Privacy Policy
How Tourist SOS handles information on this marketing, enquiry, and demonstration website, with separate context for processing through related applications and services.
Last updated: May 15, 2026
Expansion draft — pending factual and legal review. This proposed revision is not approved for publication. The existing date is retained pending an agreed effective date and any required notices. Described practices, permissions, and retention arrangements must be confirmed before this draft is adopted.
Table of Contents
About Terra — Our AI Assistant
Where you interact with Terra, our AI assistant, conversation handling depends on the feature and service used. A website demonstration is not a live emergency-dispatch service. Responding to a request, reviewing service quality, and training or fine-tuning a model are different activities; using Terra does not by itself authorize every one of them. Sections 2.4, 3.3, 3.4, and 4.4 explain those distinctions, the applicable permissions, and AI-provider processing. Your rights — including access, deletion, withdrawal of consent, and objections to particular uses — are described in Section 8.
Introduction
Tourist SOS LLC (“Tourist SOS,” “Company,” “we,” “us,” or “our”), a Delaware limited liability company with its principal office at 401 Ryland Street, Ste 200A, Reno, NV 89502, USA, is committed to protecting your privacy. This Privacy Policy explains how we collect, use, share, retain, and safeguard your information on this marketing, enquiry, and demonstration website. It also describes processing that may be relevant to related applications and services, including Terra, SOS Travel, SOS Pro, SOS Safe, and the internal Command Center(together with the website, our “Services”), subject to the scope below.
This website presents Tourist SOS and receives enquiries and demonstration requests; live emergency dispatch is not available through it. Tourist SOS may arrange or subcontract assistance under a separate agreement. Descriptions of healthcare, insurance, or emergency coordination below apply only where the relevant service is actually provided and the processing is lawfully authorized. Where such a service involves parties in different countries, information may move between the traveler, providers, partners, and infrastructure locations, subject to Section 7. A directory listing does not itself establish verification, a contractual relationship, or availability; those are distinct statuses, as explained in our Terms of Service.
This Policy provides information about data processing; it is not a request for blanket consent. Reading it, accepting our Terms of Service, or continuing to use a Service does not replace a separate permission or explicit consent where applicable law requires one. Some processing is necessary for the service you request or is permitted or required on another legal basis, as explained in Section 3.4.
This Privacy Policy should be read alongside our Terms of Service. Capitalized terms not defined here have the meanings given in the Terms of Service. A customer-specific data-processing agreement governs processing undertaken on that customer's behalf and is not enlarged by the general descriptions in this notice.
1.1Scope, Roles, and Responsibility
The information handled depends on the surface and service you use. Visiting a public page, asking a general question, opening an assistance case, and using an organization's operational account do not all involve the same data. A category listed in this Policy does not mean that every visitor must provide it or that it is collected on every visit.
Website enquiries and demonstrations must be distinguished from account, patient, case, or operational processing in related applications. An application-specific notice and any applicable agreement must identify the processing relevant to that interaction. Separate applications do not, by themselves, establish different legal operators or privacy roles. The responsible organization and its role must be identified from the actual activity and arrangement.
Tourist SOS is a controller for processing whose purposes and essential means it determines, such as managing its own website enquiries and business relationships. Where it processes information solely on a business customer's documented instructions, it acts as a processor or subprocessor within the scope of that arrangement. The actual activity and agreement determine the role; calling all parties “partners” does not make their responsibilities interchangeable.
Healthcare providers, insurers, hospitality operators, and emergency authorities may be independent controllers for their own treatment, claims, guest-service, or statutory activities. Their notices and legal duties apply to those activities. A provider's responsibility for its clinical record is distinct from Tourist SOS's responsibility for a coordination record or an AI conversation.
The laws that apply depend on the processing, the people and organizations involved, and relevant territorial rules. References to GDPR, UK GDPR, or other regimes do not mean that every law applies to every interaction. Contact us under Section 12 if you need to identify the responsible organization for a particular record or request.
