Product Identity··14 min read

Who Owns Your Product Data When You Switch Platforms?

Featured image for Who Owns Your Product Data When You Switch Platforms?

Who Owns Your Product Data When You Switch Platforms?

Suppose you've been paying a QR platform a hefty monthly fee for three years. Millions of scans. Hundreds of thousands of warranty registrations. A rich trail of customer behavior mapped to individual serialized products. Then the platform raises its prices sharply, and you start shopping for alternatives.

That's when you discover the trap.

Your QR codes don't point to your domain. They point to theirs. Your scan history lives in their database, not yours. Your warranty registrations are formatted in a proprietary schema they control. Export your data? Sure, you can get a CSV. But what you can't get is your product identities, the persistent, scannable connection between a physical product and a digital experience. Those die the moment you cancel.

You don't own your product data. You rent it.

This is one of the least-discussed risks in connected product strategy, and it has the potential to become a crisis. As more manufacturers tie revenue, compliance, and customer relationships to digital product identity, the question of who actually controls that data isn't academic. It's existential.


The Anatomy of the Lock-In Problem

To understand why this happens, you need to understand how most QR and connected product platforms actually work.

When you sign up for a typical QR code platform, here's what you're actually getting:

  • A redirect service: Your QR code encodes a URL on the vendor's domain (e.g., scan.vendorplatform.com/abc123). When someone scans it, their servers receive the request, log the scan, and redirect the user to your content.
  • A hosted content layer: The product page, warranty form, or support guide lives on their servers, styled with their tools.
  • A proprietary data silo: Every scan, every registration, every support interaction is captured in their database in their schema.

The QR code printed on your product, the one that shipped in millions of boxes and will be scanned for years to come, is a permanent pointer to infrastructure you don't control.

Cancel your contract, and that pointer breaks. Your customers scan a dead code. Your warranty registrations are stranded. Your product history is held hostage.

The Warranty Registration Double-Bind

The lock-in problem is even sharper for warranty and service data. When a customer registers a product, that record contains:

  • Proof of purchase and purchase date
  • Customer contact details
  • Serial number and product configuration
  • Scan history and support interactions
  • Jurisdiction-specific warranty entitlement

This isn't generic CRM data you can migrate to a new tool with a CSV import. It's structured product identity data that only makes sense in the context of your product catalog, your SKUs, your serial number ranges. When platforms store this in proprietary schemas, exporting it doesn't mean you can use it. You can read it, but you can't operate it anywhere else without rebuilding from scratch.

Consider a hypothetical power tools manufacturer trying to migrate a large back-catalogue of warranty records from a legacy platform before its contract expires. If the old codes are still in the field and can't be deactivated, the manufacturer can end up running both systems in parallel, paying twice, with no clean way out. That's the shape the problem tends to take.


Two Models of Product Identity: Vendor-Owned vs. Brand-Owned

The distinction that matters here isn't which platform has better features or better pricing. It's a more fundamental architectural question: does the identity live on your infrastructure or theirs?

Vendor-Owned Identity (the default)

In the vendor-owned model:

  • The QR code URL is on the vendor's domain
  • The resolver (the logic that decides where to send a scan) lives on vendor servers
  • The product identity record is stored in a proprietary format
  • You access your data through the vendor's API, on their terms
  • If the vendor goes out of business, raises prices, or changes terms, your product data is at risk

This is the model many connected product platforms operate today, including a range of QR code management tools, warranty platforms, and aftermarket engagement tools. It's the path of least resistance. It's also a long-term liability that compounds with every product you ship.

Brand-Owned Identity (the GS1 Digital Link model)

GS1 Digital Link is a standard maintained by GS1 that defines how product identifiers, such as GTINs, serial numbers, and batch codes, can be encoded in a URL and resolved to digital content. You can read the specification directly at GS1's standards site.

The critical difference: the resolver lives at your domain.

A GS1 Digital Link URL looks like this:

https://www.brandedmark.com/01/05012345678900/21/SN-8823441

That URL is structured around your GTIN and your serial number. It resolves through your infrastructure (or infrastructure you control). The QR code printed on your product points to you, not a third party.

