Legal
Privacy Policy
Last updated
This Privacy Policy describes how Lightnit collects, uses, discloses and protects personal information in connection with the Lightnit automation platform.
01Scope and Roles
1.1Introduction
Lightnit (“Lightnit”, “we”, “us” or “our”) provides a cloud automation platform, available at lightnit.com, through which business customers build automated workflows. Each workflow is a “Nit”, which receives an event through a Spark (an inbound webhook or a manual run), evaluates an optional Filter (conditions applied to the incoming data) and executes a Bolt (an action such as an HTTP POST request, a Discord message, a Google Sheets row or a Gmail message).
This Privacy Policy (this “Policy”) describes how Lightnit collects, uses, discloses, retains and protects personal information in connection with the Lightnit website, dashboard, webhook endpoints, application programming interfaces and related services (collectively, the “Service”).
1.2Definitions
“Customer” or “you” means the individual or entity that registers for and uses the Service, including the individuals who access the Service on that entity’s behalf. “Account Data” means personal information relating to a Customer’s account, including registration, authentication, subscription and support information. “Customer Data” means all data that a Customer submits to the Service or routes through its Nits, including webhook payloads and request metadata, Nit configuration, and the execution logs and Bolt responses generated from them.
1.3Lightnit as Controller
Lightnit acts as a controller, and as a “business” under applicable United States state privacy laws, with respect to Account Data and the technical data described in Section 2, which Lightnit processes for the purposes set out in Section 3.
1.4Lightnit as Processor
Lightnit acts as a processor, and as a “service provider” or “processor” under applicable United States state privacy laws, with respect to Customer Data. Lightnit processes Customer Data solely on behalf of the Customer and in accordance with the Customer’s instructions, as expressed through the Customer’s configuration of its Nits and the Lightnit Terms of Service. The Customer is the controller of Customer Data and is responsible for providing all notices and obtaining all consents and authorizations required for its collection, use and transmission through the Service.
1.5Relationship to Other Terms
This Policy is incorporated into, and is to be read together with, the Lightnit Terms of Service. Individuals whose personal information is contained in Customer Data should direct privacy inquiries to the Customer that controls that data, as described in Section 10.
02Information We Collect
2.1Account Data
When you register, Lightnit collects your email address, an optional name and a password. Passwords are stored solely as bcrypt hashes and are never stored or viewable in plain text. Lightnit also maintains your account’s role, plan and creation date.
2.2Billing Information
Payments are processed by Stripe. Lightnit receives and stores your Stripe customer and subscription identifiers, the price and plan selected, the subscription status and the end date of the current billing period. Payment card details are submitted directly to Stripe; Lightnit never receives or stores full payment card numbers.
2.3Nit Configuration
Lightnit stores the configuration of each Nit, including its name and description, Filter conditions, destination URLs and Bolt settings such as spreadsheet identifiers, email recipients, message templates and custom request headers.
2.4Webhook Payloads and Execution Logs
For each execution, the Service records the trigger payload (truncated to 65,536 characters); the outcome of each Filter condition, including the value evaluated, together with the Bolt outcome and response (truncated to 16,384 characters in aggregate); the execution status; and the latency. These records enable Customers to monitor, debug and audit their automations.
2.5Webhook Request Metadata
Request headers and query parameters received with a webhook are made available to the Customer’s Filters and templates. Credential headers (including Cookie, Authorization and Proxy-Authorization), proxy and content delivery network routing headers, and client IP address headers are discarded on receipt and are never stored or made available to Nits.
2.6Usage Records
For each account, the Service maintains a count of billable executions for each UTC calendar month in order to meter plan quotas. Usage records contain no payload, response or configuration content.
2.7Google Account Data
If you connect a Google account, Lightnit receives the email address of that account and the OAuth access and refresh tokens issued by Google. Tokens are encrypted before storage. Section 5 governs Lightnit’s handling of Google user data.
2.8Technical Data
Client IP addresses are processed transiently in memory to enforce rate limits and are not written to Lightnit’s database. Lightnit’s hosting provider may maintain standard server access logs for security and operational purposes.
2.9Communications
When you contact Lightnit, Lightnit retains the correspondence and the contact information you provide in order to respond to and document your request.
03How We Use Information
3.1Purposes of Processing
Lightnit uses Account Data and technical data to:
- (a)provide, operate and maintain the Service, including authenticating users and administering accounts;
- (b)receive Sparks, evaluate Filters and execute Bolts in accordance with each Customer’s configuration;
- (c)display execution history, usage and plan entitlements in the dashboard;
- (d)process subscriptions, free trials, renewals and invoices through Stripe;
- (e)enforce rate limits and plan quotas, and detect, investigate and prevent fraud, abuse and security incidents;
- (f)communicate with Customers regarding their accounts, security matters and changes to the Service, the Terms of Service or this Policy; and
- (g)comply with applicable law and legal process, and establish, exercise or defend legal claims.
