Skip to main content
Enzo Custom
Book a private appointment

United States Privacy Policy

Effective October 1, 2026 · Last updated September 30, 2026

This Privacy Policy explains how Enzo Custom Florida Inc., a Florida corporation doing business as Enzo Custom (“Enzo Custom Florida”), and its commonly controlled affiliates (together, the “Enzo Group,” “Enzo,” “Enzo Custom,” “we,” “us,” or “our”) collect, use, disclose, retain, and protect personal information about clients, prospective clients, website visitors, and other people who interact with us. Enzo Custom Florida operates shared websites, customer-facing applications and portals, vendor relationships, and customer-information systems and is the primary entity responsible for the common processing described here.

At a glance

  • We do not sell personal information for money and do not operate as a data broker.

  • Some advertising and analytics technologies may be considered a "sale," "sharing," or use for targeted advertising under state privacy laws. You can opt out through Your Privacy Choices, and we process qualifying universal opt-out signals, including Global Privacy Control.

  • We do not sell, rent, share, or transfer mobile numbers or SMS consent records to third parties or affiliates for their own marketing or promotional purposes.

  • We use tailoring measurements and fit information to make and service garments. We do not use them to identify you biometrically or infer a diagnosis, health condition, disability, or other sensitive trait.

  • We do not use facial recognition, biometric identifiers, precise location tracking, or personal data to set individualized prices.

  • A fitting or service photograph is not permission to publish it. We use an additional release or other legally valid authorization before using an identifiable client image, testimonial, or likeness in public marketing.

  • We offer the core privacy rights described below to U.S. residents, subject to identity verification, applicable exceptions, and law.

1 Scope and who we are

This Policy applies to personal information handled through Enzo websites (including enzocustom.com and sanpari.com), customer accounts, portals and applications; Enzo Custom and Enzo Sartori showrooms; Sanpari tailoring and alteration services; appointments in showrooms or at a customer’s home, workplace, hotel, or another agreed location; fittings, tailoring, purchases, payments, shipping, support, referrals, gift cards, reviews, social media, email, text, telephone, and other interactions that link to this Policy (collectively, the “Services”). Enzo’s physical showrooms are in the United States, but customers may access the Services, purchase from us, or request delivery from other countries.

This Policy does not apply to:

  • workforce members and job applicants, whose information is addressed in our separate United States Workforce and Applicant Privacy Notice;

  • information that applicable law excludes from its definition of personal information or personal data; or

  • a third party's independent handling of information under its own notice.

If a service-specific notice conflicts with this Policy, the more specific notice governs that service to the extent of the conflict. Our Cookie and Tracking Technologies Policy, California Privacy Notice, Consumer Health Data Privacy Notice, SMS Terms, and Artificial Intelligence Transparency and Use Policy supplement this Policy.

Enzo Custom Florida is the primary controller or business for shared customer systems and common processing. The local Enzo Group entity identified on an order or receipt may also determine how information is used to complete and support that transaction and meet its legal, accounting, and operational duties. The Enzo Group includes the commonly controlled entities that operate Enzo Custom showrooms; Enzo Sartori; and Sanpari, our tailoring and alterations company (sanpari.com), which also offers alterations for garments that were not purchased from Enzo. The Enzo Group entities are listed in Appendix A. They use shared customer systems with access limited by role and service need. A functional-accommodation note is restricted to the clothier and tailor serving you and program administrators who need it for the requested service. Other personnel cannot access it. If that restriction cannot be maintained in the shared system, we arrange the accommodation through a minimal restricted workflow without storing the health-revealing note in the shared CRM. You may ask us which entity is responsible for a particular transaction through the contact methods in Section 18.

Information you provide about other people. If you give us information about someone else—for example, a wedding-party member, a gift recipient, or a shipping recipient—you confirm that you are permitted to share it. We use that information only for the purpose for which you provided it and make this Policy available when we first communicate with that person directly.

2 Personal information we collect and how long we ordinarily keep it

We collect only information that is reasonably necessary and proportionate for the disclosed purposes. What we collect depends on how you interact with us. The following table describes the categories we have collected or reasonably expect to collect, representative examples, principal purposes, and ordinary retention criteria.

