Privacy
What we hold, and who can see it.
Market Run runs on a wholesaler's own book: their customers, their orders, their prices. This says what is held, why, who else touches it, and how one business's data is kept away from another's.
Last updated September 2026
1. Who we are
Market Run is a product of Titan Studio AI Ltd, registered in England and Wales, company number 17401869, Suite 23, Winsor & Newton Building, Whitefriars Avenue, Harrow, HA3 5RN, United Kingdom. Titan Studio AI Ltd is the data controller for this website and the data processor for everything inside a customer's Market Run system.
The distinction matters. Information about YOU, if you fill in a form on this site, is ours to look after. Information about a wholesaler's own customers, sitting inside their system, belongs to that wholesaler. We hold it and act on their instructions; we do not own it and we do not trade it.
2. What this website collects
If you send us a message: the name, email address and message you typed. Nothing else, and no tracking pixel.
If you sign in: a session cookie, so the next page knows it is still you.
There is no analytics on this site, no advertising network, no third-party tag and no cross-site tracking of any kind. See the cookies page.
3. What a Market Run system holds
For a wholesaler who uses the product, the system holds their trading data: their product catalogue and pack sizes, their customers and delivery addresses, contact names and phone numbers, order history, delivery rules, routes, vehicles and drivers, their cost prices and their selling prices, invoices and payments.
It also holds WhatsApp message content. Orders arrive as free text on WhatsApp, so reading and storing those messages is the product. A message is kept with the order it produced, so that any line can be traced back to the words that were actually sent. Messages that are not orders are still received by the same number and are stored the same way.
Photographs taken at a delivery - the goods and the delivery note - and a signature captured at the door, because that evidence is what an invoice is raised against.
4. How one business is fenced from another
Every table in the database carries the organisation it belongs to, and access is enforced at the database itself by row level security rather than by application code remembering to filter. A query made on behalf of one business cannot return another business's rows.
Cost prices are fenced more tightly still: they never leave the organisation that owns them - not to a customer, not to another wholesaler, not to anyone. There is an automated test in the codebase whose only job is to prove that.
We do not pool, aggregate, benchmark or resell one customer's trading data to another, and we do not use it to train models for anybody else.
5. Who else processes it
Only what the product needs to run, and each one only for its own part:
Supabase - database, authentication and file storage. Vercel - hosting for the web application. Railway - the services that do parsing, pricing, optimisation and routing. Anthropic - the model that reads WhatsApp messages and extracts order lines. Mapbox - geocoding and routing for delivery addresses. Resend - outbound email. Meta (WhatsApp Business API) and Twilio - inbound and outbound messaging. Xero - accounting, where a customer has connected it.
This list changes only when the product changes, and this page changes with it.
6. Lawful basis
For this website: your consent when you send us a message, and our legitimate interest in replying to it.
For a customer's system: we process on their instructions under a contract with them. Their own lawful basis for holding their customers' data is theirs, and we do not decide it for them.
7. How long it is kept
An enquiry sent through this website is kept while we are dealing with it and for as long afterwards as it is useful to remember the conversation. Ask and it is deleted.
Trading data inside a customer's system is kept while their account is open, because the whole point of the product is that four years of history is still there. When an account closes, their data is exported to them and removed on their instruction.
8. Your rights
Under UK GDPR you can ask what we hold about you, ask for it to be corrected, ask for it to be deleted, ask for a copy, or object to us holding it. Write to us and we will do it.
If the data you are asking about sits inside a wholesaler's Market Run system - if you are a restaurant they deliver to, for instance - then they are the controller and the request should go to them. Tell us and we will point you at them and help them answer it.
You can complain to the Information Commissioner's Office at ico.org.uk.
9. Security
Traffic is encrypted in transit. Data is encrypted at rest by the database provider. Access to production is limited to the people who build and run the system, and every no-login link we send a kitchen is scoped to that kitchen and expires.
No system is perfect, and we would rather say that than claim otherwise. If something goes wrong that affects your data, we will tell you.
10. Changes
If this policy changes in a way that matters, the date at the top changes and customers are told directly rather than left to notice.
Titan Studio AI Ltd, registered in England and Wales, company number 17401869, Suite 23, Winsor & Newton Building, Whitefriars Avenue, Harrow, HA3 5RN, United Kingdom. Get in touch.