonstration

Activities to verify or maintain the quality or safety of our services or devices

Financial transaction information

· Payment card number

· Authorization number or security code

· Billing address

· Card type (debit or credit card)

· Expiration date

· Tender Type

Data analytics providers

Payment card processors

Anti-fraud protection providers

Operating systems and platforms

Helping to ensure security and integrity

Debugging to identify and repair errors

Performing services on behalf of our business, including maintaining or servicing accounts, providing customer service, processing or fulfilling orders and transactions, verifying customer information, processing payments, providing financing, providing analytic services, providing storage, or providing similar services

Internal research for technological development and demonstration

Activities to verify or maintain the quality or safety of our services or devices

Commercial information

· Transaction history of consumers

Advertising networks

Internet service providers

Data analytics providers

Anti-fraud protection providers

Operating systems and platforms

Auditing related to ad impressions

Helping to ensure security and integrity

Debugging to identify and repair errors

Short-term, transient use, including nonpersonalized advertising

Performing services on behalf of our business, including maintaining or servicing accounts, providing customer service, processing or fulfilling orders and transactions, verifying customer information, processing payments, providing financing, providing analytic services, providing storage, or providing similar services

Providing advertising and marketing services

Internal research for technological development and demonstration

Activities to verify or maintain the quality or safety of our services or devices

Internet or other electronic network.

· Behavioral data

· Email engagement

· Browsing activity

· Device type

Advertising networks

Internet service providers

Data analytics providers

Payment card processors

Anti-fraud protection providers

Operating systems and platforms

Auditing related to ad impressions

Helping to ensure security and integrity

Debugging to identify and repair errors

Short-term, transient use, including nonpersonalized advertising

Performing services on behalf of our business, including maintaining or servicing accounts, providing customer service, processing or fulfilling orders and transactions, verifying customer information, processing payments, providing financing, providing analytic services, providing storage, or providing similar services

Providing advertising and marketing services

Internal research for technological development and demonstration

Activities to verify or maintain the quality or safety of our services or devices

Non-precise / general location information

Advertising networks

Internet service providers

Data analytics providers

Anti-fraud protection providers

Operating systems and platforms

Helping to ensure security and integrity

Debugging to identify and repair errors

Short-term, transient use, including nonpersonalized advertising

Performing services on behalf of our business, including maintaining or servicing accounts, providing customer service, processing or fulfilling orders and transactions, verifying customer information, processing payments, providing financing, providing analytic services, providing storage, or providing similar services

Providing advertising and marketing services

Internal research for technological development and demonstration

Activities to verify or maintain the quality or safety of our services or devices

Inferences drawn from any of the Personal Information collected.

· Preference selections by consumers

· Homeowner vs renter status

· Presence of children

· Estimated household income

· Mail order purchaser

· Length of residence

· Working woman present in household

Advertising networks

Data analytics providers

Operating systems and platforms

Performing services on behalf of our business, including maintaining or servicing accounts, providing customer service, processing or fulfilling orders and transactions, verifying customer information, processing payments, providing financing, providing analytic services, providing storage, or providing similar services

Providing advertising and marketing services

Internal research for technological development and demonstration

Characteristics of protected classifications under California or federal law.

· Gender based on salutation selected by consumer

· Age

· Marital Status

Advertising networks

Data analytics providers

Operating systems and platforms

Performing services on behalf of our business, including maintaining or servicing accounts, providing customer service, processing or fulfilling orders and transactions, verifying customer information, processing payments, providing financing, providing analytic services, providing storage, or providing similar services

Providing advertising and marketing services

Internal research for technological development and demonstration

The categories of personal information described above are retained and stored for as long as reasonably necessary to effectuate the business purposes described above, and otherwise as described in the section of the Privacy Policy titled "How can you access, update, or block your Personal Information?".