Information We Collect
2.1Personal Information
We collect personal information that you voluntarily provide to us:
Identity Information
- • Full name and contact information
- • Date of birth and nationality
- • Passport and identification numbers
- • Emergency contact details
Contact Information
- • Email address and phone numbers
- • Mailing address and location data
- • Preferred communication methods
- • Language preferences
Travel Information
- • Travel itineraries and accommodation details
- • Transportation information
- • Travel insurance details
- • Destination preferences
Health Information
- • Medical conditions and allergies
- • Medications
- • Healthcare provider preferences
- • Insurance and payment information
Payment Information
- • Credit and debit card information
- • Billing addresses and payment history
- • Financial account details
- • Transaction records
Account Information
- • Username, password, profile preferences
- • Account settings and notification preferences
- • Service usage history
- • Support interactions
2.2Location and Usage Information
We automatically collect certain information when you use our Services:
- • Device data: IP address, browser type, device identifiers, operating system
- • Location data: Where the device, permissions, and feature support it, GPS coordinates or location derived from network information, which may include Wi-Fi access points or cell towers (used to route assistance and find nearby providers)
- • Usage data: Pages visited, features used, time spent, click patterns
- • Communication data: Messages sent through our platform, call logs, support interactions
- • Cookies and similar technologies: Session data, preferences, analytics information (see Section 10)
Precise device location, a location you type, and an approximate location derived from an IP address are different sources. Device permission does not authorize unrelated uses of location, and a location supplied for an incident is not permission for undisclosed background tracking. Where location controls are available, you can change them through your device or browser. Declining a permission may limit nearby-provider matching or routing; you may instead provide a location manually where the service supports that option. Necessary incident records may remain subject to Section 6.
2.3Third-Party Information
We may receive information about you from third parties:
- • Healthcare providers and medical facilities in our network
- • Hotels, resorts, and tour operators using SOS Safe
- • Insurance companies and third-party administrators (TPAs)
- • Travel booking platforms and accommodation providers
- • Payment processors and financial institutions
- • Analytics providers and infrastructure partners
- • Embassy and consular services (in emergency situations)
- • Local emergency responders coordinated through our network
2.4Terra Conversation Data
Depending on the surface, features used, and applicable permissions, information handled when you interact with Terra may include:
- • Messages you send: Text input, voice transcripts (if voice features are used), and any attachments or photos shared with Terra
- • Terra's responses: The conversational outputs generated by Terra in reply to your messages
- • Inferred metadata: Detected language, sentiment, urgency, and triage category derived from the conversation
- • Structured records: Case summaries, provider matches, and insurance verification artifacts that Terra produces from your conversation
- • Session metadata: Timestamps, session identifiers, device context, and location at the time of the interaction
Conversation data supports the assistance or enquiry you request and may become part of a case record where relevant. Any separate use for quality review, evaluation datasets, or model development is subject to the distinctions and permissions in Sections 3.3 and 3.4; a message is not automatically available for every secondary purpose. Your rights with respect to this data are described in Section 8.
How We Use Your Information
Website processing covers the enquiry, demonstration, and digital operations relevant to your visit. The broader service purposes below apply only to an actually provided service under the scope in Section 1; they do not make an enquiry an active assistance case.
3.1Core Services
- • Healthcare coordination: Connect you with healthcare providers, facilitate medical appointments, coordinate emergency medical care
- • Travel support: Provide assistance, coordinate with local responders and (where appropriate) embassies and consulates
- • Assistance arrangements: Where separately agreed and available, arrange assistance or medical transport through the relevant providers; this website does not provide live emergency dispatch
- • Payment processing: Process payments, manage billing, handle insurance claims and guarantees of payment
- • Case and patient management: Maintain case records, track treatment history, coordinate follow-up care
- • Communication: Facilitate communication between travelers, providers, hospitality operators, insurers, and our internal ops team
3.2Digital Operations
- • Account management: Create and maintain user accounts, authenticate users, manage preferences
- • Service improvement: Analyze usage patterns, conduct research, develop new features
- • Communications: Send service notifications, provide customer support, deliver important updates
- • Security and compliance: Detect and prevent fraud, ensure regulatory compliance, maintain data security
- • Legal compliance: Comply with applicable laws, respond to lawful requests, protect our rights
- • Business operations: Manage partnerships, conduct business analysis, support corporate functions
3.3AI Model Training and Improvement
Using a model to respond to you (“inference”) is different from training or fine-tuning that model. Service-quality review is also a separate activity. The following distinctions govern how the conversation data and operational records described in Section 2.4 may be used; they are not blanket authorization for new uses.
- • Coordination and inference: Using relevant messages and context to generate a response, prepare a case summary, support translation, or suggest a provider. Sending data to an AI service for this purpose does not, by itself, mean its model is trained on that data.