Category Examples Principal purposes Ordinary retention criterion
Identifiers and contact information Name, email, mobile number, postal and billing address, client, appointment, order, referral, or account identifier, and account username if offered Appointments, orders, delivery, support, identity matching, account administration, consent and preference management Active relationship, then delete or irreversibly deidentify after 3 years without substantive customer activity. See the detailed rule below. Minimum transaction fields generally 7 years in a restricted archive; inquiry-only records generally 3 years.
Appointments and commercial information Consultations, appointments, quotes, purchases, garment and fabric selections, monograms, order status, alterations, returns, refunds, credits, gift-card or referral activity, shipping details, and service history Provide, fulfill, personalize, and service orders; prevent fraud; accounting; analytics; improve offerings Minimum order, payment, refund, alteration, and accounting records generally 7 years after final fulfillment, adjustment, refund, or resolution. A later unrelated interaction does not restart the archive period.
Measurements, fit, and style information Body and garment measurements, posture and nonmedical fit observations, alteration history, size, style, color, fabric, and wardrobe preferences Design, produce, alter, reorder, and improve garments; provide Fit Guarantee and consistent future service Active relationship, then delete or irreversibly deidentify after 3 years without substantive customer activity. See the detailed rule below. Minimum transaction fields generally 7 years in a restricted archive; inquiry-only records generally 3 years.
Payment and transaction information Payment token, payment status, last four digits, billing details, refunds, chargebacks, and fraud indicators. Full card data is handled by payment processors rather than stored by Enzo Custom Authorize and reconcile payments, issue refunds, prevent fraud, comply with tax and accounting duties Transaction and accounting records generally 7 years; processor retention is governed by its policy and law
Event, wedding, and group information Occasion type, event or wear-by date, travel date, event city, wedding role, party association, party size, and timing needs Plan production, fittings, deadlines, group coordination, and relevant service communications Part of the applicable inquiry or order record and kept under that record's criterion
Communications, signatures, feedback, and reviews Emails, texts, chats, social direct messages, contact-form content, electronic signatures, customer-service requests, complaints, resolutions, surveys, optional private scores, testimonials, and review-link activity Respond, authenticate transactions, support clients, assure quality, resolve disputes, administer feedback and review journeys Routine support communications generally 3 years after the last direct service contact; specific transaction or dispute records up to 7 years after resolution where justified, limited to relevant records.
Photos, recordings, and other sensory information Fitting or garment photos, content you submit, calls recorded or transcribed only after clear notice and affirmative consent, video-support content, and video-only security footage from showroom cameras (see Section 8) Fit review, alterations, service documentation and disclosed quality review by authorized people; security and client-requested support; call transcription or AI summaries only when enabled and disclosed; marketing only under separate authority Fitting photos: only while needed, ordinarily no more than 12 months from each capture; later interactions never restart. Section 8 explains permission, narrow holds, deletion, and separate publicity releases. Security footage and calls follow their documented schedules.
Internet, device, and interaction information IP address, browser, operating system, device type, cookie and advertising identifiers, pages viewed, clicks, referring URL, approximate timestamps, site-search activity, email opens or clicks, session and consent signals, security logs, and interactions with our ads Operate and secure the Services; remember choices; troubleshoot; analytics; attribution; fraud prevention; and, subject to choice, advertising No new session replay or heatmap collection. Any historical raw recordings generally no more than 30 days; security logs and other analytics generally up to 24 months; historical aggregated interaction analytics up to 24 months. Cookie duration appears in the preference center.
Approximate location City, state, or region inferred from IP address; selected or nearest showroom. We do not intentionally collect precise GPS location through ordinary Services Localize showroom information and availability, route inquiries, prevent fraud, analyze use, and advertise where permitted Follows the associated device, appointment, or order record
Preferences and inferences Likely garment interests, preferred showroom or clothier, communication choices, event timing, and service or product recommendations derived from other information Personalize service, route inquiries, plan follow-up, improve offerings, and market relevant products where permitted Delete or irreversibly deidentify after 3 years without a purchase, appointment, or direct service contact. Passive marketing opens and tracking do not restart the period. Minimal consent and suppression evidence follows its separate schedule.
Consent, privacy, and security records Email and SMS choices, notice or disclosure version, source, timestamp, opt-outs, Global Privacy Control signals, privacy requests, verification records, suppression entries, login and access logs, and fraud or security events Prove and honor choices, prevent unauthorized access, comply with law, investigate misuse, and defend claims Consent and message evidence generally 5 years after the last relevant message or withdrawal; minimal suppression records generally 10 years and longer only while reasonably necessary to honor a continuing choice, a specific law, legal hold, claim, or enforcement matter; privacy-request records generally 2 years; security records according to risk and legal need
Social, referral, and user-submitted content Social handles, tags, comments, public posts involving us, content you send or authorize, referral link or code, attribution, referred-party interaction, and program credits Respond to social interactions, display authorized content, administer referrals, attribute qualifying orders, prevent abuse, and apply benefits Social or user-submitted content under the communication or authorization period; referral and credit records generally 7 years after final activity
Professional or business-context information Company, occupation, business contact details, dress requirements, or wardrobe context that you voluntarily provide Tailor service and recommendations and communicate about a business or group engagement Under the applicable inquiry, client, or order criterion
Guest-network information, if offered Device identifiers, connection times, IP address, and security logs for showroom guest Wi-Fi Provide and secure network access and investigate misuse Generally up to 24 months unless needed for a security investigation
Functional accommodation information The practical adjustment you request for a showroom visit, communication, fitting, or garment service. We ask you not to provide a diagnosis or medical history Arrange and deliver the requested accommodation Only as long as reasonably needed to provide and document the accommodation, unless a longer period is required to resolve a claim or comply with law