When a GS1 Digital Link-compliant QR code is scanned:

  1. The scanner hits your domain (or your CDN endpoint)
  2. Your resolver logic decides what to show (customer experience, EU DPP, regulatory data, etc.)
  3. The interaction is logged to your data store
  4. You can change the underlying platform without changing the code on the product

This is the architectural difference between owning your product identity and renting it. GS1 Digital Link is not a premium feature, it's an open standard. And it was designed in part to address the kind of vendor lock-in problem described above.


What to Ask a Vendor Before You Sign

If you're evaluating a connected product platform, warranty management tool, or QR code system, these questions should be non-negotiable before any contract discussion.

On Data Ownership

"If we cancel, can we export all scan history, customer records, and product identity data in a machine-readable, portable format?"

Acceptable answer: Yes, via API or full database export, in a documented schema, with no time limit.

Watch out for: "We can export to CSV" (often missing structured relationships), a short post-cancellation availability window (a hostage clause), or evasiveness about schema documentation.

"Do you store our product data in a proprietary schema, or do you support open standards like GS1 Digital Link?"

This question reveals whether the platform was architecturally designed for portability or for lock-in.

On QR Code Portability

"Do our QR codes resolve through your domain, or can we configure them to resolve through ours?"

If codes resolve through their domain, you cannot migrate without reprinting. For products already in the field, reprinting is not an option. Those codes are permanent.

"Is GS1 Digital Link encoding supported for our product QR codes?"

GS1 Digital Link support means your codes carry structured, standards-based identifiers that any compliant resolver can interpret. This is the baseline requirement for true portability.

On Exit Terms

"What is the data retention policy after contract termination?"

Some contracts give you a fixed window. Others are indefinite. Know this before you have a large field population of serialized products.

"Is there a data export fee?"

Some platforms charge for bulk data exports, effectively a ransom. This is in the contract. Read it.


The EU Digital Product Passport Changes the Stakes

If you're a manufacturer selling into EU markets, the data ownership question isn't just a commercial risk. It's a compliance risk.

The EU Digital Product Passport (DPP) is introduced under the Ecodesign for Sustainable Products Regulation (ESPR). The regulation is designed to make product-specific data accessible across a product's lifecycle, and it is being rolled out by product category over time. You can read the European Commission's overview at the ESPR page.

A key implication is that the company managing a product's digital identity may not always be the original manufacturer. Products change hands. Companies get acquired. Platforms shut down.

The practical takeaway is straightforward: product identity records are far more durable when stored in a format that is portable, standards-based, and not dependent on a single vendor's infrastructure remaining operational.

If your product data lives exclusively in a proprietary platform and that platform closes or is acquired, you may find it harder to keep meeting your DPP obligations for products already in the field.

GS1 Digital Link can contribute to meeting these requirements, because it provides a standards-based way to identify products across their lifecycle regardless of which software manages them.


The Hidden Cost of Switching Is Already Paid

Here's the part of the lock-in calculation that most manufacturers miss: the switching cost isn't paid when you decide to leave. It's paid when you sign up with a vendor-owned platform.

Every product you ship with a vendor-domain QR code is a commitment to that vendor for the life of that product, not just the duration of your contract. A dishwasher shipped today may be in service for many years. An industrial pump, longer still. The QR code on that product needs to resolve to useful digital content for as long as the product exists.

When you sign up with a vendor-owned platform, you're implicitly agreeing to either stay with them indefinitely or accept that the codes on all products currently in the field will eventually break.

That's the lock-in. And unlike software lock-in, where you can migrate your data and move on, connected product lock-in is physical. It's printed on your products. It's in the field. It cannot be undone.

This is exactly the dynamic explored in our analysis of QR code expiration and platform dependency. Dead codes don't just frustrate customers. They signal that your brand doesn't maintain its commitments. And for products in regulated industries, dead compliance codes can create genuine legal exposure.

The true cost of connected product platform switching includes not just migration fees and re-implementation time. It includes the lasting cost of broken codes on every product you shipped during the lock-in period.


Standards-Based Identity Is the Only Path to True Ownership

The summary of everything above is this: if your product's digital identity depends on a vendor's infrastructure staying operational and keeping your business as a customer, you don't own your product data. You have a lease on it.

True product data ownership requires:

  1. QR codes that resolve through your domain (or a domain you control independently of any single vendor)
  2. GS1 Digital Link-compliant encoding so your identifiers are structured, portable, and standards-based
  3. Data stored in documented, portable schemas with export rights that survive contract termination
  4. No dependency on a single vendor's resolver remaining online for codes already in the field

This isn't about being anti-platform. Platforms provide enormous value, such as experience builders, analytics, compliance tools, and workflow automation. The distinction is between platforms that sit on top of your product identity (and can be swapped out) versus platforms that are your product identity (and cannot).

