For years, everyone in advertising braced for the death of the third-party cookie, the tracking file that follows you around the internet and helps companies target ads. Then it didn’t happen. Google decided in 2024 to keep third-party cookies in its Chrome browser after all and confirmed in 2025 that it wasn’t changing course.
So why does it feel like the ground shifted anyway?
Because it did. Other browsers like Safari and Firefox have blocked that kind of tracking for years, so a big share of the internet was already invisible to it. Businesses now compete hardest over first-party data, the customer information they collect directly through their own app, website, loyalty program or checkout counter. It’s far more valuable than third-party cookie tracking because the business knows who the customer is and what they bought, instead of guessing.
That raises a question that franchises have mostly avoided: in a franchise, who actually owns the customer?
So who owns customer data in a franchise? Legally it depends on the franchise agreement, but in practice the franchisor usually controls the central systems that hold the data, while the franchisee owns the direct customer relationship. When the contract is vague, both sides claim the same customer, and that gap is where disputes and legal risk begin.
Think about where the information lives. In most franchise brands today, the customer signs up through something the franchisor controls: the national app, the website, the rewards program. The point is to keep everything consistent and in one place.
But the franchisee is the one who actually met that customer. They ran the local event, answered the phone, did the in-home estimate, rang them up at the register. To them, that customer list is the heart of their business, and a big part of what it’s worth if they ever sell.
So, you have two parties, both sure the same customer is theirs. The franchisor sees the combined list as a company asset, and in franchising that data can be worth as much as the brand itself. The franchisee sees a relationship they built by hand. Usually the contract decides who’s right, and a lot of franchise contracts were written before any of this mattered. Many are vague, giving the franchisor sweeping rights to “all data” without spelling out who can use it for what or what happens when the franchisee leaves.
There’s a catch worth knowing. Lawyers have warned that if a contract forces a departing owner to hand all their customer information back to the franchisor, that very clause can be used as proof that the franchisor “controls” the franchisee’s business, which can make the parent company legally responsible for things it would rather not be. The clause meant to protect the brand can end up enlarging its risk.
This stopped being theoretical for Marriott. Between 2014 and 2018, attackers sat undetected inside a Starwood guest reservation database that Marriott took over when it bought the Starwood hotel group in 2016. By the time anyone noticed, around 339 million guest records had been exposed worldwide, including millions of passport numbers. In 2024, to settle the case, Marriott agreed to pay $52 million to a coalition of nearly every U.S. state, overhaul its security and let customers ask to have their data deleted and stolen loyalty points restored.
Here’s the part every franchise should sit with. Marriott is one of the world’s largest hotel brands, and much of its network is independently owned and operated. But the reservation system and the loyalty program are central systems the brand runs for everyone. So when guest data spilled, regulators didn’t go chasing individual hotel owners. They held the brand at the top responsible for the system it controlled.
That’s the direction many franchise brands are heading as they pull everyone’s customer data into one central system. The lesson isn’t “don’t centralize.” Bringing customer data together is often the right move. It’s that whoever runs that central system owns the responsibility of protecting it, no matter how many independent owners operate under the brand.
And the rules keep tightening. More than 20 U.S. states now have their own consumer privacy laws, each a little different. Customers don’t see the difference between the franchisor and a franchise location, so one mistake at a single location can become a black eye for the whole brand.
The brands handling this well have stopped treating customer information as territory to fight over and started treating it as something to share on clear terms. In plain terms, that means three things:
The payoff isn’t just staying out of trouble. It’s ending the constant argument over whether the leads the franchisor sends are any good, which is the quiet source of a lot of friction.
The cookie reprieve bought time, not a free pass. If your franchise still runs on a contract written before any of this mattered, start here:
The third-party cookie got a stay of execution. The franchise data question didn’t. Whoever owns the customer in your system, make sure it’s written down and that you can stand behind it when someone official asks.