For client profiles and measurements, substantive activity means a purchase, appointment, or direct service contact. Passive email opens, advertising activity, and tracking do not restart the 3-year inactive-profile period. A longer retention period requires a documented legal requirement or specific active claim or dispute, access restricted to those handling that matter, and periodic review. We keep only the information relevant to that basis and delete or irreversibly deidentify it when the basis ends. We do not retain a full client profile or fitting-photo archive merely because minimum order or accounting records must be kept. Lawful deletion requests and applicable exceptions still apply. When the applicable period ends, we delete, irreversibly deidentify, or securely dispose of the information. Backup deletion follows a documented cycle and applicable legal deadlines.

3 Sources of personal information

We collect personal information from:

  • You directly, including through appointments, showroom visits, fittings, purchases, account or request forms, communications, surveys, consent screens, reviews, events, and referral participation.

  • Our personnel and systems, when they create or update appointment, measurement, fit, order, alteration, delivery, service, preference, consent, or security records.

  • Your devices and interactions, through cookies, pixels, tags, local storage, server logs, analytics, call-tracking technologies, email pixels, and similar technologies, subject to applicable choices.

  • Service providers and business partners, including providers supporting scheduling, payment, fraud prevention, communications, CRM, production, delivery, storage, customer service, security, analytics, and advertising.

  • Social networks, advertising platforms, and public sources, when you interact with our content, mention us publicly, authorize a connection, or when a permitted partner provides campaign or attribution information.

  • People acting at your direction, such as a wedding or event organizer, shipping recipient, authorized agent, or person assisting with an appointment.

  • Referral sources, solely to attribute an introduction. An introducing client may share a personal referral link, but the referred person must submit their own information before we contact them through the referral journey.

4 How we use personal information

We use personal information as reasonably necessary and proportionate to:

1. provide, personalize, design, produce, fit, alter, deliver, and support garments and related services;

2. schedule and manage appointments, deadlines, events, orders, payments, credits, gift cards, deliveries, refunds, and Fit Guarantee services;

3. authenticate clients and transactions, maintain fit and preference records, prevent duplicate or fraudulent records, and preserve service continuity;

4. communicate about appointments, orders, fittings, alterations, pickup, delivery, privacy, safety, and support;

5. send marketing only under the consent, permission, or opt-out framework applicable to the channel and jurisdiction;

6. operate, debug, secure, maintain, and improve our Services, showrooms, customer experience, products, communications, and business operations;

7. conduct analytics, attribution, audience measurement, campaign reporting, and targeted advertising where permitted and subject to applicable choices;

8. solicit neutral feedback and administer reviews, referrals, group orders, surveys, and promotions;

9. detect, prevent, and investigate fraud, abuse, security incidents, illegal activity, and violations of our terms;

10. meet legal, regulatory, tax, accounting, insurance, accessibility, and recordkeeping duties; respond to lawful process; protect people, property, and rights; and establish or defend legal claims; and

11. create aggregated or deidentified information for lawful analysis and improvement. We maintain deidentified information in deidentified form, publicly commit not to reidentify it except to test whether deidentification processes comply with law, and contractually require the same of recipients where required.

We will not collect additional categories of personal information or use collected information for a materially incompatible purpose without giving legally required notice and obtaining consent where required.

5 How we disclose personal information

We disclose personal information only for the purposes described in this Policy and subject to contracts or other safeguards where applicable. Recipients may include:

  • Enzo Group affiliates, including the commonly controlled entities operating Enzo Custom showrooms, Enzo Sartori, and Sanpari, which use shared systems and information for appointments, orders, tailoring, customer service, accounting, security, legal compliance, and permitted marketing consistent with customer choices.

  • Service providers and contractors supporting website hosting, scheduling, CRM, customer accounts, email and SMS delivery, customer support, payment processing, fraud prevention, production, tailoring, shipping, IT, cybersecurity, analytics, document storage, records management, and professional services.

  • Advertising, social-media, and analytics partners that measure campaigns, operate tags, create audiences, or deliver interest-based advertising, subject to Your Privacy Choices and applicable law.

  • Professional advisers, such as lawyers, accountants, auditors, insurers, and consultants, when the information is relevant to their engagement.