Sale or Sharing of Personal Information

In the preceding 12 months, we have sold or shared the following categories of Personal Information from the above chart to third parties:

  • Identifiers;
  • Personal information covered by the California Customer Records statute (Cal. Civ. Code § 1798.80(e));
  • Characteristics of protected classifications under California or federal law (specifically gender, age, and marital status);
  • Commercial information;
  • Location data;
  • Internet or other electronic network activity information; and
  • Inferences drawn from the above information.

As of the effective date shown above we have sold or shared your Personal Information with advertising and marketing vendors for the purpose of cross-context behavioral advertising. For additional information about our use of your Personal Information for cross-context behavioral advertising, please see the section of the Privacy Policy titled “What are our policies to manage cookies, “Do Not Track” signals and interest-based advertising?”

Rights to Your Information

  1. Right to Know

As a California consumer, you have the right to request that we disclose certain information to you about our collection, use, disclosure, or sale/sharing of your Personal Information over the past 12 months. Once we receive and confirm your verifiable consumer request (see Exercising California Residents’ Privacy Rights, below), and subject to certain limitations that we describe below, we will disclose such information. You have the right to request any or all of the following:

  • The categories of Personal Information we collected about you.
  • The categories of sources from which the Personal Information is collected.
  • Our business or commercial purpose for collecting, selling, or sharing that Personal Information.
  • The categories of third parties with whom we disclose that Personal Information.
  • The specific pieces of Personal Information we collected about you (see Right to Data Portability below).
  1. Right to Delete

You have the right to request that we delete any of your Personal Information that we collected from you and retained, subject to certain exceptions. Once we receive and confirm your verifiable consumer request (see Exercising California Residents’ Privacy Rights, below), we will delete (and direct our service providers to delete) your Personal Information from our records, unless an exception applies. However, we may retain Personal Information that has been de-identified or aggregated. Furthermore, we may deny your deletion request if retaining the information is necessary for us or our service provider(s) to perform certain actions set forth under the CCPA, such as detecting security incidents and protecting against fraudulent or illegal activity.

  1. Right to Data Portability

You have the right to request a copy of the Personal Information we have collected and maintained about you. The CCPA allows you to request your information from us up to twice during a 12-month period. We will provide our response in a readily usable (and usually electronic) format.

  1. Right to Correct

You have the right to request the correction of any Personal Information we maintain about you.

  1. Right to Opt Out of Selling or Sharing Your Personal Information

You have the right to opt out of the sale or sharing of your Personal Information, along with the right to opt in to the sale or sharing of such information. We do not sell or share the Personal Information of consumers we actually know are less than 16 years of age, unless we receive affirmative authorization (the "right to opt-in") from either the consumer who is less than 16 (but greater than 13) years of age, or the parent or guardian of a consumer less than 13 years of age. To our knowledge, we do not sell or share the Personal Information of minors under 16 years of age.

To exercise the right to opt out, you (or your authorized representative) may submit a request to us by visiting the following Internet Web page: "Your Privacy Choices." Alternatively, you may submit contact customer service at the phone number, provided below. We will also treat opt-out preference (aka, Global Privacy Control) browser signals as valid opt-out requests.

You may change your mind and opt back in to Personal Information sales at any time by signing up for a MY HUGO BOSS EXPERIENCE account, or indicating that you would like to receive information from us again (through a newsletter or other opt-in link).

  1. Right to Limit the Use of Your Sensitive Personal Information

Although you have the right to limit the use or disclosure of your sensitive Personal Information (“SPI”) if we are using your SPI beyond what is reasonable and proportionate to provide the requested goods or services, as of the date of this Privacy Policy, we do not collect SPI from you and have not done so within the past 12 months.

  1. Right to Non-Discrimination

We will not discriminate against you for exercising any of your CCPA rights, including but not limited to, by:

  • Denying you goods or services.
  • Charging you different prices or rates for goods or services, including through granting discounts or other benefits, or imposing penalties.
  • Providing you a different level or quality of goods or services.
  • Suggesting that you may receive a different price or rate for goods or services or a different level or quality of goods or services.

