QR code analytics can answer a useful business question: did people engage with the code you placed in the world? They should not be confused with a record of who those people are. If you are choosing a dynamic QR code for a menu, poster, package, event sign, or business card, the important privacy work is understanding the difference before you publish.

This guide explains the scan data available with dynamic QR codes, what that data does not identify, and how to set up a measurement approach your team can explain clearly.

Start with the difference between static and dynamic QR codes

A static QR code contains its destination directly in the pattern. It can be free and remain active indefinitely, but it cannot be changed or tracked after it has been created.

A dynamic QR code points to a short link you control. That link makes two practical things possible: you can update the destination after the code has been printed, and you can review scan analytics. For a campaign that may change over time, this can prevent a printed code from leading to an outdated page. It also gives the code owner a way to assess scanning activity.

The tradeoff is straightforward: once a code is used for analytics, scan data becomes part of the project. Before creating the code, decide what you need to learn, who needs access to the report, and how long the report needs to be retained. Do not collect or share scan reports simply because they are available.

What scan analytics can reveal

Dynamic QR code analytics can provide an aggregate view of how a code is being used. Available reporting categories include:

These categories are most useful when they are tied to a specific decision. A restaurant might compare scan timing before and after changing the placement of a table card. An event team might compare different signs by giving each placement its own dynamic code. A retailer might use scan trends to decide whether a package insert is being noticed.

In each case, the useful output is a pattern, not a person. A rise in scans after a poster goes up can tell you the poster is generating interest. A city breakdown can help you understand where activity is reported. Device and browser categories can help a web team prioritize testing. None of those reports, on their own, explain an individual scanner's identity, intent, or full journey.

What QR code scan data cannot tell you

Scan analytics should not be treated as identity data. The available categories describe scan activity and technical or geographic breakdowns. They do not provide a person's name, email address, phone number, home address, or account identity.

They also do not prove that a scanner completed an action after reaching the destination. A scan is evidence that the QR code was scanned. It is not, by itself, evidence that someone read a page, submitted a form, made a purchase, or attended an event. If those outcomes matter, define a separate, appropriate measurement method on the destination itself and make sure your team understands it as separate from scan reporting.

It is equally important not to overinterpret location reporting. Country and city breakdowns are reporting categories, not a live map of a person. Avoid presenting them as precise location tracking or using them to make assumptions about an individual.

How IP addresses fit into the privacy picture

IP addresses are often part of privacy conversations because they can be involved in network-based reporting. QRhubly states that it hashes every IP address and does not store raw IP addresses. That distinction matters when your team is reviewing how scan data is handled.

For a fuller explanation of that approach, see Understand scan data privacy.

Privacy requirements can differ by organization, location, audience, and the type of information used elsewhere in a campaign. Before publishing a tracked code, have the appropriate people on your team review your notice, retention, access, and approval practices: [VERIFY WITH YOUR TEAM].

A practical setup checklist for privacy-conscious QR measurement

  1. Choose static when tracking is unnecessary. If the destination is stable and you do not need scan reporting, a static code avoids adding scan analytics to the project.
  2. Give each placement a clear purpose. Use a separate dynamic code for distinct placements only when the comparison will inform a real decision, such as poster location or campaign creative.
  3. Name codes for the placement, not the audience. A label such as “Spring event lobby sign” is easier to interpret than a label that tries to describe individual scanners.
  4. Limit report access. Decide which roles need to view analytics and exports. Keep the group focused on people who use the data to operate or evaluate the campaign.
  5. Export only when there is a reason. CSV export is useful for analysis and recordkeeping. Treat exported scan logs with the same care as any other project reporting file.
  6. Set a review rhythm. Check scan trends at a useful interval, then decide whether the code destination, placement, or campaign needs to change. Avoid collecting reports with no planned use.
  7. Explain the destination clearly. Nearby copy such as “Scan for the current menu” or “Scan for event details” tells people what to expect before they scan.

Use the smallest amount of data that answers the question

A good QR code measurement plan is modest and specific. Instead of asking what every scan can reveal, ask what decision the report should support. Do you need to know whether a printed code is being scanned? Whether one placement receives more activity than another? Whether activity is concentrated at certain times? Start there.

This approach also improves reporting. A short summary such as “the lobby sign received more scans than the registration desk sign” is more useful to most stakeholders than a large export with no agreed purpose. It keeps the focus on improving the physical-to-digital experience while respecting the limits of the data.