We have written five posts this year about five apparently unrelated bills. Delivery app commission. OTA commission. Ordering websites. Booking engines and channel managers. What custom software costs. Five different flavours of one thing: vendor lock-in.
Different industries, different numbers, different readers. And underneath every one of them, the same conversation, almost word for word:
"So if I stopped using them tomorrow, what would I actually have?"
Usually a pause. Then: less than they thought.
This post is that question, asked properly, across everything a small UK business rents. Vendor lock-in is the polite name for it, and it is rarely a clause anyone signed. It is not an argument for leaving anyone. Most of these suppliers are worth paying. It is an argument for knowing what you are holding — because the moment you find out is always the worst possible moment to find out.
The vendor lock-in test
One question, applied to every supplier you have:
If this relationship ended on Friday, what leaves with me?
Not "would I be annoyed". Not "is it good value". What, specifically, in a format I could use, would still be mine on Monday morning.
Three things qualify. The customers — names, contact details, order or stay history, permission to contact them. The thing itself — the code, the design, the content, the configuration you paid for. And the switch — whether leaving is a decision or a project.
Almost every supplier scores well on one of these and badly on the others. The ones that score badly on all three are not necessarily bad suppliers. They are just suppliers whose interests stop matching yours precisely when you want to go.
Run it across the five.
1. The delivery app: you are renting the diner
A takeaway on Just Eat pays 14% plus VAT to deliver its own orders and 30% plus VAT when the platform delivers. Uber Eats publishes 13% and 30%. Deliveroo publishes nothing, and operator-reported figures cluster between 25% and 35%. We did that arithmetic properly in the commission post, and the conclusion stands: against a 3–12% net margin, the platform is not taking a share of your profit, it is taking a multiple of it.
But the commission is the part everyone can see, and it is not the part that traps you.
What leaves with you: the food. That is roughly it. The customer who has ordered your chicken shawarma every Friday for three years is, in every commercial sense, the platform's customer. You have their first name and a delivery postcode. You do not have a marketing permission, an email address you may use, or any way to tell them you have moved premises.
Five years of trading and every repeat order — someone who needed no discovery whatsoever — still arrives through the toll booth. That is not a pricing problem. That is a data ownership problem wearing a pricing problem’s clothes. Vendor lock-in almost always arrives dressed as something else.
Exit questions: What customer data does my agreement entitle me to, in writing? Am I permitted to market to people who found me through the app? If I switch off tomorrow, is there any list at all?
2. The OTA: you are renting the guest, and it is now explicit
Hotels get the sharper version of the same thing, and unusually, the platform states it outright.
Booking.com's guidance to partners is unambiguous: "To protect your and your guests' privacy, we don't share private email addresses. Both you and your guests will only ever see an anonymous alias." Partners are told to "use only the platform, extranet and Pulse app to continue communicating with your guests securely."
Read that as an operator rather than as a lawyer. The couple who come the same week every August, request the same room and send you a Christmas card — you do not have their email address. You have an alias that routes through a company charging you 17–22% all-in (the OTA commission breakdown is here). If your PMS syncs those aliases over profiles that once held real addresses, you have not just failed to gain a guest list. You have overwritten one.
This is also why the parity question matters and why we keep flagging it. The EU's Digital Markets Act pushed Booking.com off parity clauses, and its own wording is explicitly limited to partners in the European Economic Area. The UK is not in the EEA. UK operators who assume parity is dead because they read a headline about Brussels are assuming something about a contract they have not opened.
What leaves with you: the beds. And whatever email addresses you personally collected at check-in, which is the entire reason to bother collecting them.
Exit questions: Do I hold a real, permissioned email address for every guest who has stayed? Is my PMS overwriting them? Does my contract restrict what I offer on my own site — and is that restriction actually still in force here?
3. The plumbing: you are renting the pipes, and they are not the storefront
This one is subtler because nobody is taking a percentage. A channel manager, a PMS, an EPOS, an ordering platform — you pay a monthly fee, everyone is polite, and the vendor lock-in is structural rather than commercial.
We wrote about it as a diagnosis problem: a channel manager will never win you a direct booking, because it is not for that, and operators routinely blame the wrong box. The ownership question sits one layer beneath that. Your availability, rates, restrictions, menu, modifier logic, opening hours, tax rules — the configuration that took someone eleven months of small corrections to get right — lives inside a product you do not control.
Nobody thinks of that as data. It is the single most expensive thing to rebuild.
What leaves with you: in the good cases, a CSV. In the common case, a screenshot and a memory.
Exit questions: Can I export the configuration, not just the records? Can I get historical bookings or orders out, with line detail, without asking for a favour? Is there a documented API I could use to leave, or only one to arrive?
4. The software you paid to build: you may not own it
Here is the one that surprises people who have done everything else right.