3.2Customer Data
Lightnit processes Customer Data only to provide the Service to the Customer that submitted it, in accordance with that Customer’s instructions, or as required by applicable law.
3.3Restrictions
Lightnit does not sell personal information, does not use personal information for targeted or cross-context behavioral advertising, and does not use Customer Data to develop or train artificial intelligence or machine learning models. Lightnit does not deploy third-party analytics, advertising or cross-site tracking technologies on the Service.
04Legal Bases for Processing (EEA and UK)
4.1Account Data
Where the EU General Data Protection Regulation or the UK General Data Protection Regulation applies, Lightnit processes Account Data on the following legal bases:
- (a)Performance of a contract: to create and administer your account, provide the Service and process your subscription;
- (b)Legitimate interests: to secure the Service, prevent fraud and abuse, enforce rate limits and communicate service-related information, where those interests are not overridden by your data protection rights;
- (c)Compliance with legal obligations: to meet tax, accounting and other statutory requirements and to respond to lawful requests from public authorities; and
- (d)Consent: where you have provided it, such as when you authorize Lightnit to access your Google account. You may withdraw consent at any time, without affecting the lawfulness of processing carried out before its withdrawal.
4.2Customer Data
The Customer, as controller, is responsible for determining and documenting the legal basis for the processing of Customer Data.
05Google User Data
5.1Scopes Requested
When you connect a Google account, Lightnit requests only the following scopes, each of which is used solely for the purpose described:
https://www.googleapis.com/auth/spreadsheets: to append rows to the spreadsheets you designate in Google Sheets Bolts.https://www.googleapis.com/auth/gmail.send: to send the email messages composed by your Gmail Bolts. This scope permits sending only and does not grant access to read, modify or delete mailbox content.openidandemail: to identify and display the connected Google account.
5.2Limited Use
Lightnit’s use and transfer to any other app of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. In particular, Google user data:
- (a)is used only to perform the Bolts you configure and to display your connected account, which are user-facing features of the Service;
- (b)is not transferred to third parties except as necessary to provide those features, to comply with applicable law, or as part of a merger, acquisition or sale of assets with your prior consent;
- (c)is not used or transferred to serve advertisements, including retargeting, personalized or interest-based advertising;
- (d)is not sold, and is not used or transferred to determine creditworthiness or for lending purposes;
- (e)is not used to develop, improve or train generalized artificial intelligence or machine learning models; and
- (f)is not read by any person except with your affirmative agreement for specific data, where necessary for security purposes such as investigating abuse, or to comply with applicable law.
5.3Storage, Disconnection and Revocation
Google OAuth tokens are encrypted at rest using AES-256-GCM and are decrypted only on Lightnit’s servers, solely to perform your Bolts and maintain the connection. You may disconnect your Google account at any time from Dashboard → Connections. Disconnecting revokes the token with Google and permanently deletes the stored credentials from the Service. You may also revoke Lightnit’s access at any time from your Google Account permissions page.
07Data Retention
7.1Execution Logs
Execution logs are retained for the execution history window included in the Customer’s current plan:
- Starter: 7 days
- Pro: 30 days
- Agency: 365 days
Execution logs older than the applicable window are excluded from the Service and are deleted by automated retention processes that run as the Customer’s Nits execute. Deleting a Nit permanently deletes its execution logs.
7.2Account Data, Configuration and Usage Records
Account Data, Nit configuration and monthly usage records are retained for as long as the account remains open. Google OAuth credentials are retained until the Customer disconnects the Google account or the account is closed.
7.3Account Closure
A Customer may request closure of its account by emailing support@lightnit.com from the email address associated with the account. Lightnit will delete the account and its associated Account Data, Customer Data, usage records and Google credentials within 30 days of verifying the request.
7.4Legal Retention
Lightnit may retain limited information beyond these periods where required to comply with legal, tax or accounting obligations, resolve disputes, prevent fraud or enforce its agreements. Billing and transaction records maintained by Stripe are retained in accordance with Stripe’s own legal obligations.
08Security
8.1Safeguards
Lightnit maintains administrative, technical and organizational measures designed to protect information against unauthorized access, disclosure, alteration and destruction, including:
- (a)Encryption at rest: platform API keys configured by administrators and all Google OAuth tokens are encrypted with AES-256-GCM authenticated encryption, using a unique random initialization vector for each value and associated data that binds each value to its purpose. Decrypted secrets are used only on Lightnit’s servers and are never returned to the browser.
- (b)Encryption in transit: connections to the Service are encrypted using HTTPS and enforced with HTTP Strict Transport Security (HSTS).
- (c)Credential protection: passwords are hashed with bcrypt, and authentication endpoints are rate limited to resist brute-force attempts.
- (d)Session security: sessions are signed tokens stored in HttpOnly, SameSite cookies transmitted only over secure connections, and state-changing requests are verified as same-origin.
- (e)Outbound request protection: Bolts are subject to server-side request forgery (SSRF) safeguards that block private, loopback, link-local and cloud metadata addresses over IPv4 and IPv6, and that revalidate each destination at connection time.