Exercising California Residents' Privacy Rights

As described above, as a California resident, you have certain additional rights with respect to your Personal Information, as described above in the section Rights to Your Information. 

You can submit your request to exercise these various rights (including the Right to Know and the Right to Request Deletion) in the following manner:

  1. Click here to submit your request
  2. Calling 1-800-484-6267

Process for Verifying a Consumer’s Request

We will verify any consumer’s request to exercise the Right to Know or the Right to Request Deletion using the following process:

Whenever feasible, we will match, or will engage a third-party identification verification service to match, the identifying information provided by you to the Personal Information that we maintain already on our systems. We will generally avoid requesting additional information for the purposes of verification. Only if we are unable to verify your identity or residency from the information already maintained by us will we request additional information from you. The additional Personal Information collected will only be used for the purposes of accurately verifying your identity in order to effectively allow you to exercise your rights under the CCPA and for the purposes of fraud prevention. Once we have satisfied these purposes, we will delete the additional Personal Information collected from you as soon as practically possible, except as required for compliance with our CCPA record-keeping requirements and applicable law.

At a minimum, we will ask you for your name and email address. However, we may require you to provide us with data points that ensure that we can verify your consumer request to a reasonable degree of certainty.

Inability to Verify a Request

If we are unable to verify your identity to a degree of certainty as required by the CCPA through any reasonable method, we will state in a written response to you that we are unable to verify it.

Authorized Agents

As a California resident, you may designate an authorized agent to act on your behalf to make a request under the CCPA by using the same channels for exercising your rights described above, such as requesting disclosure of any Personal Information sold or collected by Hugo Boss USA; or requesting deletion or correction of such Personal Information. If your authorized agent does not submit proof that they have been authorized by you to submit verified requests for disclosure, deletion, or correction, we reserve the right to deny such a request that we have received and will explain to your authorized agent why we have denied such request. If you should use an authorized agent to exercise your various rights under the CCPA, we may also require that you (i) provide your authorized agent with written permission to exercise your various rights and (ii) verify your own identity with us through the processes laid out in the section titled Exercising California Residents’ Privacy Rights, above and (iii) confirm with us directly that you have provided your authorized agent with permission to submit the request.

Responding to Your Request

We will make every effort to respond to your request within 45 days from when you contacted us. If you have a complex request, the CCPA allows us up to 90 days to respond. We will still contact you within 45 days from when you contacted us to let you know we need more time to respond.

California “Shine the Light”

In addition to the above rights, under California Civil Code Section 1798.83 (“Shine the Light”), California residents may have the right to request in writing from businesses with whom they have an established business relationship: (a) a list of the categories of personal information, as defined under Shine the Light, such as name, email address, and mailing address, and the type of services provided to the customer that a business has disclosed to third parties (including affiliates that are separate legal entities) during the immediately preceding calendar year for the third parties’ direct marketing purposes; and (b) the names and addresses of all such third parties. To request the above information, or to opt out of having personal information shared with any third party who may use such information for direct marketing purposes, please contact us at 1-800-484-6267, or at:

Hugo Boss Fashions, Inc.

Attn.: Shine the Light

55 Water Street, 48th Floor

New York, NY 10041

Concerns about our Privacy Policy and Practices

If you have questions or concerns about our privacy policy or practices, please contact 800-484-6267 or e-mail Informationrequests_US@hugoboss.com.

Privacy Notice for Residents of Virginia, Colorado, Connecticut, Utah and Other States

The Virginia Consumer Data Protection Act, the Colorado Privacy Act, the Connecticut Data Privacy Act, the Utah Consumer Privacy Act, and similar laws in other U.S. states ("State Privacy Laws") provide their consumers with specific rights regarding their personal data. To the extent that you are a resident of one of these states, this section describes your rights under the State Privacy Laws and explains how you may exercise these rights.

The categories of personal data we process, our purposes for processing your personal data, the categories of personal data that we share with third parties, and the categories of third parties with whom we share it are set forth generally in the terms of the Privacy Policy above, and more specifically in the sections titled “Our Personal Information Handling Practices in the Preceding 12 Months” and “Sale or Sharing of Personal Information” in the Privacy Notice for California Residents.

