The A List Portal
Privacy policy
Effective September 30, 2026
The A List Portal is a private workspace for the staff of The A List and the people it invites. It is not open to the public. This policy explains what the portal learns about a person who signs in, and what it does with it.
Who can sign in
Only a person an administrator has already added to the portal can sign in. Signing in with a Google account does not create an account: an address the portal does not know is turned away.
What the portal receives from Google
The portal uses Sign in with Google to check who you are. It asks Google for the basic sign-in details only:
- your email address, and Google's confirmation that it is verified;
- your name;
- the identifier Google's sign-in service gives your account.
The portal does not ask for access to your Gmail, Drive, Calendar, contacts or any other Google data, and it does not keep your Google profile picture.
How that information is used
- To match you to the person an administrator added, and to refuse anyone else.
- To keep you signed in for the working day, through a session cookie that ends after twelve hours, or sooner if you sign out or are idle.
- To show your name beside the work you do in the portal, and to keep a record of that work for the company's own audit.
It is used for nothing else. It is not used for advertising, and it is not used to develop or train artificial-intelligence models.
Where it is kept
The portal runs on Google Cloud in the United States. Your email address and name are stored in the portal's database there, with its backups. Sign-in itself is handled by Google's own identity services.
Who it is shared with
Nobody outside the company and the people who run the portal for it. It is never sold. Google Cloud processes it on the company's behalf, as the service the portal runs on.
How long it is kept
Your record is kept for as long as you have access to the portal. When you leave, an administrator disables it, which ends every session at once. The record of work done in the portal is kept after that as part of the company's audit trail.
Your choices
You can ask what the portal holds about you, ask for it to be corrected, or ask for it to be removed, by writing to the address below. You can also withdraw the portal's access to your Google sign-in details at any time from your Google account's security settings.
Google's policy
The portal's use of information received from Google's services follows the Google API Services User Data Policy, including its Limited Use requirements.
Cookies
The portal sets the cookies it needs to keep you signed in. It sets no advertising or tracking cookies.
Changes
If this policy changes, the new version is posted here with its date.
Contact
Questions about this policy go to matt@commitfoundry.com.