  • Corporate transaction parties, in connection with a financing, audit, reorganization, merger, sale, acquisition, insolvency, or transfer of all or part of our business, subject to customary confidentiality and legal safeguards.

  • Legal and safety recipients, including courts, regulators, law enforcement, insurers, counterparties, or others when we reasonably believe disclosure is required or appropriate to comply with law, protect people or property, prevent fraud, investigate misconduct, or establish or defend claims.

  • Recipients you direct, such as the organizer of a wedding, corporate, or other group order you join (who may receive your order status, fitting schedule, and whether payment is complete, but never your payment details), a shipping recipient, authorized representative, social network, review platform, or other person or service you intentionally choose.

Service providers and contractors may process information only to perform contracted services or as otherwise permitted by law, and our contracts require them to keep it confidential, secure it, delete or return it when the engagement ends, and help us respond to privacy requests, as applicable law requires. We do not authorize them to use SMS opt-in data for their own marketing.

6 Sale, sharing, targeted advertising, and universal opt-out signals

We do not sell personal information for money and do not operate as a data broker. Some state laws define sell, share, or targeted advertising broadly enough to cover disclosures of online identifiers, internet activity, conversion events, commercial interests, or hashed contact information to advertising and analytics partners in exchange for advertising, measurement, or other value. We treat those practices as opt-out activities where applicable.

Information involved Potential practice Recipient categories Your choice
Cookie or advertising identifiers, IP address, device information, and internet activity Advertising, audience measurement, attribution, or analytics tags may constitute sale, sharing, or targeted advertising Advertising networks, social-media platforms, and analytics providers Opt out through Your Privacy Choices or a recognized universal opt-out mechanism
Limited commercial interests, product interactions, conversion events, and related inferences Audience creation, campaign optimization, retargeting, or measurement where permitted Advertising networks and social-media platforms Opt out through Your Privacy Choices
Email address used in a matched-audience program Customer-list uploads, enhanced conversions using customer data, and matched-audience uploads are disabled in the current program. Any future use requires a new review of consent, opt-outs, minimization, contracts, and configuration. Advertising platforms acting under their applicable terms Opt out of sale, sharing, and targeted advertising and unsubscribe from marketing email; we stop future audience uploads where required
Mobile number and SMS consent record Not sold, rented, shared, or transferred to third parties or affiliates for their own marketing or promotional purposes Messaging providers, carriers, and aggregators only as needed to operate the selected program Revoke by replying STOP or using any reasonable revocation method; see the SMS Terms
Measurements, fit notes, service photos, full payment-card data, functional accommodation information, and private feedback Not used or disclosed for cross-context behavioral advertising or targeted advertising Service providers only as needed for the stated purpose Access, deletion, correction, and other privacy rights may apply

Advertising, analytics, attribution, and engagement providers and their controls are described in our Cookie and Tracking Technologies Policy and preference center. Tools disabled under the current program remain disabled regardless of a general analytics choice. Customer-data uploads and enhanced conversions are not activated until their separate review is complete.

Use Your Privacy Choices, available in the website footer, to opt out of sale, sharing, and targeted advertising. You do not need to create an account or verify your identity for an opt-out request. We also process qualifying Global Privacy Control and other legally recognized universal opt-out signals. A signal applies to the browser or device that sends it and, when we can reasonably associate it with a logged-in account or other identifier, to related information as required by law. Clearing cookies or changing browsers or devices may require you to renew a browser-based choice.

We do not respond to a browser's legacy "Do Not Track" setting because no uniform industry standard governs it. We honor qualifying Global Privacy Control and other legally recognized universal opt-out mechanisms nationwide as described in our Cookie Policy and Your Privacy Choices.

7 Cookies, analytics, advertising, and session-interaction tools

We use strictly necessary technologies to operate and secure the Services. Our policy keeps nonessential functional, analytics, advertising, call-attribution, and similar transmissions off until you affirmatively enable the relevant category. The cookie banner and preference center provide those controls. Session replay and heatmaps remain disabled under the current program.

Under our nationwide policy, nonessential technologies do not activate until your affirmative choice. Rejecting or withdrawing consent is as easy as accepting it. Strictly necessary technologies cannot be disabled through the preference center because the requested Services may not function without them. Qualifying opt-out signals and applicable legal opt-outs are honored.

Session replay and heatmap tools are disabled across our websites, applications, booking, account, payment, and support workflows. We do not collect new session recordings or heatmaps under the current program. Any future activation requires a separate review, an updated notice, a distinct affirmative opt-in before any recording or transmission, sensitive-workflow exclusions, and tested retention and deletion controls. Enabling ordinary analytics does not enable session replay.