The former is a vendor relationship. The latter is a dependency.


What Brand-Owned Identity Looks Like in Practice

When product identity is built on open standards, the operational model looks fundamentally different:

  • A new product is assigned a GTIN plus serial number at the time of manufacture, encoded in a GS1 Digital Link QR code pointing to your domain
  • The resolver at your domain handles scan requests, routing to the appropriate experience (consumer onboarding, EU DPP data, regulator view, service portal)
  • Customer interactions, such as warranty registrations, support sessions, and scan events, are logged to your data infrastructure
  • If you change the platform managing the experience layer, the codes in the field continue to work, because they point to your domain, not the platform's
  • Product data is yours by architecture, not by contract clause

This is the model BrandedMark is built on. GS1 Digital Link and EU DPP support are part of the core architecture, not add-on features, because we believe product identity belongs to the brand, not the platform. Your scan data, your warranty records, your customer relationships: they should live in infrastructure that follows your business decisions, not constrain them.

For manufacturers thinking about first-party data strategy for connected packaging, this architectural choice is foundational. You can't build a first-party data asset on infrastructure you don't control.

And for teams thinking about connected product security, the domain ownership question matters for more than portability. Vendor-domain codes can also be a vector for supply chain and spoofing attacks that brand-owned resolvers can help mitigate by design.


The Question to Ask Today

You may not be thinking about switching platforms right now. But ask yourself one question:

If your current QR code or connected product platform ceased to exist tomorrow, what would happen to every product you've shipped in the last several years?

If the honest answer is "our codes would break and our customer data would be inaccessible," that's not a platform feature gap. It's a structural problem with how your product identity is architected.

The time to solve it is before you're negotiating an exit.

GS1 Digital Link was designed by an industry standards body specifically to answer this kind of question. It exists because the connected product ecosystem recognized that proprietary lock-in at the identity layer was a risk. The standard is mature and widely supported.

Building on it isn't only a technical choice. It's a business decision about whether your product data belongs to your company, or to whoever printed the QR redirect.


FAQ: Product Data Ownership

What does "GS1 Digital Link" actually mean for my products?

Your QR code encodes your GTIN (Global Trade Item Number) and serial number in a standardized URL format. When someone scans it, the scan hits your domain (or your CDN), which you control. You decide what to show, how to log it, and where the data goes. This is different from proprietary platforms, where the scan hits their servers, gets logged to their database, and you see only what they allow you to see.

If we switch platforms, can we keep using our old QR codes?

Yes, if they're GS1 Digital Link-compliant and resolve through your domain. Your old codes point to your resolver. Your resolver logic can change (you swap out the underlying platform), but the codes remain valid. With vendor-owned codes, switching means reprinting everything already in the field, which is often impractical at scale.

What's our liability if a platform goes out of business?

With vendor-owned platforms: codes can become dead links, warranty data may be inaccessible, and you have limited recourse. With brand-owned (GS1 DL) identity: codes still resolve through your infrastructure. You can migrate the backend platform, but customers scanning in the field see no change. The data is yours, so continuity is preserved.

Does GS1 Digital Link cost more than proprietary QR platforms?

Not inherently. The choice between vendor lock-in and standards-based portability is not primarily a cost trade-off; it's a structural architecture decision. You're choosing between renting your product identity or owning it. The risk profiles differ even where pricing is similar.

How does this change under EU Digital Product Passport requirements?

The ESPR framework is designed to keep product data accessible across platform changes, vendor transitions, and company acquisitions. GS1 Digital Link is one standards-based mechanism that can support this. If your product identity lives in a proprietary platform and that platform shuts down, you may find it harder to fulfill your DPP obligations for products already in the field.


BrandedMark is built on GS1 Digital Link and EU Digital Product Passport standards from the ground up. Product identities resolve through your domain. Scan data, warranty records, and customer interactions are yours. If you're evaluating connected product platforms and want to understand what brand-owned identity looks like in practice, explore a live product experience or get in touch.

See how BrandedMark handles this

Turn every post-purchase moment into an opportunity to build loyalty and drive revenue.

See the product identity platform