Lightrider logo

Privacy Policy


Last updated: 2026-08-05


Light Rider Inc. ("we," "us," or "our") operates Light Rider Cloud (the "Service"), a software-as-a-service platform available at platform.lightriderinc.com. This Privacy Policy explains how we collect, use, disclose, and protect your personal information, and describes the rights available to you under the EU/UK General Data Protection Regulation ("GDPR") and the California Consumer Privacy Act, as amended by the California Privacy Rights Act ("CCPA").


By using the Service, you acknowledge the practices described in this Policy. If you do not agree, please do not use the Service.


1. Who We Are (Data Controller)

Light Rider Inc. is the data controller responsible for your personal information.


Contact details:


Light Rider Inc.

5825 University Research Ct Suite 2000, College Park

MD 20740

Columbia, Maryland

United States


E-mail: info@lightriderinc.com


2. Personal Information We Collect

CategoryExamplesSource
Account & identity dataName, email address, username. Your password and any multi-factor authentication setup are managed by our identity provider, Logto — we never store your password.Provided directly by you (via Logto)
API keysA hashed value of any API key you generate for programmatic access — we never store the plaintext keyGenerated by you within the Service
Payment & billing dataBilling name/address, payment card token, subscription plan, transaction and credit-usage historyYou / our payment processor (we do not store full card numbers)
Service usage dataQuantum job submissions (backend/provider selected, shot count, computed cost, job status) and other in-product activity tied to your accountAutomatically generated as you use the Service
Device & technical dataIP address, operating system, browser type, device identifiers, referring URLs, and standard server/access logsAutomatically collected
Location dataApproximate location inferred from your IP addressAutomatically collected
CommunicationsSupport requests, correspondence, and sales inquiries (e.g. company name, use case, and deployment details submitted through our Contact Sales form)Provided directly by you

Sensitive information: We do not intentionally collect special-category data (e.g. health or biometric data) unless you voluntarily provide it (for example, in a support request) or applicable law defines a category of data we process as sensitive. Where we do, we rely on your explicit consent.


3. How We Use Personal Information

  • Provide, operate, and maintain the Service and your account
  • Process payments and manage subscriptions/billing
  • Monitor, analyze, and improve the performance, security, and usability of the Service, based on server/access logs (we do not use third-party analytics or tracking tools)
  • Provide customer support and respond to inquiries
  • Send service-related communications (e.g. security alerts, billing notices)
  • Send marketing communications where you have opted in (you may opt out at any time)
  • Detect, investigate, and prevent fraud, abuse, and security incidents
  • Comply with legal obligations and enforce our Terms of Service

Legal bases for processing (GDPR)

PurposeLegal basis
Providing the Service you signed up forPerformance of a contract
Billing and payment processingPerformance of a contract / legal obligation
Service monitoring and improvement (via server/access logs)Legitimate interests
Marketing communicationsConsent
Security monitoring and fraud preventionLegitimate interests / legal obligation
Responding to legal requestsLegal obligation

4. Cookies and Similar Technologies

We only use strictly necessary cookies and similar technologies (such as local storage) that are essential for the core functionality and security of the Service. In practice, this means a session cookie set by our identity provider, Logto, to keep you signed in, and local storage used only to remember non-identifying UI preferences (e.g. dashboard view settings, onboarding progress). We do not use third-party analytics, tracking, or advertising cookies. Because we only use essential cookies, we do not use a cookie consent banner. You can instruct your browser to refuse all cookies or to indicate when a cookie is being sent, but please note that some parts of the Service may not function properly if you disable essential cookies.


5. How We Share Personal Information

We do not sell personal information for money, and we do not share personal information with third parties for cross-context behavioral advertising, as those terms are defined under the CCPA.

We disclose personal information only to:

  • Service providers/processors acting on our behalf under contract, such as cloud hosting providers, our identity provider (Logto), and our payment processor — solely to help us operate the Service
  • Quantum computing backend providers (e.g. IQM, Rigetti, IBM Quantum) and our entropy-source provider, solely to execute the quantum jobs you submit. We send only the parameters needed to run your job (such as the circuit definition, shot count, and backend selection) — never your name, email address, or billing information
  • Professional advisors (legal, accounting) as needed
  • Authorities where required by law, regulation, or legal process
  • Successors in connection with a merger, acquisition, or asset sale, subject to standard confidentiality obligations

We require our service providers to protect personal information and to use it only for the purposes we specify, consistent with our contractual and legal obligations (including CCPA service-provider requirements and GDPR Article 28 data processing terms).


6. International Data Transfers

If we transfer personal information from the EEA, UK, or Switzerland to a country not deemed to provide an adequate level of protection, we rely on appropriate safeguards, such as the European Commission's Standard Contractual Clauses or the UK International Data Transfer Addendum, together with supplementary measures as needed.


7. Data Retention

We retain personal information for as long as necessary to provide the Service, comply with legal obligations, resolve disputes, and enforce agreements. Retention periods vary by data type — for example, account data is retained while your account is active plus 2 years afterward; technical and log data (e.g. IP addresses, server/access logs) is retained for a shorter period, typically no more than 12 months, unless a longer period is needed for security investigations or legal compliance. When no longer needed, data is securely deleted or anonymized.


8. Your Privacy Rights

If you are in the EEA, UK, or Switzerland (GDPR)

You have the right to:

  • Access the personal information we hold about you
  • Rectify inaccurate or incomplete data
  • Erase your data ("right to be forgotten"), subject to certain exceptions
  • Restrict or object to certain processing, including profiling and direct marketing
  • Data portability — receive your data in a structured, machine-readable format
  • Withdraw consent at any time, where processing is based on consent
  • Lodge a complaint with your local supervisory authority

If you are a California resident (CCPA/CPRA)

You have the right to:

  • Know what personal information we collect, use, disclose, and (if applicable) sell or share, and to request a copy of the specific pieces collected
  • Delete personal information we've collected, subject to certain exceptions
  • Correct inaccurate personal information
  • Opt out of sale or sharing of personal information — not applicable, as we do not sell or share personal information
  • Limit use of sensitive personal information — not applicable, as we do not use sensitive personal information beyond what is necessary to provide the Service
  • Non-discrimination for exercising any of these rights
  • Designate an authorized agent to submit requests on your behalf

Categories of personal information collected/disclosed in the past 12 months (CCPA categories): Identifiers (name, email, IP address); customer records (e.g. payment info, billing history); internet/network activity (device and log data); geolocation data (approximate); commercial information (transaction and credit-usage history); and professional information you provide through our Contact Sales form (company name, use case, deployment details). Disclosed only to service providers as described in Section 5 — not sold or shared.


How to exercise your rights

Submit a request to info@lightriderinc.com or via Contact form. We will verify your identity before fulfilling requests and will respond within the timeframes required by applicable law (generally 30 days for GDPR, 45 days for CCPA).


9. Children's Privacy

The Service is not directed to children under 16, and we do not knowingly collect personal information from them. If you believe a child has provided us information, contact us so we can delete it.


10. Security

We implement technical and organizational measures — including encryption in transit, access controls, and regular security reviews — designed to protect personal information. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.


11. Changes to This Policy

We may update this Policy from time to time. We will post the revised version with an updated "Last updated" date and, where changes are material, provide additional notice (e.g. email or in-product notification).


12. Contact Us

Questions about this Policy or our data practices? Contact us at info@lightriderinc.com.