8 Information that receives special handling

Measurements, fit information, and accommodation requests

We collect ordinary tailoring and garment-fit measurements to create and service clothing. We do not process measurements, service photographs, or fit observations to recognize or authenticate a person, create a biometric identifier, or infer a diagnosis, medical condition, disability, race, ethnicity, religion, sexual orientation, or other sensitive trait.

If you need an accessibility or fit accommodation, tell us the practical adjustment you need rather than a diagnosis or medical history. We record only the functional accommodation reasonably needed to provide the requested service. If we receive unnecessary health details, we restrict access to or delete them when reasonably practicable, unless retention is required by law or needed to address the request or a claim.

If we later introduce technology that uses measurements, images, voice, or other physical or biological characteristics to identify a person uniquely or infer health or other sensitive traits, we will conduct the required assessment and provide any separate biometric or consumer-health notice and obtain consent before that processing begins.

Consumer health data

Our Services are not health-care services, and we do not ask for diagnoses, treatment information, medications, medical history, reproductive or sexual health information, genetic information, or precise location associated with health care. We do not infer health status from measurements, fit observations, photographs, device activity, or accommodation requests.

A functional accessibility or fit request may nevertheless reveal health or disability information and may be treated as consumer health data under some state laws. We use that information only to provide the product, service, or accommodation requested, limit the record to the practical adjustment, permit personnel and processors to use it only for that purpose, and do not sell it or use it for advertising or profiling. Please provide only the practical adjustment needed and not a diagnosis or unrelated health detail. Read our Consumer Health Data Privacy Notice. Applicable consumer-health rights may be exercised through enzocustom.com/privacy-request, [email protected], or 888-622-3696.

Photos, recordings, and publicity

Fitting photos are optional and require separate affirmative permission for the stated service purpose. We delete them when no longer reasonably needed and ordinarily no later than 12 months after each photo was captured. A later appointment, order, message, or other interaction does not restart that period. We may preserve only relevant photos under a documented legal requirement or active-dispute hold, with restricted access and periodic review; we delete them when that basis ends. Valid deletion requests are handled within the applicable legal deadline, subject to applicable exceptions. Publicity images obtained under a separate valid release follow that release and its stated media term. A service photo is not permission to publish it. We use a separate written release or other legally valid authorization before public marketing. We provide clear notice and obtain affirmative consent before recording or transcribing a call or creating an AI call summary, and we post notice where security cameras operate. We do not use AI to process customer fitting photos.

Showroom video security

Our showrooms use video cameras in sales and entry areas for safety, security, and loss prevention. Cameras record video only; audio recording is disabled. No cameras are placed in fitting rooms, changing rooms, restrooms, or other areas intended for undressing. Footage is stored securely on local equipment and/or with an approved camera-storage provider and is ordinarily overwritten or deleted after a short security cycle. We retain relevant footage longer only for an incident, legal matter, or lawful request, with restricted access and periodic review. We do not use facial recognition, face matching, or other biometric identification. We do not share footage with advertising or analytics providers. Signs at showroom entrances describe the monitoring.

Chat and customer support

If you choose to chat with us, your messages and related contact and interaction details are transmitted to Enzo and the chat provider identified in the notice before you start. Enzo and the provider may store those records to answer your request, provide support, and maintain service records under the communications retention schedule in Section 2.

The notice identifies the provider and explains the material chat processing before you affirmatively start. We do not capture chat messages or keystrokes before that step. We do not send chat text or other sensitive text-field contents to advertising or analytics tools, and session replay remains disabled. Please do not include payment-card details, passwords, diagnoses, or unnecessary sensitive information in chat.

Payment and account information

Payment providers process full card details. We ordinarily receive a token, transaction status, last four digits, and related billing or fraud information. Do not send full payment-card details, passwords, government identification numbers, or other highly sensitive information through email, text, chat, or open-text forms.

Artificial intelligence and profiling

We may use automated or AI-assisted tools for routing inquiries, analytics, fraud and security detection, drafting support, customer-service assistance, quality review, and product or communication recommendations. We do not currently offer a customer-facing AI fitting, biometric identification, or automated decision service.

We do not collect, use, or sell personal information for the purpose of training large language models. We do not authorize providers to use personal information we supply to train large language models.

We do not use, or permit vendors to use, customer fitting photographs, identifiable measurements, private client communications, or health or functional-accommodation information to train, fine-tune, or evaluate any AI model. This restriction applies to internal and vendor models, including general-purpose and shared models. There is no consent-based exception in the current program. We do not process or analyze customer fitting photographs with AI or create biometric identifiers from them. Limited review by authorized people for the disclosed service or quality purpose is distinct from AI model training. Licensed professional-model imagery used in marketing is governed by its separate rights and permissions. Payment-card data and account credentials must not be entered into AI tools. Approved providers may process only other limited information needed for an authorized AI-assisted function, under instructions and safeguards.

