{"route":"/privacy/","title":"Privacy","kind":"page","stage":null,"label":null,"html":"<p class=\"lead\"><em>The handbook is built to collect as little about you as the product allows.</em></p>\n<p>The Sleep Training Handbook does not run analytics, does not embed third-party tracking pixels, does not use behavioural advertising, does not fingerprint your device, and does not sell your data. There is no account, no password, no profile. This page explains the small amount of information that does pass through the system, who holds it, and what your rights are.</p>\n<h2 id=\"who-is-responsible-for-your-data\">Who is responsible for your data</h2>\n<p>Two parties act as data controllers for different parts of the relationship.</p>\n<p><strong>Peter Ngo</strong> is a UK sole trader operating from C/O DPC Stone House, 55 Stone Road Business Park, Stoke-On-Trent, ST4 6SR. The owner is data controller for the content-licence relationship and for any support correspondence you send to <strong>sleeptraininghandbook@gmail.com</strong>.</p>\n<p><strong>Lemon Squeezy</strong> is the Merchant of Record for the purchase. Your transaction is legally with Lemon Squeezy, not with the owner. Lemon Squeezy is data controller for everything they collect at checkout - your email, name, billing address, country/tax data, and payment details. Lemon Squeezy&#39;s privacy notice is at https://lemonsqueezy.com/privacy; any question about the transaction record itself should go there.</p>\n<p>This page is about the owner&#39;s side of the relationship.</p>\n<h2 id=\"what-the-owner-collects-directly\">What the owner collects directly</h2>\n<p>If you write to <strong>sleeptraininghandbook@gmail.com</strong>, the owner sees your email address and whatever you put in the message. That is the entire set. The owner has no CRM, no marketing list, no behaviour-tracking dashboard, and no database of buyers. The only direct, identifiable record of you on the owner&#39;s side is the support thread you start, if any.</p>\n<h2 id=\"what-the-site-does-not-do\">What the site does not do</h2>\n<p>No analytics on any page. No third-party scripts. No advertising or remarketing pixels. No fingerprinting. No tracking across other websites. No A/B testing that profiles readers. No use of reader behaviour to train machine-learning models. No newsletter, no marketing list, no automated emails after purchase beyond the receipt and access link Lemon Squeezy sends.</p>\n<p>If any of this ever changes, this page will be updated and the change flagged at the top for at least thirty days before it takes effect.</p>\n<h2 id=\"what-the-access-worker-logs\">What the access Worker logs</h2>\n<p>The gated reader sits behind a Cloudflare Worker that issues and checks the access cookie. The Worker logs only the event type (e.g. `order_created`) and the Lemon Squeezy order ID - no buyer email, name, IP, or token contents.</p>\n<p>Cloudflare itself keeps standard request logs (IP, timestamp, page) under their data processing terms, retained for a short period (typically 24 hours to 7 days). The owner does not export or mine these logs. Cloudflare&#39;s DPA: https://www.cloudflare.com/cloudflare-customer-dpa/.</p>\n<h2 id=\"on-your-device\">On your device</h2>\n<p>The handbook stores a small number of preferences in your browser&#39;s local storage (theme, font size, reading progress, the readiness-tally state, and a flag that you&#39;ve read the safety modal). None is transmitted to the owner, to Lemon Squeezy, or to anyone else. Clearing site data in your browser removes them.</p>\n<h2 id=\"cookies\">Cookies</h2>\n<p>The site sets one cookie: <strong>`psh-access`</strong>. It is set when you first visit the access link inside your Lemon Squeezy receipt. It contains a signed access token - a short opaque string. It does not contain your email, name, or payment data. Flags: `HttpOnly`, `Secure`, `SameSite=Lax`. Expiry: up to five years, refreshed each visit.