- • Quality and safety review: Evaluating response quality, accuracy, and safety; identifying failure modes, edge cases, and misuse; and assessing provider matching, language handling, triage, and routing. Human review, identifiable examples, and evaluation datasets require their own defined scope, access limits, lawful basis, and retention arrangements.
- • Training and fine-tuning: A separate model-development use that changes model parameters. Any optional future program, or material expansion of an existing use, must identify the data involved, purposes, recipients, permissions, and applicable choices before it starts. A request for assistance is not, by itself, agreement to participate.
- • Evaluation datasets and benchmarks: Copies selected for testing are still subject to purpose limits and deletion rules if they identify someone. Removing a name does not necessarily anonymize a medical narrative, photograph, location history, or unusual case.
Where Tourist SOS processes information for a business customer, that customer's documented instructions and the applicable agreement determine whether a proposed quality-review or development use is permitted. This general notice does not authorize independent training on customer-controlled records. Health information, children's information, identity documents, and precise location require the additional safeguards and lawful permissions applicable to those categories, including explicit consent where required. Emergency-processing grounds do not extend to unrelated model development.
What we do not do:
- • We do not sell your conversation data or train models for other companies
- • We do not use your data to target you with third-party advertising
- • We do not treat “service improvement” as unlimited permission to reuse voluntary medical information. A secondary use must satisfy applicable purpose, notice, legal-basis, health-data, and customer-instruction requirements
- • We do not treat acceptance of our Terms, a general content licence, or an emergency request as a substitute for a separately required consent
You may request deletion of conversation data or object to a particular use through Section 8. If information has been incorporated into a trained model, complete removal from model weights cannot be promised. That technical limitation is not a blanket exemption from privacy rights: the response must distinguish source logs, identifiable datasets, derived records, and model parameters, explain any lawful retention exception, and address the measures available for the particular request.
3.4Purposes, Legal Bases, and Health-Data Conditions
Where GDPR or UK GDPR applies, each processing activity needs an applicable Article 6 legal basis. Health information also needs an Article 9 condition and any additional safeguards required by local law. Similar requirements in other jurisdictions must be assessed separately. The applicable basis must be identified for the actual purpose; the following framework is not a choice to rely on every basis interchangeably.
- • Requested services and accounts: Contractual necessity may cover steps genuinely needed to provide the service you request or take steps at your request before entering a contract. It does not automatically cover all analytics, model training, or processing about someone who is not party to that contract.
- • Support, security, and business operations: Legitimate interests may support responding to enquiries, protecting the service against misuse, and administering business relationships where the relevant necessity and balancing tests are satisfied. The interests, impact on the individual, and available safeguards must be assessed; a commercial interest does not override health-data conditions.
- • Legal obligations: Recordkeeping, regulatory reporting, and responses to legally binding requests may be required under laws that apply to the particular organization and activity. A general reference to compliance does not create a duty to retain every record or disclose an entire case file.
- • Consent: Where consent is the basis, it must cover the particular activity, be informed and freely given, and be capable of withdrawal. Optional activities must not be bundled into unrelated service permissions. Separate, explicit consent is required where the relevant health-data condition or local law calls for it. This notice does not claim that a particular consent interface has been implemented.
- • Vital interests and emergencies: Necessary processing to protect life may rely on an applicable emergency ground. The GDPR/UK GDPR vital-interests condition for health data is limited to situations where the person is physically or legally incapable of giving consent. It is not a general fallback after a capable person refuses consent, and does not justify routine marketing or model training.
- • Health-data conditions: Depending on the facts and applicable law, a condition may involve explicit consent, qualifying health or social-care activities under required professional-secrecy safeguards, vital interests, or necessary legal claims. Tourist SOS's coordination role alone does not establish that a healthcare exception is available for every activity.
Refusing or withdrawing an optional permission does not waive your other rights. Withdrawal does not retrospectively invalidate processing that was lawful before it, but future consent-based processing must cease as required by law. A separate lawful obligation may require a limited record to be retained; it does not automatically permit that record to be used for a new purpose. Contact Section 12 for the basis, role, and available choices relevant to your particular interaction.
Data Security and Protection
We implement administrative, technical, and physical security measures designed to protect your personal information against unauthorized access, alteration, disclosure, or destruction.
