The short answer: a QR code cannot track you. The longer answer is the one worth reading, because it explains why some codes effectively do.
The pattern is inert
A printed QR code is ink. It has no processor, no connection and no memory. It cannot count scans, know who scanned it, or report anything to anyone. Scanning one does not notify the person who printed it.
If the code contains plain text, or a Wi-Fi password, or a phone number, that is the end of the story. Nothing is transmitted anywhere. Your phone reads the pattern and shows you what it says.
Where tracking actually happens
Two places, neither of them the code.
The page it opens. A code containing a link is exactly as private as visiting that link any other way. The site sees your IP address, your rough location from it, your device and browser, and can set cookies. If the link has campaign parameters on the end, the owner knows which poster you scanned. That is not the QR code tracking you — it is ordinary web analytics — but the effect is the same.
A redirect service in the middle. This is the one people miss. A dynamic QR code contains a short link on a third party domain. Every scan goes through that company first, and gets logged there, before being forwarded on. That logging is the product — it is what you are paying the subscription for.
So a dynamic code genuinely does track scans, and the data sits with a company you may not have chosen and your customers definitely did not.
| Code type | Who sees the scan |
|---|---|
| Plain text, Wi-Fi, phone, vCard | Nobody. Nothing is transmitted |
| Link to a site | That site, like any visit |
| Link with campaign tags | That site, plus which code you scanned |
| Dynamic redirect code | The redirect company, then the destination |
How to tell which one you scanned
Look at the address in the banner before you tap. If it is a short domain you do not recognise, with a few random characters after it, you are looking at a redirect — the real destination is hidden behind it.
That is not automatically sinister. Plenty of legitimate marketing uses it. But it does mean a third party records that you scanned, roughly where you were, and what device you used, and you cannot see who that party is until after you have tapped.
What we do
Everything on this site is generated in your browser. Your text, your links, your Wi-Fi password, your uploaded logo — none of it is sent to us. There is no account, so there is nothing to attach to you, and the codes are static, so no request ever comes back through us.
That is not a promise about our intentions, it is a description of the architecture: we could not log your scans if we wanted to, because they never touch us.
The trade is that we cannot offer scan analytics. There is no version of that feature that does not involve a redirect through somebody.
If you are printing codes
You can be more or less private with the same technology.
- A static code to your own domain — you see the traffic in your own analytics, nobody else does
- A dynamic code — a third party sees every scan of yours before you do
- Campaign parameters — fine, but they end up in the address bar where the customer can see them, which is more honest than most alternatives
If you want to know which poster worked without handing data to a redirect service, use a different short path on your own domain for each one — /menu-a and /menu-b. Your own server logs answer the question.
If you are scanning
- Read the address before tapping
- Treat a scan exactly like a link in an email from a stranger
- Never enter credentials on a page you reached from a code in public — see QR code scams
- Use your phone built-in camera rather than a free scanner app; those apps often carry advertising SDKs that collect far more than the code ever could
The thing that actually deserves caution
Not the code. The Wi-Fi network it might join you to.
A Wi-Fi QR code hands your phone straight onto somebody else network, where whoever runs it can see far more about your traffic than a web page could. Scanning a Wi-Fi code from a source you do not trust is a genuinely bad idea, and it is the one QR-related risk that has nothing to do with tapping a link.
Make a code — nothing you type here reaches us.
