QR Code Tracking: What a Scan Can and Can't Tell You
What a dynamic QR code's redirect actually records, what inflates or blurs the count, why scans often land in GA4 as Direct, and what privacy rules say about scan data.
A QR code scan gives the redirect server a time, an IP address and a device description, so you learn when a code was scanned, roughly where and on what kind of phone. It can't identify the person, pinpoint where they stood or show whether they read the page. MaxMind puts IP location at 99.8% for country and about 66% for city within 50 km, and email security scanners, link previews and shared IP addresses can inflate or blur counts. Tag codes with UTMs, compare scans with real outcomes and treat the number as a signal.
- Scans record time, IP-based location and device, never identity.
- City-level location is right about two times in three, per MaxMind.
- Email scanners and chat previews can add requests, so keep print and shared links separate.
- Scans often show as Direct in GA4 unless the link carries UTM tags.
- IP addresses in scan logs can be personal data under EU law.
QR code tracking tells you when a code was scanned, roughly where, and on what kind of phone. It can't tell you who scanned it, exactly where they stood, or whether they read your page. The count itself is noisy too: email scanners, link previews and shared IP addresses all add to it or blur it.
That doesn't make scan data useless. You just need to know which numbers to trust, which are estimates, and what to check them against. This guide covers how a scan is recorded, where the numbers go wrong, and what privacy rules say about them.
What does a QR code scan record?
A dynamic QR code holds a short link. When someone scans it, their phone requests that link, and a redirect server logs the request before sending the phone on to your page. A 2023 study of 37 QR generators found dynamic services usually redirect with an HTTP 302 and can record city, country and browser type (Siddiqi et al., IEEE ConPro, 2023).
The server gets the phone's IP address because it has to send its reply somewhere. The EU's top court described exactly this in the Breyer case: a website receives the visitor's IP address because the page must be sent back to it (CJEU press release 112/16, 2016). Each scan leaves a small set of signals:
| Signal | Where it comes from | What you learn |
|---|---|---|
| Time | The server's clock | When the request arrived |
| Which code | The short link that was requested | Which placement was scanned, if each placement has its own code |
| IP address | The network connection | Approximate location, via a geolocation database |
| User-Agent | A header the browser sends | Device type, operating system and browser |
| Referer | A header the browser may send | Usually nothing for a scan (see below) |
Location is the signal people over-trust. MaxMind, an IP geolocation provider, publishes its own accuracy figures (MaxMind):
| Level | MaxMind's stated accuracy |
|---|---|
| Country | 99.8% |
| US state or region | About 80% |
| City | About 66% within a 50 km radius |
MaxMind also says its data is never precise enough to find a household, a person or a street address. It can't guarantee accuracy, and VPN users may be impossible to place. Each result comes with an accuracy radius, such as 100 km.
So a report showing 40 scans from Chicago really means this: about 40 requests came from IP addresses that a database places in or near Chicago.
What can't a QR scan tell you?
Three things people assume a scan shows sit outside what a redirect server can see. MaxMind's own figures rule out the first two, and the third follows from how redirects work.
- Who scanned it. A scan carries no name, email or account. An IP address and a phone model don't add up to a person, and MaxMind says its data can't pinpoint a household.
- Exactly where they stood. About a third of city-level guesses land outside MaxMind's 50 km radius. You know where the code sat only because you put it there.
- Whether they read the page. The redirect's job ends when it hands the phone your destination. What happens next – reading, scrolling, buying or leaving after a second – happens on your site, out of the redirect's view. A scan that bounced counts the same as one that bought.
To see what people did after the scan, you need analytics on the destination page. That's where UTM tags come in.
Why do QR code scans show up as Direct in GA4?
Google Analytics 4 files a visit as Direct when it arrives "via a saved link or by entering your URL", with the source set to "(direct)" (Google Analytics Help). A visit from a QR scan usually arrives the same way, with no referring page. Without tags, GA4 usually counts it as Direct.
The missing piece is the Referer header. When you click a link on a web page, the browser usually tells the next site which page you came from. A camera app pointed at a poster has no web page to report. We haven't found Apple or browser documentation that promises either behavior, so treat "usually empty" as a working assumption. Don't build reporting that depends on it.
The fix is to tag the destination URL your QR code points to:
https://example.com/spring?utm_source=flyer&utm_medium=qr&utm_campaign=spring-sale
GA4 reads those tags and credits the visit to your flyer instead of Direct. Add utm_content to tell placements apart, such as utm_content=window and utm_content=counter. A UTM builder keeps your naming consistent, which matters because QR and qr end up as separate rows.
What inflates or blurs your scan count?
Automated traffic is a normal part of any web count. Imperva's 2026 Bad Bot Report says automated traffic made up 53% of all web traffic in 2025, up from 51% in 2024 (Imperva, 2026). On Cloudflare's network, humans made 47% of HTML requests as of December 2, 2025 (Cloudflare, 2025).
