Buyer guide
Choose a GS1 Digital Link platform on eleven things: how specifically it can describe its standards conformance, how its resolver behaves, whether you own the domain printed on the pack, what happens to your identifiers if you leave, which Application Identifiers it supports, whether routing can change without reprinting, how granular the analytics are, whether there is a real API into your PIM or ERP, where your data lives, how identity and access are handled, and what it gives your retail partners as they move to 2D scanning.
This guide is deliberately not a competitor comparison. Vendor feature sets and prices change faster than any page can track them, and a table of claims about other companies is worth less to you than a set of questions you can put to all of them. The checklist below is written to be lifted straight into an RFP.
Because part of it gets printed. Most software decisions are reversible at the cost of a migration project. This one puts a hostname onto physical packaging that may sit in a warehouse for a year and on shelf for longer, so the printed portion of the decision outlives the contract by design.
That asymmetry should drive the evaluation. Weight the criteria that are hard to reverse, meaning the domain and the identifiers, far above the ones you can change any afternoon, such as the appearance of a landing page. A platform with a plainer interface and a clean exit is a better long term position than a polished one that owns the string on your pack.
Ask which specific conformance requirements the resolver meets and against which version of the GS1 Digital Link standard, rather than accepting the phrase “GS1 compliant”. Compliance is not a single binary property, and the useful answer is a list of behaviours you can check.
GS1 Digital Link expresses GS1 identifiers as a web URI, and a resolver routes one identifier to different destinations depending on what the caller asks for. So the questions worth asking are about routing behaviour. What HTTP status codes come back. What happens when a caller requests a link type you have not registered anything for. Whether the registered links for an identifier can be enumerated by a machine rather than only viewed in a dashboard. Whether a URI carrying a qualifier such as batch resolves differently from the bare GTIN, and whether it falls back sensibly when it should not.
One more distinction is worth being precise about. Being listed in a GS1 member organisation directory as a solution provider is not certification or endorsement. Vendors word their GS1 relationship in different ways, and it is fair to ask each one exactly what their claimed relationship consists of.
You should, and this is the criterion to be least flexible on. The domain in a GS1 Digital Link URI is printed into the artwork, so if it belongs to the vendor, leaving the vendor means reprinting every pack.
The workable pattern is a subdomain of your own domain, for example scan.example.com, delegated by DNS to whichever platform resolves your codes today. The printed string stays constant across vendor changes because you control the DNS record that decides where it goes. Nothing in the standard requires a particular domain, since a GS1 Digital Link is defined by the syntax of its path rather than by who hosts the hostname, so any vendor refusing this is making a commercial choice rather than a technical one.
Ask the exit question before you sign, because that is the only moment you have leverage. Three parts matter: what you can export, in what format, and whether the printed URIs keep working.
Check for explicit support of the Application Identifiers you plan to print, not just the GTIN. GTIN is AI (01), batch or lot is (10), expiration date is (17) and serial number is (21), and platforms differ in how far past (01) they actually go.
There is a difference between accepting a qualifier and doing something with it. A platform can store a batch value and still route every scan of that product to the same page. What you want to confirm is that a URI carrying (10) can be routed and reported on separately from the bare GTIN, because that is the capability behind targeted recall messaging and run level analysis.
Match this to your category. Food and beverage tends to care about batch and expiry. Pharmaceutical and high value goods care about serialisation under (21). A general merchandise brand may genuinely need nothing past the GTIN, and paying for serialisation you will never apply is a real cost with no return.
This is the core value of resolution, and it should be a plain yes. The printed symbol holds the identifier, the resolver decides the destination at scan time, so re-pointing the resolver changes where every pack already in market sends people, with no artwork change.
The follow up questions are the ones that separate platforms. How fast does a change reach codes in the field, and is there a cache you cannot flush. Can a change be scheduled ahead of a campaign or a seasonal switch. Can one identifier hold several typed destinations at once so a shopper and a regulatory system each get the right one. Is there an audit trail showing who changed a destination and when, which matters a great deal the first time a scan lands somewhere it should not.
Ask whether scan data can be read per GTIN and per batch, because a single total across a whole catalogue answers almost no useful question. Per identifier reporting is the minimum bar, and batch level is what turns analytics into an operational tool.
Batch level reporting is the difference between knowing a product is scanned and knowing which production run is being scanned, where and when. That is how you confirm a recall notice is actually reaching the affected run, how you see regional rollout differences, and how you tell a genuine demand signal from a distribution artefact.
Two practical questions people forget. How long is scan data retained, since a year on year comparison is impossible if the window is shorter than a year. And can you export raw scan events into your own warehouse, or are you limited to the vendor dashboard.
