Privacy
Last updated 1 September 2026
The short version
This is a one-person studio. I collect what I need to talk to you and to build what you hired me to build, and nothing else. I do not sell anything about you, I do not trade it, and there is no advertising network on this site.
There are three ways your information reaches me, and they are genuinely different from each other, so this page treats them separately: you came to this site, I emailed you first, or we work together.
If you came to this site
These pages set no analytics cookies, no advertising cookies, and no cookies of any other kind. There is no tracking pixel, no session recorder, no Meta or Google tag, and no third-party script of any sort. Nothing about your visit is recorded beyond the ordinary server logs my host keeps to serve the page and keep the site up.
Booking a call hands you to Cal.com, which takes your name, email and chosen time under its own privacy policy. Emailing, calling or messaging me shares whatever you choose to put in the message.
If I emailed you first
I contact businesses I have not met — studios and clinics that fit the kind of work I do. Nobody enjoys getting an email they did not ask for, so here is exactly where the details came from and how to end it, without having to ask me.
What I hold about your business: its name, its public email address and phone number, its website, its address, its Google listing (rating, number of reviews, category, hours), the booking or scheduling software I could identify from the public pages of its own website, its public social profiles, and roughly when it last posted publicly.
Where it came from: public business listings on Google Maps, collected through a commercial crawling service, and your own public website. No purchased lists, no data brokers, no email-finding service that guesses addresses from a name, and nothing behind a login. Every field is something a person could have found by opening your listing and your site — I only did it at volume.
Why: to work out whether the thing I build would be any use to you, and to talk to you about your business specifically rather than read you a script with your name pasted in.
What happens next: a call, and at most four follow-ups across a DM, a text and two more calls, over twelve days. If you answer, it stops immediately — including an answer that says no. If you never answer, it ends on its own.
To be removed: say so — on the phone, by text, or in the DM. No form, no login, no reason needed. It stops everything on every channel immediately and permanently. You can also write to hello@21x.studio and I will confirm it is done. There is more detail on why you heard from me.
If we work together
Your business details, your booking rules, and the client and schedule data you ask me to migrate. That data is yours. I hold it to do the work, I do not use it for anything else, I do not use it to train anything, and you can ask for it back or ask me to delete it at any time.
Med spas and aesthetics practices: I build the booking layer only. I do not collect, process or store treatment records, clinical notes or patient health information, and you should not send me any. If your build needs to sit alongside a system that holds them, it stays alongside — the two do not mix.
The studio application is on a separate host, is private, and is used only by me. It sets one session cookie for sign-in. That cookie is strictly necessary, it does nothing else, and it is never set on the pages you are reading now.
Who else touches it
- Vercel — hosting for this site and the application.
- Supabase — the database, hosted in the United States.
- Google — Workspace, which carries my email and calendar.
- Resend — an alternative sending route for email.
- Apify — the crawling service that reads public Google Maps listings.
- Cal.com — scheduling, when you book a call.
- Stripe — payments. Card details go to Stripe directly; I never see them.
Each one is a supplier doing a job for me, not a party I have shared anything with for its own purposes. None of them is paid in data, and none of them is permitted to use yours for anything except the job.
How long I keep it
- Enquiries that go nowhere — deleted within a year.
- Businesses I contacted who did not become clients — deleted within two years of the last message.
- Unsubscribes and people who asked not to be contacted — the email address is kept indefinitely and on purpose, because it is the only way to guarantee you are never contacted again. It is used for nothing else, ever.
- Client records — kept while we work together, and afterwards for as long as tax and accounting rules require. Then deleted.
Your rights in California
California residents have the right to know what personal information I hold and where it came from, to have it corrected, to have it deleted, to opt out of its sale or sharing, and to not be treated worse for exercising any of those. These rights cover information about a business contact, not only a consumer — the exemption that used to carve business contacts out of California law expired at the start of 2023, and this policy is written on that basis.
I do not sell personal information and I do not share it for cross-context behavioural advertising. I never have. There is nothing to opt out of, which is why there is no “Do Not Sell” button on this site — a button that did nothing would be worse than saying so plainly. I also do not collect the categories California treats as sensitive.
To exercise any of these, write to hello@21x.studio. It reaches me, not a queue. You do not need to give a reason, there is no form, and I will answer within 45 days — usually the same week. If you are asking on someone’s behalf I will need something showing they asked you to.
Children
Nothing here is aimed at children and I do not knowingly collect anything about anyone under 16. If a client’s booking system handles minors — a parent booking for a child — that data belongs to the client, who is responsible for it, and I only process it on their instructions.
Keeping it safe
Data is encrypted in transit and at rest by the hosts above. Access is limited to me, protected by two-factor authentication. I am one person, not a security department, and I would rather say that than imply a certification I do not hold. If a breach ever affected your data, I would tell you directly and quickly, and I would tell you what I actually knew rather than waiting until the story was tidy.
Changes
If this policy changes materially while we are working together, I will tell you directly rather than quietly updating this page. The date at the top is the last time anything on it changed.
