Privacy Policy
Last updated: August 13, 2026
Tourlink Privacy Policy
Last updated: 11 August 2026
1. Who is responsible for your personal data
Tourlink is a trading name and eSIM store operated by OMAX Group Ltd (“OMAX”, “Tourlink”, “we”, “us” or “our”). Tourlink is not a separate legal entity.
OMAX Group Ltd is a private limited company registered in England and Wales under company number 16125244, with registered office at 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ, United Kingdom.
For the processing described in this Policy, OMAX is normally the controller. This means we decide why and how personal data is used. Where a clearly identified white-label partner determines its own marketing, analytics or customer-relationship purposes, that partner is a separate controller for those activities and must be identified in the store-specific version of this Policy.
Contact our Privacy Team at dpo@omaxtelecom.com.
2. Scope
This Policy explains how we process personal data when you:
visit tourlink.me or use a Tourlink account;
search for, purchase, install, activate or top up an eSIM;
use mobile data supplied through an eSIM plan;
use our referral, affiliate or promotional features;
contact support, make a complaint or exercise a legal right; or
interact with our transactional or marketing communications.
It is written under the UK General Data Protection Regulation, the Data Protection Act 2018, the Privacy and Electronic Communications Regulations 2003, and the Data (Use and Access) Act 2025.
3. Personal data we collect
3.1 Data you provide
We may collect:
identity and contact data, such as name, email address, telephone number, country and billing address;
account data, such as login credentials, account ID, language, currency and communication preferences;
order data, such as destination, plan, allowance, validity, price, discounts, referral code, invoice and transaction identifiers;
payment-related data, such as billing name, payment method, payment status, fraud checks and limited card information supplied by the payment provider; we do not normally receive or store your full card number;
support and complaint data, such as messages, screenshots, device details, diagnostic information, call recordings where notified, and the outcome of a request or complaint;
marketing data, such as newsletter consent, campaign interaction and unsubscribe status; and
identity-verification data where required for fraud prevention or a destination-specific SIM registration rule, which may include an identity document, proof of address or an electronic verification result. We will provide additional information where sensitive or biometric verification is required.
3.2 Data created when you use the Service
We may process:
eSIM and network identifiers, including ICCID, IMSI, MSISDN where assigned, and IMEI or EID where available or needed for support;
activation and provisioning status;
network session dates and times, data volume, serving country or region, network operator and technical routing information;
remaining allowance, expiry, top-ups and service events;
account logins, security events, IP address, device type, browser, operating system and approximate location derived from IP address or the serving network;
website activity, such as pages viewed, referral source, clicks, errors and performance data, subject to the Cookie Policy; and
fraud and risk signals supplied by payment, security or network providers.
Tourlink does not use GPS to track your precise location as part of the standard eSIM Service. A mobile network will necessarily process location-related information to connect your device, generally at network or country/region level.
Tourlink plans are normally data-only. We do not inspect the content of your internet traffic. Network providers may process traffic as required to route communications, maintain security and comply with law.
3.3 Data obtained from others
We may receive data from:
payment processors and banks;
mobile operators, roaming and connectivity providers;
fraud-prevention, sanctions-screening and identity-verification providers;
a white-label, referral or affiliate partner that directed you to the Store;
analytics and advertising providers where permitted by your choices; and
public authorities or publicly available sources where necessary to comply with law.
4. Why we use personal data and our lawful bases
We use personal data only where we have a lawful basis.
4.1 Contract and pre-contract steps
We process data to:
create and manage an account;
show relevant plans and currencies;
accept payment and form the contract;
generate, deliver, install, activate and administer an eSIM;
provide data connectivity and top-ups;
show usage and expiry information;
send receipts, activation details and service messages;
provide support, troubleshoot and process valid refunds; and
close an account or complete a requested data export.
If you do not provide essential contact, order or payment data, we may be unable to supply the Service.