Neither figure is your QR code's bot rate. Imperva's blog doesn't publish its sample or method, and Cloudflare's figure covers HTML requests only, with non-AI bots at 44% and AI bots averaging 4.2%. What they do show is that a request count and a human count are different numbers. For short links behind QR codes, these are the usual suspects:
| Source | What it does | Effect on your numbers |
|---|---|---|
| Microsoft Safe Links | Scans URLs in email before delivery. Links without a valid reputation are "detonated asynchronously in the background", and rewritten links are checked again at click time (Microsoft Learn, 2026) | Requests from Microsoft's systems if your tracked link also appears in an email |
| Slack link previews | Slackbot fetches links posted in channels and caches the result for about 30 minutes (Slack) | About one extra request per URL per 30 minutes while it's being shared |
| Meta link previews | The facebookexternalhit crawler fetches links shared on Facebook, Instagram and Messenger to build a title and thumbnail (Meta) | Requests with no person behind them |
| iCloud Private Relay | Safari traffic leaves through relay IPs that may be shared by several users and show a coarse city-level location, or only country and time zone (Apple) | Blurred location, and several people can look like one |
| Apple Mail Privacy Protection | Downloads an email's remote content in the background "regardless of whether you engage with the email" (Apple, 2025) | Anything in the email that loads from a tracking server can register activity from nobody |
| Carrier-grade NAT | Mobile carriers often put many subscribers behind one public IP address (EDPB Guidelines 2/2023, 2024) | Different people share one IP, which blurs location and unique counts |
Messaging apps differ in how they build previews. In a study published in October 2020, Mysk found that iMessage, WhatsApp, Viber and Signal built previews on the sender's device. Discord, Messenger, Instagram, LinkedIn, Slack and Zoom built them on a server (Mysk, 2020). That study is six years old, so apps may have changed. Our reading: a preview built on the sender's phone comes from a real phone, so it may be harder to tell apart from a scan.
A printed code on a shop counter is mostly scanned by people holding phones. The same link pasted into Slack or an email picks up machines. That's the best reason to keep the two apart.
Why is "unique scans" only an estimate?
We found no neutral standard for counting unique scans, so each vendor sets its own rules. One method, used by QR Planet, hashes part of the IP address: it drops the last part of the IP and hashes it with SHA-256, with the User-Agent as an option. QR Planet says this "might make the number of unique visitors smaller" (QR Planet).
Any IP-based method breaks in two directions:
| What happens | Example | Effect on uniques |
|---|---|---|
| Different people share one IP | Customers behind their carrier's shared IP, or Private Relay users on the same relay | Several people merge into one |
| One person's IP changes | Someone scans on coffee-shop Wi-Fi, then again on mobile data | One person splits into two |
So a unique count can be too low and too high at once, and you can't tell which error is bigger for a given code. Compare uniques across your own codes, counted the same way. Don't compare them with another tool's uniques.
Is QR code analytics a privacy risk?
QR codes aren't a special privacy threat. After scanning 948 QR codes found in public and testing 37 generators, University of Illinois Chicago researchers found "no evidence that QR codes are a substantial or unique privacy threat" compared with other ways of sharing links (Siddiqi et al., 2023). A scan is still a web request, though, so the usual rules on IP addresses and tracking apply.
| Rule | What it says | What it means for scan data |
|---|---|---|
| Breyer, CJEU case C-582/14 (2016) | A dynamic IP address is personal data for a site operator with the legal means to identify the visitor through the internet provider. A site may have a legitimate interest in storing it to guard against attacks (CJEU) | Assume scan logs with IP addresses can be personal data in the EU. The ruling came before GDPR |
| EDPB Guidelines 2/2023 (v2.0, October 2024) | Tracking links sent through messaging, and IP-based tracking, can fall under ePrivacy Article 5(3), the EU's cookie rule. That "does not systematically mean that consent needs to be collected" (EDPB) | The board didn't analyze the exemptions, so whether a scan counter needs consent is unsettled |
| CNIL audience-measurement exemption | France exempts measurement from consent if it's limited to measurement and A/B testing, for one publisher, not combined with other data, with the last byte of the IP dropped, trackers kept 13 months at most, and users told and able to object (CNIL) | A useful checklist, though the guidance covers cookies and trackers and doesn't mention server logs |
| CCPA, Cal. Civ. Code §1798.140(v)(1) | Lists "Internet Protocol address" as an identifier, along with geolocation data and internet activity (California Legislature) | Scan logs with IP addresses can be personal information for businesses the law covers |
| EU Digital Omnibus (proposed November 19, 2025) | Would move the cookie rules into GDPR and allow some low-risk uses without consent, reportedly including aggregated first-party audience measurement (European Commission, Taylor Wessing) | Only a proposal. Nothing has changed yet |
The low-risk habits line up with CNIL's list. Count only what you'll use, keep scan data for a limited time, don't combine it with other personal data, drop or truncate IP addresses once geolocated, let people object, and say in your privacy notice that you count scans by location and device.
*This is general information, not legal advice. If your business depends on the answer, ask a privacy lawyer in your market.*
How to read your scan numbers
- Tag every destination with UTMs. Your analytics tool can then credit scans to the right campaign instead of Direct, and you can see what people did after the scan.
- Use one code per placement. A code on the window and another on the counter tell you which spot works. One shared code only tells you that something did. Our dynamic QR code guide covers setting them up.
- Compare scans with an outcome. Sales, form fills, bookings or coupon redemptions matter more than scans. If scans rise and outcomes don't, look at the page or the offer.
- Rely on country, treat city as a guess. By MaxMind's figures, country is right 99.8% of the time, and city lands within 50 km about two times in three.
- Read trends, not single spikes. A steady weekly count means more than one busy afternoon. Check any spike against when you shared the link in Slack, email or a social post.
- Keep print codes and shared links separate. If you email or post the short link your poster uses, previewers and security scanners land in the poster's count. Use a second link for digital sharing.
- Scan your own code before launch, then remember you did. Your test scans are in the total too.
What Whooshly shows for scans
Whooshly counts each dynamic QR code's scans against that code, separately from ordinary link clicks, with daily totals, breakdowns by country, device, referrer, UTM source and UTM campaign, and CSV export. The free plan keeps 7 days of analytics, and Core, a one-time $35, keeps 120 days. It doesn't know who scanned, and the limits in this post apply to it as they do to any tracker. Read the numbers with that in mind: a scan count is a signal, not a headcount.