We do not use solely automated processing to make decisions that produce legal or similarly significant effects about clients. Personnel remain responsible for material service decisions. If a qualifying automated decisionmaking or profiling practice is introduced, we will provide the required pre-use notice, rights, and assessments before use. See our Artificial Intelligence Transparency and Use Policy.

9 Communications reviews and referrals

Service and marketing communications

We may send communications needed to manage an appointment, order, fitting, alteration, pickup, delivery, privacy request, security matter, or customer-service issue. Marketing email and SMS choices are managed separately from necessary service communications. You may unsubscribe from marketing email through the link in the message. You may revoke SMS consent as explained in our SMS Terms. We may keep a minimal suppression record so we can honor an opt-out.

Feedback and public reviews

Access to a public-review page is not conditioned on a salesperson's rating, predicted sentiment, or the score a client gives us. A client may optionally provide private feedback. We use private feedback for service improvement; it does not determine whether a client can access a public review site or receive a referral invitation.

Referral program

An introducing client receives a personal link to share privately. We do not text or email a friend merely because an introducing client names them. The friend must submit their own information and choices. We use participant, attribution, order, and credit information to administer eligibility, prevent abuse, apply the current $100 friend benefit and $100 introducing-client benefit to qualifying purchases, and maintain accounting records. The program's terms govern eligibility, the $400 qualifying-garment threshold, credit use, and other restrictions.

Participation is voluntary and is not conditioned on consent to sell or share personal information. California residents should review the Notice of Financial Incentive in our California Privacy Notice before participating. If we introduce another loyalty, VIP, or incentive program that uses personal information, we will provide the disclosures that California, Colorado, or other applicable law requires before you join.

10 Retention and deletion

The criteria in Section 2 are our ordinary retention schedule. The 12-month fitting-photo limit runs from each capture, and the 3-year inactive-profile limit runs from substantive customer activity as defined there. Longer preservation is limited to the documented grounds and review requirements in Section 2.

Deletion from active systems is followed by deletion from backups on a documented cycle within any applicable legal deadline. Restored backup data remains subject to the same deletion and suppression controls. We retain only minimal records needed to honor an opt-out or deletion, document compliance, or address a specific applicable legal exception; we may keep irreversibly deidentified information.

11 Security and incident response

We use administrative, technical, and physical safeguards designed for the nature of the information and our operations. These may include role-based access, authentication, encryption of information in transit and, where appropriate, at rest, payment-tokenization, vendor review, logging, staff training, backup and recovery procedures, and incident response. Payment-card processing is delegated to providers designed for that purpose. We maintain a written incident response plan.

No system is completely secure. You are responsible for protecting any account credentials and for telling us if you believe your account, phone number, or communications have been compromised. If a security incident triggers a legal notice duty, we will provide notice in the manner and time required by applicable law.

12 Your US privacy rights

Subject to identity verification, exceptions, and applicable law, U.S. residents may ask us to:

  • confirm whether we process their personal information and provide access to categories or specific pieces of information;

  • explain the categories of information, sources, purposes, and recipients, including a list of specific third parties where applicable law grants that right;

  • correct inaccurate personal information;

  • delete personal information, including covered information obtained from a third party where applicable law grants that right;

  • provide a portable copy of covered information;

  • opt out of sale, California sharing, targeted advertising, or qualifying profiling that produces legal or similarly significant effects;

  • limit the use or disclosure of California sensitive personal information, or withdraw consent to sensitive-data processing, where applicable;

  • provide information about qualifying profiling and allow a challenge or human review where required;

  • appeal a denied request and receive information about the appropriate state regulator where required;

  • use an authorized agent where permitted; and

  • receive equal service and pricing without unlawful discrimination for exercising privacy rights.

We voluntarily use this as a nationwide baseline even where a state's law does not require every right; offering a right voluntarily does not mean that a particular law applies to us. These rights are not absolute. For example, we may keep information needed to complete a transaction, provide a requested product, honor a warranty or fit obligation, detect fraud or security incidents, comply with law, exercise another person's rights, or establish or defend legal claims. We explain a denial when required.

13 How to exercise rights appeal and use an authorized agent

Submit a request through enzocustom.com/privacy-request, email [email protected], or call 888-622-3696. You do not need to create an account. Tell us which right you wish to exercise and provide enough information to locate the relevant records.

To appeal a denied request, use the same channels, state "Privacy Appeal," and identify the decision you are appealing. We ordinarily decide appeals within 45 days. When applicable law provides a different deadline, we use that deadline. If an appeal is denied and applicable law grants a regulator-complaint right, our response will identify the appropriate attorney general or privacy regulator.

