Cookie Policy
Last updated: August 13, 2026
Tourlink Cookie Policy
Last updated: 11 August 2026
1. About this Policy
This Cookie Policy explains how OMAX Group Ltd, trading as Tourlink (“OMAX”, “Tourlink”, “we”, “us” or “our”), uses cookies and similar storage or access technologies on tourlink.me (the “Store”).
OMAX Group Ltd is registered in England and Wales under company number 16125244, with registered office at 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ, United Kingdom.
This Policy should be read with our Privacy Policy. Questions may be sent to dpo@omaxtelecom.com.
2. What cookies and similar technologies are
Cookies are small text files stored on a browser or device. We may also use local storage, pixels, tags, scripts and software development kits that store information on, or access information from, a device. In this Policy, we refer to all of these as “cookies” unless the context requires otherwise.
Cookies may be:
session cookies, which expire when the browser is closed;
persistent cookies, which remain until their stated expiry date or are deleted;
first-party cookies, set by Tourlink; or
third-party cookies, set by another provider whose service appears in the Store.
3. When we need consent
Under UK privacy rules, we may use a cookie without consent only where a legal exception applies. This normally includes cookies that are strictly necessary to provide a service you requested, transmit a communication, maintain security or remember a privacy choice.
We ask for consent before using non-essential analytics, advertising, cross-site tracking or similar cookies. Refusing these cookies does not prevent you from purchasing or using an eSIM, although some optional features may be less personalised.
Where we rely on consent:
non-essential cookies remain off until you make a choice;
“Reject all” is offered as clearly as “Accept all”;
you can make a granular choice by category; and
you can withdraw consent at any time through Cookie settings in the Store footer.
We do not treat continued browsing, silence or a pre-ticked box as consent.
4. Cookies used by the Store
The table below describes the expected cookies in the standard Tourlink deployment. The live Store may use fewer cookies. We will update this table before introducing a materially different cookie or provider.
| Category | Cookie or provider | Purpose | Typical duration | Consent |
|---|---|---|---|---|
| Strictly necessary | omaxwhitelabel-session | Maintains a secure Store session, account state and checkout journey. | Up to 30 days | Not required |
| Strictly necessary | XSRF-TOKEN | Helps protect forms and requests against cross-site request forgery. | Up to 30 days | Not required |
| Strictly necessary | Consent preference | Records whether non-essential cookies were accepted or rejected so that the banner does not reappear on every visit. | Up to 12 months | Not required |
| Preferences | theme | Remembers the selected display theme. | Up to 12 months | Normally not required where requested by the user |
| Preferences | Language and currency preference | Remembers a language or display currency selected by the user. Names may vary by deployment. | Session or up to 12 months | Normally not required where requested by the user |
| Analytics | Google Analytics 4, including _ga and _ga_<container-id> | Measures visits, page use, conversions and technical performance so we can understand and improve the Store. | Commonly up to 2 years, subject to the configured retention period | Required before use |
| Payments and fraud prevention | The payment provider selected at checkout, which may include Stripe, PayPal, Airwallex or Paddle | Processes a payment, authenticates the payer and prevents payment fraud. The provider may set its own cookies when its checkout component is loaded. | Set by the selected provider and described in its notice | Not required where strictly necessary for the payment requested; otherwise required |
An entry saying that consent is not required does not mean the information is unregulated. We use the cookie only for the stated limited purpose and handle associated personal data as described in our Privacy Policy.
5. Analytics
We use Google Analytics only after the user has consented to analytics cookies. It may collect or derive information such as:
browser and device type;
approximate location based on an IP address;
pages viewed and actions taken;
referral source;
technical identifiers; and
purchase or conversion events that we configure.
We do not intentionally send payment-card details, eSIM activation codes or the content of support messages to analytics providers. Analytics consent may be withdrawn at any time. Withdrawal does not affect processing that occurred lawfully before withdrawal.
If we introduce a consent-free audience-measurement configuration, we will do so only where all conditions of the applicable UK statistical-use exception are met, including aggregate-only use, no individual or cross-service tracking, limited retention and a simple free objection mechanism. Until then, analytics remains consent-based.
6. Payments and third-party content
We load payment functionality when it is needed for the checkout method the user chooses. The selected payment provider may receive device, transaction, account and anti-fraud information and may operate as an independent controller for some purposes. Its privacy and cookie information will apply to that processing.
The Store may link to third-party pages or display content supplied by mobile-network, mapping, support or media providers. Opening or interacting with that content may allow the provider to use its own technologies. We will request consent first where UK law requires it.
7. Referrals and advertising
The standard Tourlink referral programme uses referral codes or account-based attribution and does not require third-party advertising cookies. If a particular Store introduces affiliate tracking, retargeting, advertising pixels or cross-site profiling, those technologies will be listed here and will remain disabled until consent is given.
8. How to control cookies
You can:
use Cookie settings in the Store footer to accept, reject or change optional categories;
use browser controls to view, block or delete cookies; and
adjust device-level privacy settings where relevant.
Blocking all cookies may prevent account login, cart, security or checkout functions from working. Refusing only non-essential cookies will not prevent use of the core Store.
Guidance for common browsers is available through their help pages. Browser settings do not always control local storage, applications or other technologies, so use the Store’s Cookie settings as well.
9. Personal data and international transfers
Cookie data may be shared with hosting, security, analytics and payment providers. Some providers may process data outside the United Kingdom. Where UK law requires safeguards, we use an adequacy regulation, the UK International Data Transfer Agreement, the UK Addendum to approved contractual clauses or another lawful safeguard, together with a transfer risk assessment where required.
Our Privacy Policy explains the purposes and legal bases for processing, recipients, retention, rights and complaints.
10. Changes to this Policy
We may update this Policy when the Store, providers or law changes. The date above shows the latest revision. We will not use a new non-essential cookie merely because this Policy was updated: we will obtain consent where required.
11. Contact
Privacy Team - OMAX Group Ltd
Email: dpo@omaxtelecom.com
Registered office: 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ, United Kingdom
Company number: 16125244
Telephone: +44 20 8058 6185