Trust, Security & Privacy

This page is maintained by the team behind The CPAP Guide to answer common security and privacy questions about this site. It describes the controls and practices currently in place. It is editable content owned by us — not an independent audit or certification.

What this site does

The CPAP Guide is a landing page for the book The CPAP Guide by Daniel Marabita. Visitors can read information about the book, submit a contact / enquiry form, and request a free sample chapter by email.

What data we collect

  • Enquiry form: the name, email, and message you submit. These are delivered to us through a third-party form provider (Formspree) so we can reply.
  • Free chapter signup: your email address (and first name, if you provide it) so we can send the chapter and follow-up emails about the book.
  • Analytics: we use Google Analytics to understand aggregate site usage (pages viewed, approximate location, device type). We do not use it to build advertising profiles.

How we use your data

We use the information you submit to respond to your enquiry or to send you the material you requested. We do not sell your personal data. We do not share it with third parties except the service providers listed below, who process it on our behalf.

Service providers we rely on

  • Lovable Cloud — application hosting and managed database. Data in transit is protected with TLS. Database access is restricted via row-level security policies, and administrative credentials are held server-side only.
  • Formspree — handles delivery of enquiry-form submissions to our inbox.
  • Google Analytics — aggregate site analytics.

These providers operate under their own privacy and security terms. We share with them only the data needed for the service they provide.

Platform security controls in place

  • All traffic to this site is served over HTTPS / TLS.
  • Secrets (API keys, database credentials) used by the backend are stored server-side and are not shipped to the browser.
  • Database tables are protected by row-level security, with privileged operations restricted to server-side service roles.
  • Form inputs are validated server-side before being stored or forwarded to providers.

These are the application-level controls we have enabled. They are not a substitute for a formal certification such as SOC 2, ISO 27001, HIPAA, or GDPR audit, and this page should not be read as claiming any such certification.

Cookies

We use a small number of cookies, primarily set by Google Analytics for aggregate measurement. We do not use cookies for cross-site advertising.

Data retention and deletion

We keep enquiry messages and mailing-list contacts for as long as we need them to respond to you and to operate the mailing list. You can ask us to delete your data at any time using the contact address below; we will action the request within a reasonable timeframe.

Your privacy rights

Depending on where you live, you may have rights to access, correct, or delete the personal data we hold about you, and to unsubscribe from marketing emails at any time via the link in those emails. To exercise these rights, email us at the address below.

Reporting a security issue

If you believe you have found a security or privacy issue with this site, please email hello@thecpap.guide with details so we can investigate. Please give us a reasonable opportunity to respond before any public disclosure.

Contact

For any privacy, security, or data-handling question, contact hello@thecpap.guide.

Last updated: June 2026. This page is maintained by the site owner and may be revised as our practices change.