4.2 Legal obligations
We process data where necessary to:
maintain tax, accounting and transaction records;
respond to lawful requests, court orders and regulatory requirements;
comply with sanctions, fraud-prevention, telecommunications and consumer-protection duties;
support data protection rights and complaints; and
notify affected individuals or regulators of a personal data breach where required.
4.3 Legitimate interests
We may process data where necessary for our legitimate interests or those of a third party, after considering your rights. These interests include:
securing the Store, accounts, payments and networks;
detecting and preventing fraud, misuse, chargebacks and technical faults;
maintaining, testing and improving service reliability;
measuring aggregate business and service performance;
responding to enquiries and managing customer relationships;
establishing, exercising or defending legal claims; and
sending existing customers information about similar products where PECR permits and an easy opt-out is provided.
You may object to processing based on legitimate interests. We will stop unless we have compelling grounds to continue or need the data for legal claims.
4.4 Consent
We rely on consent for:
non-essential cookies or similar technologies where consent is required;
email or SMS marketing where another PECR permission does not apply;
optional advertising personalisation or cross-site measurement; and
another optional use clearly described when consent is requested.
You may withdraw consent at any time without affecting processing that occurred before withdrawal.
5. Cookies and similar technologies
We use cookies, local storage, scripts, tags and similar technologies for security, sessions, preferences, analytics and payments. Non-essential technologies are controlled as described in the Tourlink Cookie Policy.
The Store currently uses Google Analytics when enabled. Analytics or advertising technology that does not meet a PECR exception must not be activated before the required consent. You can change your choices using the Cookie settings link in the Store footer.
6. Marketing
Transactional communications about an order, security, expiry, support or a material service change are not marketing and are sent as part of the Service or for our legitimate interests.
We send promotional email or SMS only where PECR and data protection law permit. You can opt out using the unsubscribe link, account setting or dpo@omaxtelecom.com. Opting out of marketing does not stop necessary service messages.
We keep a minimal suppression record after an opt-out so that we do not contact you again through that channel.
7. Automated fraud and payment decisions
We and our payment or fraud-prevention providers may use automated risk checks to identify suspicious transactions, account takeovers, sanctions risks or abusive use. A high-risk transaction may be delayed, rejected or referred for review.
Where a decision is based solely on automated processing and produces a legal or similarly significant effect, we will provide the protections required by UK law. You may contact support@omaxtelecom.com to ask for a human review, provide your view or challenge an incorrect decision.
8. Who receives personal data
We share only what is reasonably necessary with:
payment providers, which may include Stripe, PayPal, Airwallex, Paddle or the provider identified at checkout;
mobile network operators, roaming partners and connectivity suppliers needed to provision and operate the eSIM;
Tenzor d.o.o., Banja Luka, Bosnia and Herzegovina, for contracted technical and operational support;
hosting, security, database, email, customer-support and software providers;
analytics and advertising providers, including Google where the relevant technology is enabled in accordance with your choices;
white-label, referral or affiliate partners, where necessary to provide the branded service, calculate an earned commission, deliver first-line support or honour a referral benefit;
professional advisers, insurers, auditors and prospective purchasers under confidentiality obligations;
fraud-prevention bodies, banks and card schemes; and
courts, regulators, law-enforcement bodies and other authorities where disclosure is required or lawfully permitted.
Mobile operators and payment providers may act as independent controllers for their own regulated purposes. Their own privacy notices also apply to that processing.
We do not sell personal data. We do not share it with third parties for their independent direct marketing unless you have given valid consent or another lawful permission clearly applies.
9. International transfers
Travel connectivity is global. Personal data may be accessed or processed outside the United Kingdom, including by mobile operators in the country where you use the eSIM and by contracted technical or cloud providers.
For a restricted transfer under UK data protection law, we use an available lawful mechanism, which may include:
UK adequacy regulations;
the UK International Data Transfer Agreement;
the UK Addendum to approved contractual clauses;
another approved safeguard, together with the required data protection test and additional measures; or
a limited statutory exception where it is necessary for your requested service or otherwise lawful.