Under UK law the author of a work is the first owner of copyright in it (Copyright, Designs and Patents Act 1988, s.11(1)). There is an exception where the work is made by an employee in the course of employment (s.11(2)). Your development agency is not your employee. Neither is your freelancer. And copyright does not move because you paid the invoice: "an assignment of copyright is not effective unless it is in writing signed by or on behalf of the assignor" (s.90(3)).
So unless the contract contains a written, signed assignment, the default position is that the supplier owns the software you commissioned. You have a licence. It is the quietest vendor lock-in on this list. That is a perfectly workable arrangement right up until you want to change supplier, sell the business, or survive due diligence.
We covered how this sits inside the wider question of what a build costs in the pricing post. Standing alone, it is the cheapest thing on this page to fix and the most expensive to discover late.
What leaves with you: whatever the assignment clause says, and nothing else.
Exit questions: Is there an assignment clause, in writing, covering source code, designs and documentation — not just "the deliverables"? Is it conditional on anything other than final payment? Which components are open-source or third-party licensed, and therefore not the supplier's to give? And do I have the repository, the infrastructure accounts and the domains in my own name today?
5. The AI vendor: you are renting the switch
The newest shape of vendor lock-in, and the one where the sales process is least mature.
The commercial questions are the ordinary ones — does it pay for itself, can you tell whether it is working. The ownership question is specific: what happens to your data on the way through, and what happens to you if the price triples.
Three things worth pinning down in writing, because they are rarely volunteered. Whether your inputs and outputs are used to train anything. Whether you can extract the accumulated material — the prompts, the labelled examples, the corrections your staff have fed it for eighteen months, which is the actual asset. And whether the thing is architected such that swapping the underlying model is a config change or a rebuild.
We wrote about the data-ownership side of AI integration separately. The short version is that the model is a commodity and the accumulated context is not, so the vendor who holds the context holds you.
Exit questions: Is my data used for training, and can I turn that off? Can I export the prompts, fine-tuning sets and corrections? Is the model swappable? What is the notice period, and what does it cost to be told the price has changed?
The law is not going to rescue you
Two reasonable-sounding assumptions about vendor lock-in, both wrong for a UK small business.
"GDPR means I can demand my customer data back." No. The right to data portability under Article 20 belongs to the individual, not to you. The ICO’s framing is that it "allows individuals to obtain and reuse their personal data for their own purposes across different services", it applies only where the lawful basis is consent or performance of a contract, only to automated processing, and only to information "of the individual that they have provided" — expressly excluding data the organisation derived. Your diner could ask Deliveroo for their own order history. You cannot ask on their behalf, and your commercial interest in the list is not a data protection right. The lever is the contract. It has always been the contract.
"The new switching rules cover me." The EU Data Act’s cloud-switching provisions have applied since 12 September 2025, with all switching charges prohibited outright from 12 January 2027, a maximum two-month notice period and a 30-day transition. It is a genuinely useful piece of regulation. It applies to providers serving customers in the EU. A UK business buying a UK or US service for UK use is not covered by it, in the same way UK hotels are not covered by the DMA parity change. Twice now, the protection everyone has read about stops at a border we are on the wrong side of.
Which leaves exactly one instrument against vendor lock-in. The thing you sign before you start.
What good looks like
None of this means running everything yourself. That is the other expensive mistake, and we would be arguing against our own advice — we tell restaurants to keep the apps for discovery and hotels to keep the OTAs for the billboard effect, because both of those are real services worth paying for.
The pattern that avoids vendor lock-in is narrower than "own everything":
Rent discovery. Own the relationship. Pay the platform to find people. Do not pay it in perpetuity to talk to people it already found. Collect the email at check-in, put the card in the bag, give staff one sentence to say at handover.
Own the identifiers, always. Domain, DNS, repository, cloud accounts, payment gateway, analytics — in your name, on your card, with you as the account owner. A supplier can have access. A supplier should not have possession.
Ask the exit question during the sales process, when you have leverage, not during the argument, when you have none. How the answer is delivered tells you as much as the answer.
Write down what you would need on the Monday. For each supplier, one line. If you cannot fill it in, that is the finding.
A supplier who welcomes these questions is telling you something. So is one who does not, at no charge.
The short version
Five bills, one question, and five different shapes of vendor lock-in. The delivery apps rent you the diner. The OTAs rent you the guest and now say so in writing. The plumbing rents you a configuration that took a year to get right. The development agency may, by legal default, own the software you paid for. The AI vendor holds the context that makes the model useful.
GDPR portability is your customer's right, not yours. The EU switching rules stop at the Channel. Neither will help you, and neither was ever going to.
What is left is the contract, and the four minutes it takes to ask what happens on Friday.
Not sure what your contracts actually say? We build custom software for UK hospitality and food businesses, and we run our own products — which means we have been the buyer in every one of these situations as well as the supplier. Happy to look over an agreement you have been sent, including one from someone else. See what we've built, or tell us what you're trying to do.
Related reading: How much commission do Deliveroo and Just Eat actually charge? · How much commission do Booking.com and Expedia charge? · A channel manager will never win you a direct booking · Nobody can price your software from a blog post