5.1Technical Safeguards
- • Encryption: Encryption in transit (TLS) and at rest for personal and health data
- • Access controls: Multi-factor authentication, role-based access, regular access reviews
- • Network security: Firewalls, intrusion detection, hardened network configuration
- • Backup and recovery: Automated backups, disaster recovery testing
- • Row-level data isolation: Database-level controls so each user's data is logically isolated
5.2Organizational Safeguards
- • Staff training: Privacy and security training, confidentiality agreements
- • Policies and procedures: Documented data-protection policies and incident-response procedures
- • Vendor management: Due diligence on processors, contractual data-protection requirements
- • Compliance monitoring: Internal reviews and (where applicable) third-party audits
Important Notice: No method of transmission over the Internet or electronic storage is completely secure. These descriptions are not a certification or a guarantee that an incident cannot occur. Our Trust & Security page distinguishes current measures from formal compliance work still in progress. Specific safeguards and customer commitments must be verified for the relevant service.
Breach-notification duties depend on our role, the incident, and applicable law. Where GDPR or UK GDPR requires Tourist SOS as controller to notify a supervisory authority, notification is due without undue delay and, where feasible, within 72 hours after becoming aware of a notifiable breach. Affected individuals must be informed without undue delay where the applicable high-risk threshold is met; that is a distinct duty, not a universal 72-hour deadline for every user.
Where Tourist SOS is a processor, the responsible customer must be notified without undue delay after awareness of a personal-data breach affecting its data, with further information supplied as it becomes available. Completion of an investigation must not be used to postpone a notification already required by law. Other applicable health, consumer, or national breach rules may impose different recipients, thresholds, and deadlines. Nothing here assumes that HIPAA or another particular regime applies to every record or interaction.
Data Retention
We retain personal information only for as long as necessary to deliver our Services, comply with our legal obligations, resolve disputes, and enforce our agreements.
- • Account data: Retained for the duration of your account, plus 30 days after a deletion request to allow for reversal
- • Medical and case records: Retained for the minimum period required by applicable law in the jurisdiction where care was delivered (typically 5–10 years)
- • Terra conversation logs: Active conversation logs retained for up to 24 months for service quality and AI improvement subject to Sections 3.3 and 3.4, then anonymized or deleted unless retention is required by law
- • Transaction and billing records: Retained for 7 years for tax and regulatory compliance
- • Usage analytics: Aggregated and anonymized after 24 months
- • Backups: Standard backups are retained on a 30–90 day rotation; deletion requests propagate to backups in the next regular cycle
The existing schedule above is retained for review and must be verified against the relevant deployed systems, applicable rules, and customer arrangements before adoption. These periods are not blanket permission to retain information for every possible use. Necessity, a valid erasure request, a customer instruction, or a shorter applicable legal limit may require earlier action. Conversely, an identified legal duty or properly scoped legal hold may require a particular record to be preserved. The reason, affected categories, and applicable period must be distinguished from routine storage.
- • When a period starts: The account-deletion period is measured from the deletion request. The 24-month conversation and analytics periods are measured from creation or collection of the individual record, not restarted by unrelated account activity. Medical and financial retention starts from the event required by the relevant recordkeeping rule, which can differ by record type and jurisdiction, including special rules for children. A reversible account period must not defeat a legally required erasure.
- • Overlapping records: Closing an account does not automatically erase a case, billing, or legal record that must lawfully be retained. A relevant extract from a conversation may form part of that record, but this does not make every unrelated message subject to the longest medical-record period.
- • Copies and derived data: A deletion assessment must consider active logs, attachments, case extracts, identifiable evaluation or training datasets, exports, and relevant processor-held copies. Calling a dataset “de-identified” is not enough if a person can still reasonably be identified. Separate recipient-controller records remain subject to that organization's duties.
- • Backups: Deletion from active systems and expiry of a protected backup are different steps. Where immediate backup erasure is not reasonably possible, retained copies must be kept out of ordinary use until the scheduled rotation, and deletion instructions must be reapplied if a backup is restored. A backup exception must not become permission to reuse data for new analysis or training.
- • Customer-controlled records: Where we act as processor, the customer's lawful instructions and agreed return/deletion arrangements govern; this general schedule does not override an applicable data-processing agreement.
Where information has actually been incorporated into model parameters, complete extraction cannot be guaranteed. This does not settle whether source records or identifiable datasets must be deleted, nor remove any duty to consider other lawful measures. A response to a deletion request must explain the scope of action, any justified limitations, and available routes to challenge the outcome. This Policy does not represent that an automated deletion or model-unlearning feature is available.