We acknowledge verifiable requests within 10 business days and ordinarily respond within 45 calendar days. If law permits an extension and one is reasonably necessary, we will notify you within the original response period, explain why, and provide the expected completion date. Sale, sharing, and targeted-advertising opt-outs are processed as soon as feasible and no later than 15 business days after we receive them. After you opt out, we will not ask you to opt back in for at least 12 months unless you start that conversation.

We verify requests in a way proportionate to their sensitivity, using information already associated with an account, appointment, order, or communication when possible. We do not ask for a Social Security number. We may deny a request if we cannot reasonably verify identity or authority. Opt-out requests and universal opt-out signals do not require identity verification.

An authorized agent may submit a request where permitted. We may require proof of the agent's authority and may ask you to verify your identity or confirm the request directly, unless the agent has legally sufficient power of attorney. We do not charge a fee unless a request is manifestly unfounded, excessive, repetitive, or otherwise fee-eligible under law.

We provide this Policy and our request methods in a format designed to be accessible. Contact us if you need an accessible copy or a copy in another language in which we provide material privacy notices.

14 Additional state disclosures

California

California residents should read our California Privacy Notice, which describes California categories, practices during the preceding 12 months, rights, notices at collection, opt-out instructions, and our referral-program notice.

Nevada

Nevada residents may submit a verified request through the methods in Section 13 to opt out of a covered sale. We do not currently sell covered information for monetary consideration as Nevada law defines that term.

Pricing, precise geolocation, and facial recognition

We do not use personal data or an automated tool to set an individualized price or offer for a particular person (sometimes called surveillance or algorithmic pricing), do not use facial-recognition technology on our premises or to identify showroom visitors, and do not sell or otherwise make available precise geolocation data. Before introducing any such practice, we will complete the required legal and risk review and provide any point-of-sale disclosure, premises signage, linked policy, consent, or other control required by Connecticut, New York, or other applicable law.

Oregon, Minnesota, and states with expanded rights

Where applicable, you may request a list of specific third parties to which we disclosed personal information. Where law grants rights concerning qualifying profiling, you may request information about the profiling, question or challenge its result, state your view, and request human review. We do not currently use solely automated profiling to make decisions producing legal or similarly significant effects about clients. Minnesota residents may also use the footer link labeled Your Opt-Out Rights, which leads to the same privacy-choice controls.

Rhode Island and similar website notice requirements

The advertising, social-media, and analytics third parties that may receive online information under broad state definitions are described in Section 6 and identified by name in Section 4 of our Cookie and Tracking Technologies Policy, which we update when providers change. We do not sell personal information for money.

Sensitive data

We do not sell sensitive personal information or sensitive data, and we do not ask for consent to sell it. We process sensitive data only when strictly necessary to provide or maintain a specific product, service, or accommodation you requested; to process a payment or authenticate access through a provider; to protect security and prevent fraud; or to meet a legal duty—or, in states that permit consent-based processing, with your consent. We do not use sensitive data to infer characteristics about you. If you gave consent to sensitive-data processing, you may withdraw it using the methods in Section 13; we stop consent-based processing as soon as practicable and within 15 days where required.

15 Children and teens

The Services are not directed to children under 13, and a child under 13 may not independently create an online account or enroll in direct marketing. We do not knowingly collect personal information online from a child under 13 without verifiable parental consent where the law requires it. People ages 13 through 17 may receive tailoring services, hold an account with a parent’s or guardian’s permission, and enroll in communications subject to applicable law; orders for a minor are placed and paid for by a parent, guardian, or other adult. When we know that a user is 13 through 17, we process that person’s information only as necessary to provide the requested product or service, operate and secure the Services, and meet legal duties, or with the informed consent that applicable law requires. Where law requires parent or guardian authorization for a particular practice, we obtain it or do not conduct that practice.

We do not sell, share, use for targeted advertising, or use for qualifying profiling the personal information of anyone we know, or should reasonably know, is under 18. If you believe a minor provided personal information contrary to this section, contact us. We will investigate and delete or restrict the information as required. A parent or guardian may submit a request through the methods in Section 13.

16 International customers and cross border processing

Enzo is based in the United States, and our Services are designed for customers in the United States. We ship internationally only when a customer asks us to. Personal information is processed in the United States. Authorized Enzo personnel and providers outside the United States, including in the Philippines, Brazil, and Guyana, may access limited information for approved business functions. Information may also be processed where approved providers and their subprocessors operate. Privacy and government-access laws may differ from those where a customer resides. Enzo uses contractual, organizational, and technical measures designed to protect information in cross-border processing. Accepting or shipping an order does not by itself determine which foreign privacy laws apply; applicability depends on the relevant legal requirements and our activities. Where another jurisdiction's law applies, Enzo provides the additional notices, choices, rights, or transfer safeguards that law requires. Residents of other countries may contact us through Section 18 about rights under their local law.

