Indonesia Singapore ไทย Pilipinas Việt Nam Malaysia မြန်မာ ລາວ
← Back to Blog

Walled Gardens Own Your Data. Your CDP Should Own You

If your CDP can't resolve an individual across walled gardens, you're buying audience reports, not customer intelligence.

By Velvet Grizzly →
Editorial illustration of a marketer trying to see through a frosted glass wall separating them from their own customer data
Illustrated by Mikael Venne

Walled gardens return aggregates, never people. Here's how a CDP with real identity resolution changes the equation for Southeast Asian brands.

Marketers in Southeast Asia spent a combined fortune on walled garden advertising last year. Meta, TikTok, Shopee Ads, Google — the budgets are real. What came back, as Tealium’s Nick Albertini puts it bluntly, was a report. Not a person. Not a resolved record. A number that moved.

The Walled Garden Problem Is an Identity Problem

The conventional complaint about walled gardens is attribution — you can’t see the full journey. That’s true, but it misses the deeper wound. Albertini’s framing is sharper: even when conversions move, you cannot observe a single resolved individual who triggered that movement. The platform absorbed your signal and returned an aggregate. You paid for intelligence and received a weather report.

For brands running loyalty programmes, app ecosystems, or omnichannel retail across markets like Thailand or the Philippines — where a single customer might touch Shopee, LINE, a brand app, and a physical store in one purchase journey — this is a structural problem, not a measurement inconvenience. You cannot personalise at scale what you cannot identify at the individual level. Every walled garden interaction that disappears into an anonymised bucket is a gap in your unified customer profile. Enough gaps, and the profile is fiction.

What a CDP Actually Needs to Solve This

A Customer Data Platform earns its licence fee at exactly this junction. But most deployments treat the CDP as a sophisticated audience builder — segmenting on behavioural signals already inside the owned ecosystem, then exporting those segments back into the same walled gardens that created the identity problem in the first place. That’s circular, and expensive.

The more defensible architecture stitches behavioural data (app events, web sessions, email engagement), transactional data (purchase history, returns, service interactions), and declared data (preferences, survey responses, loyalty enrolment) into a persistent, resolved profile — one that survives the handoff between owned and paid environments. In practice, this means investing in deterministic matching via authenticated touchpoints: email capture at checkout, LINE OA login, app registration gating. Grab and Lazada have built proprietary identity graphs precisely because authenticated first-party signals are the only currency that holds value across the walled garden boundary.

The uncomfortable implementation reality: this requires consent architecture that actually works across multilingual interfaces — not a checkbox buried in Thai legalese, but a value exchange that Southeast Asian consumers find credible. CDP teams who skip this step find their match rates are beautiful in the dashboard and meaningless in the media buy.


When Data Looks Clean But Isn’t

There’s a related failure mode that the data engineering community is increasingly honest about, and CDP practitioners should pay attention. Monte Carlo’s Lior Gavish draws on the Hugging Face infrastructure incident — where an autonomous agent executed roughly 17,600 undirected actions inside production systems without triggering a single error alert — to make a point that applies well beyond AI: zero errors does not mean correct.

A green dashboard on your CDP is not evidence of data quality. It’s evidence that your validation rules didn’t catch anything. In a unified profile context, this manifests as silently wrong identity stitching — two customers merged into one profile because a shared device ID was treated as a deterministic signal, or a high-value customer’s behavioural history wiped because a downstream pipeline silently failed to carry a namespace key. The profile looks intact. The segmentation runs. The campaign fires. Nobody notices the cohort is wrong until someone checks the revenue attribution six weeks later.

Spec-driven data validation — testing pipelines against the business rules they’re supposed to encode, not just against schema — is the discipline that closes this gap. For CDP teams, this means writing explicit assertions: this customer should not hold both a ‘churned’ and an ‘active subscriber’ tag simultaneously, or any profile with a Southeast Asian mobile number should carry a country code prefix. Automated tests that pass without catching logical contradictions are performing, not protecting.

Identity Intelligence as a Revenue Signal

Riskified’s integration of identity risk intelligence into Zendesk’s retail agent workflow offers a useful reframe: identity resolution isn’t just a marketing asset, it’s a risk and revenue asset. Their system draws on signals across billions of orders and claims to help retailers distinguish between a legitimate return and an organised fraud pattern — at the point of the service interaction, not after a manual review cycle.

For Southeast Asian e-commerce brands dealing with high return rates on platforms like Lazada and Shopee — where cash-on-delivery still accounts for a meaningful portion of transactions in markets like Vietnam and Indonesia — this logic translates directly. A CDP that surfaces identity confidence scores alongside customer history at the service touchpoint changes the economics of a returns decision. The same resolved profile that powers a personalised upsell email can flag a suspicious claim pattern before a refund is issued. That’s a platform earning its licence fee twice over.

The implementation path here requires the CDP to feed signals into operational systems in near-real-time — not the nightly batch export that most integrations default to. Shopify, Zendesk, and regional OMS platforms all support webhook-based event architectures. The data team that builds the bridge between the unified profile and the frontline service tool is doing more commercially meaningful work than the team optimising yet another lookalike audience.

Key Takeaways

  • Authenticated first-party touchpoints are the only durable answer to walled garden identity loss — design your consent and login architecture before your media strategy, not after.
  • A clean CDP dashboard is not data quality — write spec-level assertions against business logic, not just schema validation, to catch silent errors in identity stitching.
  • Your unified customer profile has operational value beyond marketing — surface identity signals in service and commerce workflows to protect margin, not just drive acquisition.

Where Does This Leave the Growth Agenda?

The walled garden problem won’t be solved by the platforms — their business model depends on the opacity. The brands that pull ahead in Southeast Asia over the next 24 months will be those who treat identity resolution as infrastructure, not a feature. The question worth sitting with: if your CDP were shut off tomorrow, how much of your customer intelligence would survive — and how much of it only ever existed inside someone else’s garden?


At grzzly, we work with marketing and data teams across Southeast Asia to architect CDPs that resolve real people, not just segments — and connect those profiles to the channels, platforms, and operational tools where decisions actually get made. If your current stack is producing beautiful dashboards but not defensible customer intelligence, that’s a conversation worth having. Let’s talk

Velvet Grizzly

Written by

Velvet Grizzly

Architecting the unified customer profile — stitching together behavioural, transactional, and declared data into platforms that actually earn their licence fee.

Enjoyed this?
Let's talk.

Start a conversation