QR code privacy and tracking
SmartQRCode editorial · Updated October 2026
QR code privacy and tracking is a three-field log on hosted types, and an empty log on static Wi-Fi. The owner sees totals, a coarse device class, and a country from request headers. A scanner name never stored. If you need zero owner-side data, print a static file or type the address.
QR code privacy and tracking
This walkthrough is for an owner who is about to turn on a tracked code, or a reviewer who was told "we track scans" and needs the actual columns. It does not apply to a Canva PNG taped to a fridge. That static file has no SmartQRCode hop, so there is nothing to disclose from this product.
Hosted website and landing-page types encode a SmartQRCode URL. The printed modules stay still while you change the destination. The trade is provider dependence: the print works while the host resolves. Redirects use HTTP 302 so browsers do not cache an old destination and freeze later edits.
Wi-Fi is the static exception. The phone reads the password from the modules. There is no scan analytics row. Do not brief a privacy team that you can count Wi-Fi joins from this product. You cannot.
Map the fields before you print the run
- Open the code type list and pick a redirect or landing-page type only if you accept a hop through smart-qrcode.com (or your custom scan host).
- Write the three stored fields on the brief: totals over time, device type in the dashboard, header-derived country.
- Write the three fields you will not have: legal name, email, GPS coordinates.
- If the payload is Wi-Fi, stop the tracking conversation. Export PNG or SVG and treat the password like a whiteboard secret.
- Separate pause is not archive in the runbook. Archive keeps the symbol scanning. Pause is the state that stops the live destination.
- Export SVG or a 300 dpi PNG at the final millimetre size. Do not screenshot the on-screen preview; that preview encodes /qr-preview.
- Test-scan from a phone that is not already on the destination page, then confirm the dashboard gained one total and a country, not a personal identity.
What fields does a hosted scan actually store
The tracking generator exists because some campaigns need a count. That count is not a CRM. Country is inferred from headers, which can be wrong at borders, on VPNs, and on carrier-grade NAT. Do not present it as a home address.
Device type is a coarse class for layout decisions (phone versus desktop), not a serial number. Totals over time answer "did the poster work," not "who came." If a healthcare clinic needs named attendance, a QR scan log is the wrong system. Use the appointment software.
A website code and a landing-page menu share this same log shape. The destination page may set its own cookies. That is the destination's policy, not the scan hop. Keep those two processors separate in the brief.
Can a scanner opt out of the log
There is no scanner-facing off switch on the hop. The practical opt-out is not scanning, or scanning a static symbol that never calls the host. Put a printed https URL next to the code when you serve people who will refuse a tracker. That is the honest layout, not a tiny footnote.
If your brief cannot survive that printed URL existing, you did not need a QR code. You needed a mandatory tracker, and this product should not be sold as quiet surveillance.
How do you brief a privacy review
One page. Product name SmartQRCode. Domain smart-qrcode.com. Encoding: hosted URL in the modules. Redirect: 302. Fields: totals, device type, country from headers. Identity: none. Wi-Fi: no hop, no counters. Archive versus pause: archived keeps scanning; pause is separate. Provider dependence: if we shut the host down, hosted prints stop. Static Canva files do not.
Healthcare waiting rooms should not hide this. Anxious readers at sitting distance already distrust mystery symbols. Pair the code with the spoken URL. See healthcare use.
Failure modes of this privacy brief
Treating country as GPS. Promising a named visitor. Claiming Wi-Fi joins appear in the same chart. Using pause and archive as synonyms so a deleted campaign still counts. Wrapping the hop in an extra public shortener so the preview lies. Sending a screenshot of /qr-preview to the printer and thinking the live payload was tested.
A screenshot of the designer is the wrong file for two reasons. It is often a low-resolution raster with UI chrome, and the payload is /qr-preview rather than the live hosted URL. Vector SVG or a 300 dpi PNG at final millimetres is the press file. Privacy review does not replace a scan test, and a scan test does not replace the field list.
When a static generator is the privacy win
A one-off poster that will never change and will never be counted should be a Canva, Google Chart, or in-app iOS static file. You avoid the hop, the log, and the invoice. Use SmartQRCode when you need edit after print or a count. For who can open the dashboard, continue with who sees QR code scan data.
A church rummage-sale flyer with a PayPal URL that dies on Sunday night is that Canva job. A clinic that will swap the form link after a software cutover is the hosted job. Mixing them on one brief produces a dashboard nobody needed or a reprint nobody budgeted.
Custom scan domains, when you use them, still record the same three fields. The hostname on the print can be yours. The columns do not grow a name field because the host changed. White-label scanning is a hostname story, not an identity story.
Teams share those same columns. Owner, admin, and member do not receive a hidden guest list. If someone asks the dashboard to become a CRM, the answer is to buy a CRM. The scan table will not grow extra columns because the brief was anxious.
Custom scan domains, when you use them, still record the same three fields. The hostname on the print can be yours. The columns do not grow a name field because the host changed. White-label scanning is a hostname story, not an identity story.
Teams share those same columns. Owner, admin, and member do not receive a hidden guest list. If someone asks the dashboard to become a CRM, the answer is to buy a CRM.
Questions this raises
Totals over time, device type in the dashboard, and a header-derived country. A scanner name never stored, nor an email, nor a GPS pin.
Not via a SmartQRCode toggle on the phone. A scanner who wants no owner log should use a static print or type the URL.
List the three fields, name 302 redirects, state that Wi-Fi has no hop, and separate pause from archive.
User-archived codes keep scanning. Pause is not archive. Pause is the state that stops the live hop.
No. A paper menu or a Canva static URL avoids an owner-side scan log. Use that when counting covers is unused.
Keep going
The tools and playbooks this post refers to, one click away.
Make the code this post is about
$1.99 for 7 days, then a paid plan. Pick a type, brand it, and edit the destination whenever you like, even after it is printed.