17 Changes to this Policy

We may update this Policy to reflect changes in law, technology, vendors, or our practices. We will post the revised version with a new Last updated date. If a change materially affects how we use information we already hold about you, we will give you additional notice—for example, by email or a prominent notice on our website—before the change takes effect and, where law requires, a reasonable opportunity to withdraw consent. We will obtain new consent before materially expanding a consent-based use where law requires it. Prior versions are available on request.

18 Contact us

Privacy Office
Enzo Custom Florida Inc. d/b/a Enzo Custom
501 E Las Olas Blvd., Suite 300
Fort Lauderdale, FL 33301
Privacy email: [email protected]
Telephone: 888-622-3696
Privacy Request Form: enzocustom.com/privacy-request
Your Privacy Choices: enzocustom.com/privacy-choices

Appendix A Enzo Group entities

The table identifies commonly controlled legal entities and their business or contact addresses. It is an entity schedule; an address or affiliate listing does not identify a currently open showroom or appointment location. Use the Showrooms and booking pages for current visitor locations. The entity responsible for your transaction appears on your order, receipt, or intake ticket. Enzo Custom Florida Inc. administers shared systems and privacy requests for the Group.

Legal name State of formation Business or contact address Entity role
Enzo Custom Florida Inc. Florida 501 E Las Olas Blvd., Suite 300, Fort Lauderdale, FL 33301 Program administrator; shared websites, systems, and vendor relationships
Enzo Custom Beverly Hills Inc. California 150 S Rodeo Drive, Suite 150, Beverly Hills, CA 90212 Enzo Group affiliate
Enzo Custom Boca Raton Inc. Florida One Town Center Road, Suite 101, Boca Raton, FL 33486 Enzo Group affiliate
Enzo Custom Boston Inc. Massachusetts 35 Newbury St, 2nd Fl, Boston, MA 02116 Enzo Group affiliate
Enzo Custom Charlotte Inc. North Carolina 201 South College St, Suite 2255, Charlotte, NC 28244 Enzo Group affiliate
Enzo Custom Clothiers Chicago Inc. Illinois 48 E Oak St, Fl 3, Chicago, IL 60611 Enzo Group affiliate
Enzo Custom Clothiers D.C. Inc. District of Columbia 1001 Connecticut Ave NW, Suite 1110, Washington, DC 20036 Enzo Group affiliate
Enzo Custom Clothiers Philadelphia Inc. Pennsylvania 1601 Walnut St, 2nd Floor, Philadelphia, PA 19102 Enzo Group affiliate
Enzo Custom Dallas Inc. Texas 3699 McKinney Ave, Dallas, TX 75204 Enzo Group affiliate
Enzo Custom Greenwich Inc. Connecticut 415 Greenwich Ave, Greenwich, CT 06830 Enzo Group affiliate
Enzo Custom Houston Inc. Texas 2001 Kirby Dr, Suite 1375, Houston, TX 77019 Enzo Group affiliate
Enzo Custom Miami Inc. Florida 800 Brickell Ave, Suite 110, Miami, FL 33131 Enzo Group affiliate
Enzo Custom Nashville Inc. Tennessee 434-438 Houston St, Suite 254, Nashville, TN 37203 Enzo Group affiliate
Enzo Custom Palo Alto Inc. California 575 High Street, Palo Alto, CA 94301 Enzo Group affiliate
Enzo Custom Short Hills Inc New Jersey 533 Millburn Ave, Short Hills, NJ 07078 Enzo Group affiliate
Enzo Custom SoHo Inc. New York 118 Spring Street, Fl 2, New York, NY 10012 Enzo Group affiliate
Enzo Custom Williamsburg Inc. New York 105 N 13th St, Suite 407, Brooklyn, NY 11249 Enzo Group affiliate
Enzo Sartori Inc. New York 5 East 57th St, 18th Fl, New York, NY 10022 Enzo Sartori affiliate
Custom Clothing Solutions Inc. New York 315 Madison Ave, 14th Fl, New York, NY 10017 Enzo Group affiliate
Sanpari Tailors Boston Inc Massachusetts 39/45 Newbury St, Suite 206, Boston, MA 02116 Sanpari affiliate
Sanpari Tailors DC Inc District of Columbia 1634 I Street NW, Suite 901, Washington, DC 20006 Sanpari affiliate
Sanpari Tailors Philadelphia Inc. Pennsylvania 1601 Walnut St, 2nd Fl, Philadelphia, PA 19102 Sanpari affiliate
Sanpari Tailors SoHo Inc. New York 599 Broadway, 10th Fl, New York, NY 10012 Sanpari affiliate