- (f)Access control: role-based access control restricts administrative functions to administrator accounts, and each Customer’s Nits, execution logs and connections are accessible only to that Customer’s account.
- (g)Abuse prevention: plan-based rate limits apply to webhook endpoints, and additional rate limits apply to authentication and manual execution endpoints.
No method of transmission over the internet or of electronic storage is completely secure, and Lightnit cannot guarantee the absolute security of information.
8.2Customer Responsibilities
Customers are responsible for maintaining the confidentiality of their account credentials and webhook URLs, which authorize the triggering of Nits, and for configuring Nits to transmit only data that is appropriate for the selected destinations.
8.3Security Incidents
Lightnit will notify affected Customers of a security incident involving their personal information without undue delay and in accordance with applicable law.
09International Data Transfers
9.1Cross-Border Processing
Lightnit and its service providers may process and store information in countries other than the country in which it was collected, including the United States. These countries may have data protection laws that differ from those of your jurisdiction.
9.2Transfer Safeguards
Where personal information originating in the European Economic Area, the United Kingdom or Switzerland is transferred to a country that has not been recognized as providing an adequate level of protection, Lightnit relies on appropriate safeguards, such as the European Commission’s Standard Contractual Clauses and the UK International Data Transfer Addendum, as incorporated into the data processing terms of its service providers.
10Your Rights and Choices
10.1Data Protection Rights
Depending on your jurisdiction, and subject to applicable exceptions, you may have the right to:
- (a)access the personal information Lightnit holds about you and obtain information about how it is processed;
- (b)correct inaccurate or incomplete personal information;
- (c)delete your personal information;
- (d)receive your personal information in a structured, commonly used and machine-readable format and transmit it to another controller;
- (e)object to, or request the restriction of, processing based on legitimate interests;
- (f)withdraw consent at any time, where processing is based on consent; and
- (g)lodge a complaint with your local data protection supervisory authority.
10.2Account Controls
You may edit your Nits, or delete them together with their execution logs, from the dashboard; disconnect your Google account from Dashboard → Connections; and change or cancel your subscription in the Stripe customer portal, accessible from Dashboard → Billing.
10.3California Residents
If you are a California resident, the California Consumer Privacy Act, as amended (the “CCPA”), provides you with the right to know the categories and specific pieces of personal information Lightnit has collected about you; the right to delete and to correct personal information; the right to opt out of the sale or sharing of personal information; the right to limit the use of sensitive personal information; and the right not to receive discriminatory treatment for exercising these rights.
In the preceding twelve months, Lightnit has collected the following categories of personal information: identifiers (such as name, email address and IP address); customer records and commercial information (such as plan, subscription and billing identifiers); internet or other electronic network activity information (such as execution logs and usage records); and sensitive personal information limited to account login credentials. Lightnit collects this information from you, from your use of the Service, and from Stripe and Google; uses it for the business purposes described in Section 3; and discloses it for those business purposes only to the categories of recipients described in Section 6. Lightnit does not sell or share personal information and uses sensitive personal information only for purposes permitted by the CCPA, such as providing and securing the Service.
10.4Other United States Jurisdictions
Residents of other United States jurisdictions with comprehensive consumer privacy laws may have comparable rights, which Lightnit honors in accordance with applicable law.
10.5Exercising Your Rights
To exercise any of these rights, email support@lightnit.com. Lightnit verifies requests by confirming that they originate from, or are confirmed through, the email address associated with the relevant account, and may request additional information where necessary to verify your identity. You may designate an authorized agent to submit a request on your behalf by providing that agent with signed written permission, subject to verification. Lightnit will respond within the period required by applicable law. If Lightnit declines to act on a request, you may appeal the decision by replying to Lightnit’s response, and Lightnit will respond to the appeal within the period required by applicable law.
10.6Requests Concerning Customer Data
Where Lightnit processes personal information as a processor on behalf of a Customer, individuals should submit requests to that Customer. Lightnit will refer any such request it receives to the relevant Customer where the Customer can be identified, and will assist Customers in responding to such requests as required by applicable law.
12Children’s Privacy
The Service is intended for businesses and professionals and is not directed to children. Lightnit does not knowingly collect personal information from individuals under the age of 16. If Lightnit learns that it has collected personal information from a child under 16, it will delete that information promptly. Any person who believes that a child has provided personal information to Lightnit should contact support@lightnit.com.
13Changes to This Policy
Lightnit may update this Policy from time to time to reflect changes to the Service, its practices or applicable law. Lightnit will post the updated Policy on this page and revise the “Last updated” date above. Where changes are material, Lightnit will notify Customers by email or through the dashboard before the changes take effect. Continued use of the Service after an updated Policy takes effect constitutes acknowledgment of the updated Policy.
14Contact Us
Questions, requests and complaints concerning this Policy or Lightnit’s data practices may be directed to Lightnit at support@lightnit.com. Use of the Service is governed by the Lightnit Terms of Service.