Privacy Policy
OnTheList.Live is not open yet. Two pages here do anything: a Preview list, and a fit questionnaire you can take without joining anything. This policy covers what those two pages do with information about you. There is no product behind them yet, so there is nothing else for it to cover.
Who is responsible
Moretime.ai Inc., a Texas corporation, is the controller of the personal data described here. OnTheList.Live is one of its products; its main site is moretime.ai. Write to hi@moretime.ai about anything on this page. Your use of the site is also covered by our Terms of Use.
There is no data protection officer, and no representative appointed in the EU or the UK. One email address is the whole contact surface.
What this site does not do
This site sets no cookies of its own. It writes nothing to local storage or session storage. There is no consent banner because, until you fill in a form, there is nothing to consent to.
There is no login, no account, no tracking pixel, no advertising network, no tag manager, no CRM, no session recording and no chat widget. Your email address is not sold, rented, or shared for anyone else's marketing.
The scorecard runs in your browser
The fifteen statements on the Sponsorship Board Fit Scorecard are scored by JavaScript on the page in front of you. Nothing is sent anywhere while you answer, and your result appears before you are asked for an email address. You can take it, read the result, and leave.
If you then choose to join the list, your answers go with it, and the database works out the same score and band again from them. So once you submit, we hold your answers and your result. Before you submit, we hold neither.
What is stored when you submit a form
A sponsor submits a name, an email address, and a role. A host submits those plus the questionnaire. This is the whole record — nothing is gathered in the background to go with it.
| What | The fields | Where it comes from |
|---|---|---|
| Who you are | Full name, email address | You type them. The address is lowercased and trimmed before it is stored, so one address is one record. |
| Which side you are on | Role: host, sponsor, or both | You choose it. If you come back on the other side later, the two are merged into one record marked both. |
| Your questionnaire answers | The fifteen statements, each scored 0, 1 or 2, plus two eligibility statements you either agree with or do not | You answer them. Hosts only. They are self-assessments about your audience and your business, not anything measured. |
| Profile context | Audience size as a number, and your category in up to 120 characters | You type them. Hosts only. Audience size is context and is deliberately not part of your score. |
| The record of the submission | When you submitted, which form you were on, when the record was created, and the version of this policy in force where it is recorded | Generated at the moment you press the button. |
| What we work out from it | Total score, fit band, and a status of NEW, INVITED or DECLINED | Not submitted by you. Score and band are computed by the database from your answers. Status is set by us, by hand, and never by you. |
The record holds no IP address and no user agent. Neither is sent by the form and there is nowhere in the table for them. The companies that host the site and run the database see connection details in the ordinary course of answering a request — that is described under Who else handles it.
Why we hold it, and what allows us to
The list: your consent
You submit a form to be told about a small number of things, and the record is used for those things only:
- to tell you when your side of OnTheList.Live opens;
- to tell you when Board Fit Review applications open;
- to assess whether you are a fit for the pilot, if you are a host;
- to email you your result and the next steps for your band, if you completed the questionnaire.
Not a newsletter. Not general marketing. Not passed to anyone else. There is no consent checkbox on either form: pressing the button is the act of consent, and the record notes the moment you did it and which form you were on.
You can withdraw consent at any time by emailing hi@moretime.ai. Withdrawing it stops any future use and does not make what came before it unlawful.
Fit and status: how a decision is actually made
A host's total and band are worked out automatically, by the same rule your browser used. Nothing follows from that number on its own. An invitation or a decline is a decision a person makes and records by hand, and joining the list does not entitle anyone to a place in the pilot.
Running and protecting the site: legitimate interests
Serving a page and connecting to a database produce logs at the companies that do those things — an address, a timestamp, what was asked for. We do not pull those into the record above and we do not use them to build a picture of you. Keeping a site reachable and able to survive abuse is a real interest, the data involved is minimal and held by the providers under their own retention, and it is what anyone would expect a website to need. That is the balance we have struck. If you think it comes out differently for you, object at hi@moretime.ai.
Who else handles it
Four companies are involved. There are no others.
- Vercel hosts the site. Every page you load is a request to Vercel's servers, which receive it in order to answer it and keep operational logs of that under their own retention.
- Supabase runs the PostgreSQL database that holds the record above, in its West US (Oregon) region. Reaching a database is also a request, and Supabase keeps its own infrastructure logs of those connections.