Look for a documented API that covers everything the interface can do, because anything only available by clicking becomes a manual process at catalogue scale. Twenty products can be managed by hand. Two thousand cannot.
Your product master data already lives in a PIM or an ERP. The GS1 Digital Link platform should follow that system of record rather than becoming a second one that drifts out of sync. Ask how a new product in the PIM becomes a resolvable identifier, and whether that path is an API call, a scheduled import or a person retyping GTINs.
Specifics to confirm: authentication method, rate limits at your volume, bulk operations rather than one call per product, webhooks or another way to be notified of events, and whether the documentation is public. Public API documentation you can read before signing tells you more about a platform than most demos do.
Get named countries for primary storage, backups, logs and subprocessors, in writing. Scan data is behavioural data about your customers, so residency is a privacy and procurement question rather than a technical preference.
For Canadian brands this comes up early. Federal and provincial privacy obligations shape how personal information may be handled, public sector and healthcare buyers frequently set residency requirements in procurement, and enterprise security reviews ask the question regardless. Having the answer documented before the review starts is considerably easier than sourcing it mid-process.
The common gap is partial answers. A vendor may host the primary database in one region while backups, log aggregation, analytics processing or a support tool sit somewhere else entirely. Ask about each of those separately, and ask for the subprocessor list.
Ask whether single sign-on is supported on the plan you would actually buy, and whether it carries a separate charge. Some vendors place SSO behind an enterprise tier or price it as an add-on, which turns a basic access control into a line item negotiation.
SSO matters for an unglamorous reason. It ties platform access to your identity provider, so an employee who leaves loses access when their directory account is disabled, rather than when somebody remembers to remove them from one more tool. On a system that can change where your packaging sends customers, a stale account is a genuine operational risk.
Look at the rest of the access model at the same time. Role based permissions so an agency can edit a landing destination without holding domain settings, an audit log showing who changed what and when, and a sane invitation and removal flow for the people who join a project for six weeks.
QRbolt includes single sign-on on every plan that supports more than one team member, at no additional cost. We think charging separately for the control that governs who can change your destinations is the wrong way round. Setup is done with you rather than self serve: our team configures the connection to your identity provider and enables it for your organization.
It requires codes your retail partners can actually handle during a transition that is still in progress. Sunrise 2027 is a voluntary industry goal asking retail point of sale systems to be able to accept 2D barcodes by the end of 2027, and readiness varies by market and by chain.
No software makes you Sunrise ready by itself, because the readiness in question belongs to the retailer’s checkout, not to your vendor. What a platform can do is make sure the data on your side is correct and that you are not forced into a single symbol before your customers can read it. Dual marking, meaning printing the existing linear barcode alongside the 2D symbol, is the normal transition approach and keeps checkout working everywhere while the upgrade proceeds.
Practical questions for a vendor: can they produce print ready artwork for both symbologies, do they support GS1 DataMatrix as well as QR for categories that need it, can they hand you documentation a retail partner will accept, and do they have people who can join a conversation with your retail customer rather than pointing you at a help article.
Read more about Sunrise 2027Send the same questions to every candidate in writing and score the answers side by side. Written answers are comparable, survive staff changes on your side, and reveal more than a demo does.
| Criterion | What to ask the vendor | What a strong answer looks like |
|---|---|---|
| Standards conformance | Which specific GS1 Digital Link conformance requirements does your resolver meet, and against which version of the standard? | A named standard version and a specific list of behaviours, rather than the phrase "GS1 compliant" on its own. |
| Resolver behaviour | What HTTP status codes do you return, how do you handle a request for a link type you have no entry for, and do you expose the registered links for an identifier? | Documented redirect semantics, a defined default when a requested link type is missing, and a way to enumerate what is registered against an identifier. |
| Domain ownership | Whose domain is printed on the packaging, and can it be a hostname we own? | Our own domain or a subdomain we control, delegated to the platform by DNS. |
| Portability on exit | If we leave, what do we get back, in what format, and do the printed URIs keep resolving? | A full export of identifiers, link registrations and history, plus a documented path to keep the same URIs resolving elsewhere. |
| Identifier support | Which Application Identifiers do you support beyond GTIN (01), specifically batch (10), expiry (17) and serial (21)? | Explicit support for the qualifiers we plan to print, including routing that can distinguish them. |
| Dynamic routing | Can we change a destination after packaging is printed, and how quickly does the change take effect on codes already in market? | Destination changes are configuration, not reprints, and take effect without waiting on a cache we cannot flush. |
| Analytics granularity | Can scan data be broken down by GTIN and by batch, and how long is it retained? | Per identifier reporting including batch level, with a stated retention period and an export path. |
| API and integration | Is there a documented API covering everything the interface can do, and how does it connect to our PIM or ERP? | A documented API with authentication, rate limits and bulk operations, so a catalogue can be driven from the system of record. |
| Data residency | In which countries is our data stored and processed, including backups, logs and any subprocessors? | Named regions for primary storage, backups and subprocessors, in writing, not just for the main database. |
| Identity and access | Do you support single sign-on, is it an extra charge, and what roles and audit logging come with it? | SSO available on the plan we would actually buy, at no separate security surcharge, with role based access and an audit trail. |
| Retail and POS readiness | What do you produce for retail partners running 2D scanning, and can you support dual marking during the transition? | Support for producing both symbols during transition and clear guidance on what a retail partner needs from us. |
| Commercial fit | What is the price at our real volume, and which line items change as GTIN count, scans or users grow? | A price we can model against our own catalogue size and scan volume, with the growth levers named up front. |
If you only have room for three questions, use these: whose domain gets printed, what we get back if we leave, and which conformance requirements the resolver meets. Those three separate platforms far more sharply than feature lists do.