Rights to Your Information

In addition to the rights set forth in our Privacy Policy, the State Privacy Laws provide you with the following rights:

  • Right to know. You have the right to know whether we process your personal data and to access such personal data.
  • Right to data portability. You have the right to obtain a copy of your personal data that you previously provided to us in a portable and, to the extent technically feasible, readily usable format that allows you to transmit the data to another business without hindrance, where the processing is carried out by automated means. You may request such personal data up to twice annually, subject to certain exceptions.
  • Right to delete. You have the right to delete personal data that you have provided to us or, for residents of Virginia, Colorado, and Connecticut, that we have obtained about you from other sources. Please note that we may deny such request if the requested deletion falls under an exception as set forth in the State Privacy Laws. Additionally, if you request deletion of your personal data and we have obtained such information from a third-party source, we may retain such data by keeping a record of the deletion request and the minimum data necessary to ensure that your personal data remains deleted from our records and that such retained data is not used for any other purpose, or we may opt you out of the processing of such personal data for any purpose except for those allowed under the State Privacy Laws.
  • Right to opt out. You have the right to opt out of the processing of the personal data for purposes of: (i) targeted advertising; (ii) the sale of personal data; or (iii) profiling in furtherance of decisions that produce legal or similarly significant effects concerning you. As of the latest date of the Privacy Policy:
    • We do process personal data for the purposes of targeted advertising;
    • We do NOT sell your personal data for monetary or other valuable consideration (while we do share your personal data with third parties for purposes of targeted advertising, we do not believe this constitutes a "sale" under State Privacy Laws); and
    • We do NOT engage in profiling decisions based on your personal data that produce legal or similarly significant effects concerning you.
  • Right to correct. Residents of Virginia, Colorado, and Connecticut have the right to correct inaccuracies in your personal data, taking into account the nature of the personal data and the purposes for which we process it.
  • Right to nondiscrimination. You have the right not to receive discriminatory treatment by us for the exercise of your privacy rights. Unless permitted by the State Privacy Laws, we will not:
    • Deny you goods or services;
    • Charge you different prices or rates for goods or services, including through granting discounts or other benefits, or imposing penalties;
    • Provide you a different level or quality of goods or services; or
    • Suggest that you may receive a different price or rate for goods or services or a different level or quality of goods or services.

How to Exercise Your Rights; Verifying Your Identity

To exercise any of your privacy rights, or if you have any questions about your privacy rights, you may contact us by:

  • Calling 1-800-484-6267

After submitting a request, we will take steps to verify your identity in order for us to properly respond and/or confirm that your request is not fraudulent. We may contact you for additional information as reasonably necessary to authenticate your request, but if we are ultimately unable to authenticate your request using reasonably commercial efforts, then we may not be able to comply with it.

Only you or your authorized agent may make a verifiable request related to your personal data. If you are making a request as the parent or legal guardian of a known child regarding the processing of that child's personal data, we may ask you to submit reliable proof of your identity.

Response Time; Your Right to Appeal

We will make every effort to respond to your request within 45 days from when you contacted us. If you have a complex request, the State Privacy Laws allow us up to 90 days to respond. We will contact you within 45 days from when you contacted us to inform you of the need for additional time and the reason for such extension. We may charge you a reasonable fee to cover administrative costs if your requests are manifestly unfounded, excessive, or repetitive.

If we decline to take action on a request that you have submitted, we will inform you of our reasons for doing so, and provide instructions for how to appeal the decision. Residents of Virginia, Colorado, and Connecticut will have the right to appeal within a reasonable period of time after you have received our decision. Within 60 days (45 days for residents of Colorado) of our receipt of your appeal, we will inform you in writing of any action taken or not taken in response to the appeal, including a written explanation of the reasons for the decisions. If we deny your appeal, we will provide you with a method for contacting your state attorney general's office to submit a complaint.