Privacy Policy
Last updated: 2026-08-05
Light Rider Inc. ("we," "us," or "our") operates Light Rider Cloud (the "Service"), a software-as-a-service platform available at platform.lightriderinc.com. This Privacy Policy explains how we collect, use, disclose, and protect your personal information, and describes the rights available to you under the EU/UK General Data Protection Regulation ("GDPR") and the California Consumer Privacy Act, as amended by the California Privacy Rights Act ("CCPA").
By using the Service, you acknowledge the practices described in this Policy. If you do not agree, please do not use the Service.
1. Who We Are (Data Controller)
Light Rider Inc. is the data controller responsible for your personal information.
Contact details:
Light Rider Inc.
5825 University Research Ct Suite 2000, College Park
MD 20740
Columbia, Maryland
United States
E-mail: info@lightriderinc.com
2. Personal Information We Collect
| Category | Examples | Source |
|---|---|---|
| Account & identity data | Name, email address, username. Your password and any multi-factor authentication setup are managed by our identity provider, Logto — we never store your password. | Provided directly by you (via Logto) |
| API keys | A hashed value of any API key you generate for programmatic access — we never store the plaintext key | Generated by you within the Service |
| Payment & billing data | Billing name/address, payment card token, subscription plan, transaction and credit-usage history | You / our payment processor (we do not store full card numbers) |
| Service usage data | Quantum job submissions (backend/provider selected, shot count, computed cost, job status) and other in-product activity tied to your account | Automatically generated as you use the Service |
| Device & technical data | IP address, operating system, browser type, device identifiers, referring URLs, and standard server/access logs | Automatically collected |
| Location data | Approximate location inferred from your IP address | Automatically collected |
| Communications | Support requests, correspondence, and sales inquiries (e.g. company name, use case, and deployment details submitted through our Contact Sales form) | Provided directly by you |
Sensitive information: We do not intentionally collect special-category data (e.g. health or biometric data) unless you voluntarily provide it (for example, in a support request) or applicable law defines a category of data we process as sensitive. Where we do, we rely on your explicit consent.
3. How We Use Personal Information
- Provide, operate, and maintain the Service and your account
- Process payments and manage subscriptions/billing
- Monitor, analyze, and improve the performance, security, and usability of the Service, based on server/access logs (we do not use third-party analytics or tracking tools)
- Provide customer support and respond to inquiries
- Send service-related communications (e.g. security alerts, billing notices)
- Send marketing communications where you have opted in (you may opt out at any time)
- Detect, investigate, and prevent fraud, abuse, and security incidents
- Comply with legal obligations and enforce our Terms of Service
Legal bases for processing (GDPR)
| Purpose | Legal basis |
|---|---|
| Providing the Service you signed up for | Performance of a contract |
| Billing and payment processing | Performance of a contract / legal obligation |
| Service monitoring and improvement (via server/access logs) | Legitimate interests |
| Marketing communications | Consent |
| Security monitoring and fraud prevention | Legitimate interests / legal obligation |
| Responding to legal requests | Legal obligation |
4. Cookies and Similar Technologies
We only use strictly necessary cookies and similar technologies (such as local storage) that are essential for the core functionality and security of the Service. In practice, this means a session cookie set by our identity provider, Logto, to keep you signed in, and local storage used only to remember non-identifying UI preferences (e.g. dashboard view settings, onboarding progress). We do not use third-party analytics, tracking, or advertising cookies. Because we only use essential cookies, we do not use a cookie consent banner. You can instruct your browser to refuse all cookies or to indicate when a cookie is being sent, but please note that some parts of the Service may not function properly if you disable essential cookies.
5. How We Share Personal Information
We do not sell personal information for money, and we do not share personal information with third parties for cross-context behavioral advertising, as those terms are defined under the CCPA.
We disclose personal information only to:
- Service providers/processors acting on our behalf under contract, such as cloud hosting providers, our identity provider (Logto), and our payment processor — solely to help us operate the Service
- Quantum computing backend providers (e.g. IQM, Rigetti, IBM Quantum) and our entropy-source provider, solely to execute the quantum jobs you submit. We send only the parameters needed to run your job (such as the circuit definition, shot count, and backend selection) — never your name, email address, or billing information
- Professional advisors (legal, accounting) as needed
- Authorities where required by law, regulation, or legal process
- Successors in connection with a merger, acquisition, or asset sale, subject to standard confidentiality obligations
We require our service providers to protect personal information and to use it only for the purposes we specify, consistent with our contractual and legal obligations (including CCPA service-provider requirements and GDPR Article 28 data processing terms).
6. International Data Transfers
If we transfer personal information from the EEA, UK, or Switzerland to a country not deemed to provide an adequate level of protection, we rely on appropriate safeguards, such as the European Commission's Standard Contractual Clauses or the UK International Data Transfer Addendum, together with supplementary measures as needed.
7. Data Retention
We retain personal information for as long as necessary to provide the Service, comply with legal obligations, resolve disputes, and enforce agreements. Retention periods vary by data type — for example, account data is retained while your account is active plus 2 years afterward; technical and log data (e.g. IP addresses, server/access logs) is retained for a shorter period, typically no more than 12 months, unless a longer period is needed for security investigations or legal compliance. When no longer needed, data is securely deleted or anonymized.
8. Your Privacy Rights
If you are in the EEA, UK, or Switzerland (GDPR)
You have the right to:
- Access the personal information we hold about you
- Rectify inaccurate or incomplete data
- Erase your data ("right to be forgotten"), subject to certain exceptions
- Restrict or object to certain processing, including profiling and direct marketing
- Data portability — receive your data in a structured, machine-readable format
- Withdraw consent at any time, where processing is based on consent
- Lodge a complaint with your local supervisory authority
If you are a California resident (CCPA/CPRA)
You have the right to:
- Know what personal information we collect, use, disclose, and (if applicable) sell or share, and to request a copy of the specific pieces collected
- Delete personal information we've collected, subject to certain exceptions
- Correct inaccurate personal information
- Opt out of sale or sharing of personal information — not applicable, as we do not sell or share personal information
- Limit use of sensitive personal information — not applicable, as we do not use sensitive personal information beyond what is necessary to provide the Service
- Non-discrimination for exercising any of these rights
- Designate an authorized agent to submit requests on your behalf
Categories of personal information collected/disclosed in the past 12 months (CCPA categories): Identifiers (name, email, IP address); customer records (e.g. payment info, billing history); internet/network activity (device and log data); geolocation data (approximate); commercial information (transaction and credit-usage history); and professional information you provide through our Contact Sales form (company name, use case, deployment details). Disclosed only to service providers as described in Section 5 — not sold or shared.
How to exercise your rights
Submit a request to info@lightriderinc.com or via Contact form. We will verify your identity before fulfilling requests and will respond within the timeframes required by applicable law (generally 30 days for GDPR, 45 days for CCPA).
9. Children's Privacy
The Service is not directed to children under 16, and we do not knowingly collect personal information from them. If you believe a child has provided us information, contact us so we can delete it.
10. Security
We implement technical and organizational measures — including encryption in transit, access controls, and regular security reviews — designed to protect personal information. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
11. Changes to This Policy
We may update this Policy from time to time. We will post the revised version with an updated "Last updated" date and, where changes are material, provide additional notice (e.g. email or in-product notification).
12. Contact Us
Questions about this Policy or our data practices? Contact us at info@lightriderinc.com.