</p>\n<p>The cookie&#39;s only job is to recognise you as a buyer so the gated reader unlocks. It is <strong>strictly necessary</strong> under UK PECR Regulation 6(4); strictly-necessary cookies don&#39;t require prior consent, which is why there is no cookie consent banner.</p>\n<p>No analytics cookies. No tracking cookies. No third-party cookies.</p>\n<h2 id=\"legal-basis-uk-gdpr-article-6\">Legal basis (UK GDPR Article 6)</h2>\n<p>The owner relies on two legal bases:</p>\n<ul><li><strong>Performance of a contract</strong> - the licence to read the handbook is between you and the owner; processing any data needed to deliver that licence (in practice, almost nothing) sits here.</li><li><strong>Legitimate interests</strong> - when you write in to support, the owner reads and replies. The legitimate interest is responding to your question.</li></ul>\n<p>No data is processed for direct marketing, profiling, or automated decision-making.</p>\n<h2 id=\"international-transfers\">International transfers</h2>\n<p>Lemon Squeezy stores buyer data per their published privacy notice. Cloudflare delivers the site from its global edge network. Google (Gmail) processes the support inbox. All three publish their UK GDPR / EU GDPR posture and the safeguards they rely on (adequacy decisions, Standard Contractual Clauses).</p>\n<h2 id=\"your-rights\">Your rights</h2>\n<p>Under UK GDPR you can ask for: <strong>access</strong> (a copy of the data the owner holds - in practice, just your support thread), <strong>rectification</strong>, <strong>erasure</strong>, <strong>restriction</strong>, <strong>portability</strong>, or <strong>objection</strong> to processing on legitimate-interests grounds.</p>\n<p>For transaction data - your receipt, billing address, refund record - direct the request to Lemon Squeezy via their privacy notice.</p>\n<p>Email <strong>sleeptraininghandbook@gmail.com</strong> from the address you wrote in from. The owner responds within thirty days (usually much sooner).</p>\n<h2 id=\"retention\">Retention</h2>\n<p>Support email threads: up to two years from the last reply, then deleted. Earlier deletion on request.</p>\n<p>Worker logs: per Cloudflare defaults (24 hours to 7 days).</p>\n<p>Transaction record: held by Lemon Squeezy under their retention policy.</p>\n<h2 id=\"children\">Children</h2>\n<p>The handbook is for parents and caregivers; the buyer is the adult. The owner does not knowingly collect data from children, and nothing on the site is directed at children.</p>\n<h2 id=\"security\">Security</h2>\n<p>Site served only over HTTPS. The access cookie is `HttpOnly` and `Secure`. The Worker verifies Lemon Squeezy webhook signatures before acting on payloads. No source maps published. No personal data in client-side JavaScript or in any URL beyond the time-limited access token in the receipt link.</p>\n<h2 id=\"complaints\">Complaints</h2>\n<p>Write first to <strong>sleeptraininghandbook@gmail.com</strong>. If unresolved, you can complain to a supervisory authority - UK buyers to the ICO at https://ico.org.uk/make-a-complaint/, EU buyers to their national DPA (list at https://edpb.europa.eu/about-edpb/about-edpb/members_en).</p>\n<h2 id=\"changes-to-this-policy\">Changes to this policy</h2>\n<p>Material changes will be summarised at the top of the page for at least thirty days. The &quot;last updated&quot; date below moves forward on each change.</p>\n<h2 id=\"not-medical-advice\">Not medical advice</h2>\n<p>Nothing on this page is medical advice. If something about your child&#39;s sleep is worrying you, please speak to your GP, health visitor, or paediatrician first. The full <a href=\"/safety/\">safety note</a> is always reachable.</p>\n<h2 id=\"contact\">Contact</h2>\n<ul><li><strong>Email:</strong> sleeptraininghandbook@gmail.com</li><li><strong>Post:</strong> Peter Ngo, C/O DPC Stone House, 55 Stone Road Business Park, Stoke-On-Trent, ST4 6SR</li></ul>\n<hr>\n<p class=\"lead\"><em>Last updated: 14 May 2026.</em></p>","prev":null,"next":null,"up":{"route":"/","title":"The Sleep Training Handbook"},"hubItems":null,"redirectTo":null}