Sometimes. A static QR code can encode a destination directly, so a generator may never receive information about scans. A dynamic QR code commonly sends scanners through a provider’s redirect service, which can make destination changes and scan counting possible. What gets recorded depends on the provider and setup. If your business uses scan analytics that process personal data, explain the actual data flow in a privacy notice and meet the rules that apply to your jurisdiction.
Can a QR code track who scans it?
A QR code itself is just encoded information. Whether a scan generates data for a business or service provider depends mainly on where the code sends the scanner and what the receiving systems record.
- Direct or static code: The code contains its destination, such as a web address. If it opens that address directly and the code is generated locally, the QR generator need not receive a scan event. The destination website may still collect information through its own logs, analytics, or other tools.
- Dynamic code: The code points to a provider-controlled address that redirects the scanner to the destination. That extra step can let the provider change the destination later and count scans. It can also expose scan information to the redirect service.
Scan analytics do not necessarily identify a person by name. Depending on the implementation, records may include scan time, device or browser details, approximate location derived from an IP address, or an identifier used to distinguish scans or sessions. Such details can still raise privacy issues; a hashed identifier is not automatically anonymous.
Do static QR codes track scans?
Not necessarily. A static code can be generated in a browser and encode the destination without sending its content to the generator’s servers. OpenQR says that is how its static codes work; it says its dynamic-code destinations are stored server-side so scans can be redirected and counted. These are claims about OpenQR’s implementation, not a guarantee about all QR services. See its privacy policy.
Windows Errors? Fix Them Before They Spread
Repair common Windows errors and clear accumulated junk for a smoother, more stable PC - no reinstall needed.Free scan · no reinstallOutdated Drivers Are Slowing You Down
One free scan finds every outdated or missing driver and matches the right update for your exact hardware.Free scan · exact hardware match#1 Best Overall
Even when the QR generator does not receive scan data, the website opened by the code may log visits. A business should therefore consider the full route—from scanning, through any redirect, to the destination—not just the tool used to make the image.
What information can a dynamic QR code collect?
The fields vary by provider. These published policies illustrate why a business should inspect the exact scan fields, IP handling, purposes, recipients, and retention period rather than assume all dynamic codes work alike.
Rank #2
- Ideal for Gifting
- Ideal for a bookworm
- Compact for travelling
| Provider and policy date | What the provider says it processes or records | Retention stated in the policy |
|---|---|---|
| DynamicQRCode; policy effective 28 August 2026 | It says it temporarily processes raw scanner IP addresses for approximate geolocation, then stores a SHA-256-derived identifier with scan time, QR code ID, browser-session ID, derived country or state, and broad device type. The provider describes its hashed IP-derived identifier as pseudonymised personal data. | It says active code scan logs remain while the QR code and owner account are active, with no fixed automatic expiration period currently applied to active logs. |
| QRCode.io; policy updated June 2026 | It says dynamic scans record scan time, device type, operating system, browser, and approximate city-level location derived from IP. It says static codes can be made without an account or personal information. | It says dynamic scan statistics remain while the code exists. |
| OpenQR; policy updated 27 June 2026 | It says static-code payloads are generated in the browser and not uploaded. It says dynamic-code destinations are stored server-side for redirection and counting. For site analytics, it says it uses self-hosted Matomo without cookies, respects Do Not Track, and anonymises IP addresses. | Not stated in the cited policy details for scan logs. |
Sources: DynamicQRCode’s privacy policy, QRCode.io’s privacy policy, and OpenQR’s privacy policy. These are providers’ own descriptions of their practices, not independent verification or an industry-wide comparison; policies and implementations can change.
Who is responsible for the scan data?
Responsibility depends on the arrangement and the purposes for which data are used. A QR vendor may operate the redirect and process scan information to provide analytics, while the business may decide to use those analytics for its own campaign or operational purposes. DynamicQRCode’s terms describe that arrangement as the QR owner determining the purposes and acting as controller where applicable, with the service processing scan information on the owner’s behalf for analytics. That is the provider’s stated model, not a rule that automatically applies to every vendor or contract. Read the relevant terms and any data-processing agreement.
The Tool Desk
Outbyte PC Repair FREEClear out junk files and repair common Windows errorsFree Scan →Outbyte Driver Updater FREEFix the driver behind crashes, sound loss and screen glitchesFind Drivers →Rank #3
What should a business disclose?
Where the GDPR applies and personal data are collected, Article 13 requires the controller to provide transparency information when the data are obtained. Its scope includes the controller’s identity and contact details, processing purposes and legal basis, recipients, applicable international transfers, retention period or criteria, rights and complaint route, and—where relevant—legitimate interests and automated decision-making information. The exact notice depends on the actual processing and applicable law; this is not a universal worldwide template. See Article 13 of Regulation (EU) 2016/679.
Before publishing a QR campaign, verify these points and explain the relevant ones clearly in the privacy notice:
Rank #4
- Route: Does the code encode the destination directly, or does it first go through a dynamic-code provider?
- Data: What is recorded on a scan—for example, IP address or an IP-derived location, timestamp, device or browser information, or a unique scan or session identifier?
- Purpose and basis: Why is each category processed, and what legal basis applies where required?
- Recipients: Which QR vendor, analytics provider, or other service provider receives or can access the information?
- Retention: How long are scan records kept, or what criteria determine when they are deleted?
- Contact and rights: Who controls the campaign data, how can a scanner contact them, and what rights or complaint channels apply?
A short notice near a QR code can direct people to a fuller privacy notice. The sources cited here do not establish a universal rule about where or how that notice must appear. Check the requirements that apply to your business, audience, and campaign location.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.How to choose a QR setup for a campaign
Choose based on what the campaign needs, not just whether a service advertises “analytics.”
Quick Recap
Best Value
- It can be a gift option
- Comes with secure packaging
- Helpful in various ways
- If the destination will not change and scan counts are unnecessary: A direct, static code can avoid a QR-provider redirect and its associated scan analytics, if the chosen generator really creates it locally and the code points straight to the destination.
- If you need to edit the destination or count scans: A dynamic code may provide those functions, but check the provider’s exact fields, IP handling, other recipients, retention and deletion options, and contractual responsibilities before using it.
- For either approach: Account for data collected by the destination website and any other services in the route. Confirm that your privacy notice describes the actual setup rather than making a general claim that scans are anonymous or not tracked.
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