International Data Transfers
Depending on the website function or separately provided service, information may be transferred to, processed in, or stored in a country outside your residence, including the United States or a country in Southeast Asia where relevant recipients or infrastructure are located. The actual destinations must be confirmed for the processing concerned; this description does not establish a live assistance footprint.
This explanation is not consent to unrestricted international transfers. Where a transfer requires an agreement, assessment, authorization, or other safeguard, the actual arrangement must satisfy that requirement; naming a mechanism in this Policy does not put it in place. Remote access by an overseas recipient can also be relevant, even if a database is hosted in a different region. You may contact Section 12 for information about the safeguards applicable to your data and how to obtain a copy, subject to appropriate protection of confidential information.
For users in the EEA, UK, or Switzerland
Where we transfer your personal data outside the EEA, UK, or Switzerland to a country that has not been recognized as providing an adequate level of data protection, we rely on appropriate safeguards including:
- • Standard Contractual Clauses (SCCs) approved by the European Commission
- • UK International Data Transfer Agreement (IDTA) where applicable
- • Supplementary safeguards based on transfer impact assessments
For users in Southeast Asia
We endeavor to comply with local data-protection laws in the jurisdictions where we operate, including:
- • Singapore PDPA
- • Thailand PDPA
- • Indonesia PDP Law
- • Vietnam Personal Data Protection Law and applicable implementing rules
- • Comparable local regimes in other regional markets
Additional individual rights and any applicable localization or international-transfer requirements under local law also apply to the relevant processing.
Your Privacy Rights
8.1Universal Rights
Regardless of your jurisdiction, you have the following rights with respect to your personal information:
- • Access: Request a copy of the personal data we hold about you
- • Correction: Request correction of inaccurate or incomplete data
- • Deletion: Request deletion of your personal data (subject to legal retention obligations)
- • Portability: Request your data in a structured, machine-readable format
- • Objection and restriction: Object to or restrict certain types of processing
- • Withdraw consent: Where processing is based on consent, withdraw that consent at any time
8.2AI-Specific Rights
- • Human review: You have the right to request human review of any material decision that has been substantially driven by Terra's automated outputs
- • Conversation deletion: You can request deletion of your stored conversation logs at any time, subject to operational and legal retention rules
- • Information about AI processing: You can request meaningful information about the logic involved in any AI-driven decisions affecting you
- • Training-use choices: You may request that your future conversations not be used for training or fine-tuning. Where a use relies on consent, you may withdraw it; other objections must be considered under the applicable law. A technical limitation is not, by itself, a reason to disregard a legally required choice. We must explain the scope of the response and any specific service consequence, rather than assume that opting out always reduces personalization
8.3Jurisdiction-Specific Rights
EEA / UK (GDPR)
- • All universal rights above
- • Right to lodge a complaint with your supervisory authority
- • Right against solely automated decision-making (Art. 22)
California (CCPA / CPRA)
- • Right to know, delete, and correct
- • Right to opt out of sale or sharing (we do not sell)
- • Right to limit use of sensitive personal information
- • Right to non-discrimination for exercising your rights
Brazil (LGPD)
- • Equivalent rights to those described above
- • Right to information about public and private entities with whom data has been shared
Other jurisdictions
- • Local data-protection law applies in your jurisdiction
- • We will honor any additional rights provided by local law
8.4How to Exercise Your Rights
To exercise any of these rights, contact us at johnny@tourist-sos.com. We will acknowledge your request within 5 business days and respond substantively within 30 calendar days. We may need to verify your identity before processing the request. There is no fee for reasonable requests; we may charge a reasonable fee for excessive or repetitive requests as permitted by law.
This email route is available for manual requests; it is not a claim that a self-service opt-out, instant deletion switch, or model-unlearning tool exists. Identify the relevant account or interaction and the action you want, such as access, correction, deletion, consent withdrawal, or an objection to a specified AI use. Do not include a full passport, payment-card number, or medical file in an initial email. Any identity or representative-authority check should be proportionate to the request and the sensitivity of the information.
Any shorter mandatory deadline takes precedence. Extensions, fees, or a refusal must have a basis permitted by applicable law, with the reason and available complaint or review route explained as required. Where we process the relevant records only for a customer, the request must be directed or passed to the responsible controller with appropriate assistance under the applicable agreement. A retained medical or legal record does not justify rejecting every part of a wider request.