- Cloudflare runs Turnstile, the check that tells a person from a script on the two forms. It loads on the pages that carry a form, so those page loads send your IP address to Cloudflare whether or not you go on to submit anything. We send it nothing about you beyond what the check itself needs.
- Resend sends the one email this site sends. If you join the list from the questionnaire, we email you your result and the next steps for your band — nothing else. Resend receives the address it goes to and the message itself, in order to deliver it.
Page-view counts
This site uses Vercel Web Analytics to count page views. According to Vercel's own documentation, it uses no third-party cookies; a visitor is identified by a hash created from the incoming request, and the visitor session built from that hash is discarded after 24 hours. It is designed to produce aggregated counts rather than anything tied to a person.
Vercel's documentation lists what may be stored with each data point: a timestamp, the URL and its filtered query string, the referring page, geolocation to city level, operating system and version, browser and version, device type, and the version of the analytics script. The URL matters here because the sign-up form routes hosts to the questionnaire with the role in the address — so the side you picked can appear in that URL. No name, email address, or questionnaire answer is ever sent to it.
The basis is legitimate interests: we want to know how many people reach the questionnaire and how many finish it. Without a cookie, without an identifier that outlives a day, and without anything tied back to the record above, that is a light touch on you and a real need for us. Vercel's account of it is at vercel.com/docs/analytics/privacy-policy. Object at hi@moretime.ai.
Where the data goes
The record itself is in the United States. Moretime.ai Inc. is a Texas corporation, and Vercel, Supabase and Resend are United States companies; the database sits in Supabase's West US (Oregon) region. There is no copy of the record in the UK or the European Economic Area.
Cloudflare is the exception, and in your favour: it answers the bot check from whichever of its locations is nearest you, so if you are in Europe that request is likely answered in Europe. It is also the one thing here that sees you before you submit anything — but all it gets is the check itself.
So if you are in the UK or the EEA, submitting a form sends your data to a United States company directly. That is the whole journey rather than a step in it — nothing is moved out of a European system, because it was never in one. What happens after that is Vercel, Supabase and Resend handling it inside the US under their own data processing terms. Ask at hi@moretime.ai if you want the specifics for your case.
How long it is kept
Being honest about this: no deletion schedule is set, because the product it belongs to does not exist yet. The commitment instead is concrete. We keep your record until the Preview list is retired or until you ask us to remove it, whichever comes first. Ask at hi@moretime.ai and the record is deleted.
When a schedule is set, it goes in this policy and the version at the top goes up.
Your rights, and the one way to use them
You can ask us to:
- tell you what we hold about you, and give you a copy;
- correct anything wrong in it;
- delete it;
- stop using it, or withdraw the consent you gave by submitting the form;
- object to the processing we do on legitimate interests;
- hand you a machine-readable copy to take somewhere else.
Every one of these goes through one route: email hi@moretime.ai. There is no self-serve export, no account to log into, no deletion button, and no unsubscribe link — because there is no account system, and the one email described above is sent because you asked for it rather than as a list you could leave. Requests are handled by hand. Writing from the address on the record is normally enough to identify you, and we will not charge you for it.
You can also complain to the data protection authority for the country you live in. We would rather you wrote to us first, but you do not have to.
How the record is protected
Your browser never talks to the database and carries no key of any kind. An earlier version of this site put a publishable one in the page source; that is gone. A form posts to this site's own server, which holds the only credential and is the only thing that can write. The database refuses that path to everyone else, and refuses it in the database rather than in the page, so it holds however the request is made.
What the server may write is constrained too: it calls one function, that function only writes and returns nothing, and where a record already exists the stored answers win over the submitted ones. So a request that somehow got through still could not read the list, and could not overwrite what someone else told us.
Everything is served over HTTPS. Apart from Supabase as the database host, only the people running OnTheList.Live read the table.
Not for under-18s
This site is for people running or sponsoring a business audience. It is not directed at children, and you should not use it or join the list if you are under 18. If you think someone under 18 has joined, write to hi@moretime.ai and the record will be deleted.
Changes to this policy
The version number and date at the top of this page are how you tell one version from another. If what is collected changes, or why it is collected changes, the version goes up. If a change materially affects people already on the list, we will tell them by email rather than only editing this page.
Contact
hi@moretime.ai, for every question, request, objection, and complaint on this page. It is read by the people who run OnTheList.Live, and answered by hand.