You may contact dpo@omaxtelecom.com for more information about relevant safeguards.
10. How long we keep personal data
We keep personal data only for as long as reasonably necessary for the stated purpose, legal obligations, fraud prevention and legal claims. Our normal retention periods are:
account profile: while the account is active and normally up to 24 months after the last activity, except for data retained under another category;
orders, invoices, payments and tax records: normally six years after the end of the relevant accounting period;
eSIM provisioning, activation and network usage records: normally 12 months after the plan expires or the account closes, and longer where reasonably required for billing disputes, fraud, security, legal claims or a lawful retention notice;
support tickets and ordinary complaints: normally 24 months after closure;
formal legal, regulatory, chargeback or fraud cases: for the life of the matter and normally up to six years after closure where needed for claims;
security logs: normally up to 24 months, unless an incident requires longer retention;
unsuccessful identity-verification material: only for the period needed to complete, audit or contest the check, unless law requires longer;
marketing records: until you opt out or the purpose ends; and
suppression records: for as long as needed to respect the opt-out.
Cookie and similar-technology durations are stated in the Cookie Policy.
We may keep data longer if required by law, a court order, a regulatory instruction or a documented legal claim. When data is no longer needed, we delete it, put it beyond use or anonymise it. Secure backups may retain isolated copies until they are overwritten under the backup cycle.
11. Security
We use technical and organisational measures appropriate to the risk, including encryption in transit, access controls, authentication, logging, network protection, supplier due diligence, staff confidentiality obligations and incident-response procedures.
No internet or telecommunications system is completely secure. You should use a strong unique password, protect your email account and device, and notify us promptly of suspected unauthorised access.
12. Your UK data protection rights
Subject to legal conditions and exceptions, you may have the right to:
receive information about how we use your data;
access your personal data;
correct inaccurate or incomplete data;
request deletion;
restrict processing;
object to processing based on legitimate interests;
object to direct marketing at any time;
receive certain data in a portable format;
withdraw consent; and
obtain safeguards concerning qualifying automated decisions.
To exercise a right, email dpo@omaxtelecom.com. We may request proportionate information to verify identity and protect your account. We normally respond within one month, subject to any lawful extension or pause while necessary clarification is obtained.
13. Data protection complaints
You have the right to complain to us if you believe we have not complied with data protection law.
Email dpo@omaxtelecom.com with the subject Data Protection Complaint and describe what happened, the data involved and the outcome you want. We will:
acknowledge the complaint within 30 days of receipt;
take appropriate steps to investigate without undue delay;
keep you informed where the investigation is ongoing; and
tell you the outcome without undue delay.
You may also complain to the Information Commissioner’s Office (ICO) at ico.org.uk/make-a-complaint or by telephone on 0303 123 1113. You do not have to contact us before complaining to the ICO, although we would appreciate the opportunity to resolve the matter.
14. Children
The Store is intended for adults who can enter into a purchase contract. We do not knowingly create accounts for children under 18. A parent or guardian may purchase and supervise an eSIM used by a child. If you believe a child provided data without appropriate involvement, contact dpo@omaxtelecom.com.
15. Third-party links and services
The Store may link to third-party websites, applications or device instructions. Those third parties control their own processing, and their privacy notices apply. We are not responsible for an independent third party’s privacy practices.
16. Changes to this Policy
We may update this Policy to reflect changes in the Service, suppliers or law. We will update the date above and provide a prominent notice or direct notification where a change is material. A new purpose requiring consent will not be introduced merely by changing this Policy; we will request consent where required.
17. Contact
Privacy Team - OMAX Group Ltd
Email: dpo@omaxtelecom.com
Registered office: 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ, United Kingdom
Company number: 16125244
Telephone: +44 20 8058 6185