Withdrawal applies to the activity that relied on consent and does not undo past lawful processing. If a requested service genuinely cannot be provided without particular information, we must explain the affected function and any available alternative. Refusing an optional use does not waive access, correction, complaint, or other rights. Privacy correspondence is not an emergency-response channel.
Children's Privacy
Our Services are not directed to children under the age of 13 (or under 16 in the EEA and comparable jurisdictions). We do not knowingly collect personal information from children for marketing or general account creation purposes.
These statements do not authorize a child to open an independent account. Account eligibility is governed by the Terms of Service, the relevant product requirements, and applicable law. A child may nevertheless be the patient in an assistance case managed by a parent, guardian, or other lawfully authorized representative.
In emergency situations, we may receive and process information about minors when they are the patient and a parent, guardian, or authorized adult is coordinating their care through our platform. This processing is limited to what is necessary to facilitate the emergency response and is governed by the same protections that apply to all health data on the platform.
A person submitting information for someone else must have authority appropriate to the action requested; being a companion, hotel employee, or emergency contact does not automatically confer authority to consent to every disclosure or exercise every right. A request involving a child must take account of applicable parental-authority rules, the child's own confidentiality and decision-making rights, and the information necessary for the incident. Emergency grounds and children's additional protections are not permission to include their records in optional AI training.
If you are a parent or guardian and believe a child has provided personal information through our Services without appropriate authorization, contact johnny@tourist-sos.com so that we can investigate and take appropriate action, including deletion or restriction where required. We must consider any lawful duty to preserve a necessary care record and the child's own rights before deleting records or disclosing them to a person claiming to be a representative.
Cookies and Tracking
We use cookies and similar technologies to operate, secure, and improve our website and applications. Where applicable law requires prior consent for non-essential storage or access, that permission must be obtained before the activity occurs. A privacy notice or continued browsing is not a substitute. Our Cookie Policy explains the relevant technologies, choices, and current implementation limitations.
Strictly Necessary
Used where necessary for a requested function, such as authentication, security, or session management. Browser blocking remains possible but may prevent the function from working; not every useful preference qualifies as strictly necessary.
Functional
Where a surface offers preference controls, storage may remember a selected preference, such as a theme choice. The actual purposes and controls depend on that surface; disabling preference storage may affect those functions.
Analytics
Help us understand use of the website. The site includes Google Analytics when configured and Vercel Web Analytics. Non-essential collection remains subject to applicable consent or objection requirements; limited exemptions depend on the technology, purpose, safeguards, and jurisdiction.
You can manage cookies and other site storage through your browser settings. The public website currently lacks an on-site consent/preference centre, and its Google Analytics loader does not itself check a consent choice, “Do Not Track”, or Global Privacy Control before loading when configured. These are implementation gaps, not a waiver of your choices or of any obligation to recognize applicable opt-out signals. Required controls must be in place before affected collection is enabled in a jurisdiction that requires them. Contact Section 12 for a manual privacy request; email does not provide an instant browser-level blocking mechanism.
Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we make changes:
- • Notice: Material changes will be communicated via email or in-app notification at least 30 days before they take effect
- • Effective date: The “Last updated” date at the top of this Policy will be revised
- • Version control: The most current version will always be posted at this URL; previous versions are available on request
- • No automatic new permissions: Continued use after an update does not supply a separately required consent or authorize incompatible new uses of previously collected information. Any required fresh notice, consent, or customer instruction must be addressed before the changed processing begins
If you object to changes, you may contact us to exercise the applicable rights described in Section 8, discontinue use, or request deletion subject to lawful retention obligations. A notice update does not extinguish those rights. New vendors, additional data categories, or expanded AI purposes must also be assessed against the existing permissions and applicable customer agreements; a revised date alone does not resolve those requirements.
Contact Information
If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact our Data Protection team:
johnny@tourist-sos.com
For all privacy inquiries
Phone
+1 619 865 0445
Business hours support
Mailing Address
Tourist SOS LLC
401 Ryland Street, Ste 200A
Reno, NV 89502, USA
Response Timeline
We acknowledge privacy-related inquiries within 5 business days and provide a substantive response within 30 calendar days. If additional time is needed, we will notify you of the reason for the delay. For urgent data-protection matters, please call our phone support line during business hours (Monday–Friday, 9:00 AM – 5:00 PM PT).
Related documents: See our Terms of Service (including Section 5 on AI-Powered Assistance) and our Medical Disclaimer for additional context on how the platform operates.