Held against the same checklist, here is what QRbolt does. We have kept this to things that are plainly true and checkable, because a buyer guide that ends in unverifiable claims is not worth the earlier pages.
QRbolt creates GS1 Digital Link URIs and resolves them, alongside dynamic QR codes for everything that is not a GS1 identifier.
Codes can resolve on a domain you own, which is the position this guide argues for and which we hold ourselves to.
A URI carrying a batch under AI (10) can be routed separately from the bare GTIN, and the destination can be changed after packaging has been printed.
Scan analytics are tied to the identifier, so engagement reads per product and per batch rather than as one undifferentiated total.
Single sign-on is included on every plan that supports more than one team member, at no additional cost. GS1 plans start at CAD $150 per month.
QRbolt is listed by GS1 Canada as a solution provider. That is a directory listing, not an endorsement or a certification, and we would rather say so than let the distinction blur. Apply the same question to every vendor you shortlist.
Criteria this section does not claim are ones you should ask us about directly, in writing, exactly as you would ask anyone else on your shortlist.
Domain ownership, because it is the only decision that gets physically printed onto packaging. Every other choice can be revised after launch. If the hostname in your printed URIs belongs to a vendor, changing vendor means reprinting artwork and living with packaging in the field that points at a company you no longer work with. Resolve on a domain or subdomain you control and the rest of the stack stays replaceable.
Not on its own. Vendors describe their relationship with GS1 in different ways, and a directory listing as a solution provider is not the same thing as certification or endorsement. Ask which specific conformance requirements the resolver meets and against which version of the GS1 Digital Link standard, then evaluate the answer rather than the label.
It reads the GS1 identifier out of the incoming request, looks up the destinations registered against that identifier, and redirects the caller to the one that fits the request. A caller can name the kind of resource it wants using a link type from the GS1 vocabulary, so a regulatory system and a shopper can ask the same printed identifier for different things and get different answers.
Only if you have a use for the granularity. Batch under Application Identifier (10) is what makes a targeted recall or a run specific message possible, but printing a batch means generating and applying codes per production run rather than pre-printing one identical symbol. Decide whether recall precision, freshness messaging or run level analytics justify that change to your packaging line before you buy for it.
Because scan data is behavioural data about your customers, and Canadian privacy obligations and many enterprise procurement policies ask where personal information is stored and processed. Ask for named regions covering primary storage, backups, logs and subprocessors. A vendor that can only answer for the main database has not actually answered the question.
That is a commercial choice each vendor makes, and it is worth pricing explicitly rather than discovering it at contract stage. SSO is how you keep account access tied to your identity provider, so joiners and leavers are handled centrally. QRbolt includes SSO on every plan that supports more than one team member, at no additional cost, and our team configures the connection with you rather than leaving it as a self serve toggle.
Sunrise 2027 is a retail point of sale readiness initiative rather than a software product category, so no tool makes you compliant by itself. What you need is the ability to create GS1 Digital Link URIs correctly, resolve them on a domain you own, carry the qualifiers your category requires, and support dual marking while your retail partners complete their own transition. Evaluate candidates against those capabilities rather than against the label.
Send the same written questions to every candidate and score the answers, rather than watching demos. Demos show the parts a vendor chose to show. A written answer about resolver status codes, export format on exit, data residency for backups and the price at your real volume is comparable across vendors and survives staff turnover on your side.
Reference material: the GS1 Digital Link standard defines URI syntax and resolution behaviour, and the GS1 General Specifications define Application Identifiers. Sunrise 2027 is a GS1 industry initiative, and it is voluntary rather than a mandate. All are published by GS1, and your national GS1 member organisation is the right first stop for questions about your own market.