Privacy Policy

20 Studio

Effective 9 September 2026 · Version 3

The short version: this site keeps the message you send through the contact form, so we can reply. It also counts visitors with Google Analytics — but only if you say yes, and nothing at all is loaded from Google until you do. Say no, or send nothing, and we hold nothing of yours. The rest of this page is the same thing in more detail.

One boundary first: this page is about 20.studio only. The label's site, 20studiorecords.com, has its own policy. And when you listen on Spotify, Apple Music, TIDAL or anywhere else, those services collect data under their own policies — that part is between you and them.

Who is behind this

The person responsible for your data here is Tharin Karnjanapong (ธรินทร์ กาญจนพงษ์), who runs 20 Studio, a music studio in Bangkok, and the label 20studio Records. "20 Studio" is a trading name, not a registered company.

You can find us at 49/49 Soi Vibhavadi Rangsit 64, Yaek 19, Vibhavadi Rangsit Road, Talat Bang Khen, Lak Si, Bangkok 10210, Thailand — and for anything about your data, the direct line is privacy@20.studio.

What we keep, why, and for how long

Thailand's data-protection law (the PDPA) is the law behind this page, so the table names the legal ground for each item — but the plain reading is the middle two columns: what it is for, and when it is gone.

WhatWhat it is forLegal ground (PDPA)When it is gone
Name, email, subject and message from the contact formSo we can read your note and write backTaking steps at your request; our legitimate interest in running the studio24 months after your last message
The IP address and time recorded with that messageSpotting abuse of the formLegitimate interest in keeping our systems safeSame 24 months, kept with the message
Standard web-server logs — IP, time, page, browser, referrerKeeping the site up and secureLegitimate interest; legal obligationTwo months at most: logs archive daily, and last month's archives are deleted at each month's end. No other copy exists
A short log line when the form's hidden anti-spam field is filled in — IP address and browser string, never anything you typedTelling a bot apart from a personLegitimate interest in keeping the form usableWith the server logs above, two months at most
A rate-limit file holding your IP address as a one-way hash, with the times you submittedStopping the form being flooded — five submissions an hourLegitimate interest in keeping our systems safeCleared with the server's temporary files; entries older than an hour are ignored
Cookie identifiers and usage data, once you accept (next section)Counting visitors and understanding how the site is usedYour consentEvent data 2 months; visitor-level data 14 months from your last visit

Nothing here is required of you. Skip the form and the site works exactly the same.

We do not sell personal data. There are no social-media pixels, no advertising, and no visitor profiling of any kind.

Cookies

The site needs no cookies to work, so there are no "strictly necessary" ones. There are exactly two, both from Google Analytics, and both only after you agree:

CookieWhat it doesHow long it lives
_gaTells one browser apart from anotherabout 13 months
_ga_C5F5WDBLBMKeeps the analytics session togetherabout 13 months

When the analytics tag loads, your IP address and browser details reach Google too.

Nothing from Google is fetched before you answer. This is worth stating plainly because most sites cannot: the usual arrangement loads Google's script immediately and then asks it not to count you. Here the script is not requested at all until you press Accept.

Measured on 9 September 2026 in two real browsers: before answering — 0 cookies, 0 requests to Google. After Decline — 0 cookies, 0 requests to Google. After Accept — the two cookies above, and the tag loads.

Changed your mind? The cookie-settings link at the bottom of the page reopens the choice — declining switches the cookies off and deletes them. The change works from that moment on; it cannot rewind counting that already happened while you had said yes.

One honest technical note. Your answer is remembered in your own browser's local storage, under the key 20st.consent. It holds the answer, a format version and the date — nothing that identifies you — and it never leaves your device. It expires after twelve months, so you are asked again rather than held to a decision you made a year ago.

And one thing this site deliberately does not do. Google's instructions include a <noscript> fallback that tags visitors who have JavaScript turned off. We do not ship it. The consent question is asked in JavaScript, so those visitors could never be asked and never answer — tagging them anyway would be collecting from exactly the people with no way to refuse. They are not counted.

Who else sees anything

WhoWhat reaches themWhy
Namecheap, Inc., 4600 E Washington St, Suite 300, Phoenix, AZ 85034, United StatesServer logs; contact emails in transit and in the mailboxThey host the site and the mailbox
Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, United StatesAnalytics data and IP address — only if you said yesThey run the analytics

Beyond those two, we pass data to no one, except where the law requires it.

Your data crosses the ocean

The server lives in Los Angeles and both companies above are American, so what little we hold is stored and processed outside Thailand. What protects it there is those providers' own data-protection commitments — Namecheap's policy commits to standard contractual clauses for transfers, and Google Analytics runs under Google's data-processing terms. And as always: decline, and Google gets nothing.

Your rights — and they are real

The PDPA gives you proper rights over anything we hold about you. Ask what we have and get a copy. Have it corrected. Have it deleted or anonymised. Have its use paused. Take it with you. Object to the things we do on the "legitimate interest" ground. And withdraw consent whenever you like.

Just write to privacy@20.studio — a plain email is enough, no form needed. We answer within 30 days. We may first verify your identity before acting.

Security, kids, and changes

The site runs over HTTPS, everything the form accepts is checked and size-limited, submissions are rate-limited per IP address, and the page ships a full set of security headers — HSTS, a Content-Security-Policy, nosniff, Referrer-Policy and Permissions-Policy. No system is perfectly secure.

This site isn't aimed at children, and we don't knowingly keep personal data from anyone under 20 — the age of majority in Thailand. Where the PDPA wants a parent or guardian's consent for a minor, that is whose consent counts. If you think a minor has sent us something, tell us and it's gone.

When this page changes, the date at the top changes with it.

Back to the site