Skip to content
Whooshly Blog · QR codes

QR Code Tracking: What a Scan Can and Can't Tell You

What a dynamic QR code's redirect actually records, what inflates or blurs the count, why scans often land in GA4 as Direct, and what privacy rules say about scan data.

Updated Sep 2026·8 min read

QR code tracking tells you when a code was scanned, roughly where, and on what kind of phone. It can't tell you who scanned it, exactly where they stood, or whether they read your page. The count itself is noisy too: email scanners, link previews and shared IP addresses all add to it or blur it.

That doesn't make scan data useless. You just need to know which numbers to trust, which are estimates, and what to check them against. This guide covers how a scan is recorded, where the numbers go wrong, and what privacy rules say about them.

What does a QR code scan record?

A dynamic QR code holds a short link. When someone scans it, their phone requests that link, and a redirect server logs the request before sending the phone on to your page. A 2023 study of 37 QR generators found dynamic services usually redirect with an HTTP 302 and can record city, country and browser type (Siddiqi et al., IEEE ConPro, 2023).

The server gets the phone's IP address because it has to send its reply somewhere. The EU's top court described exactly this in the Breyer case: a website receives the visitor's IP address because the page must be sent back to it (CJEU press release 112/16, 2016). Each scan leaves a small set of signals:

SignalWhere it comes fromWhat you learn
TimeThe server's clockWhen the request arrived
Which codeThe short link that was requestedWhich placement was scanned, if each placement has its own code
IP addressThe network connectionApproximate location, via a geolocation database
User-AgentA header the browser sendsDevice type, operating system and browser
RefererA header the browser may sendUsually nothing for a scan (see below)

Location is the signal people over-trust. MaxMind, an IP geolocation provider, publishes its own accuracy figures (MaxMind):

LevelMaxMind's stated accuracy
Country99.8%
US state or regionAbout 80%
CityAbout 66% within a 50 km radius

MaxMind also says its data is never precise enough to find a household, a person or a street address. It can't guarantee accuracy, and VPN users may be impossible to place. Each result comes with an accuracy radius, such as 100 km.

So a report showing 40 scans from Chicago really means this: about 40 requests came from IP addresses that a database places in or near Chicago.

What can't a QR scan tell you?

Three things people assume a scan shows sit outside what a redirect server can see. MaxMind's own figures rule out the first two, and the third follows from how redirects work.

  • Who scanned it. A scan carries no name, email or account. An IP address and a phone model don't add up to a person, and MaxMind says its data can't pinpoint a household.
  • Exactly where they stood. About a third of city-level guesses land outside MaxMind's 50 km radius. You know where the code sat only because you put it there.
  • Whether they read the page. The redirect's job ends when it hands the phone your destination. What happens next – reading, scrolling, buying or leaving after a second – happens on your site, out of the redirect's view. A scan that bounced counts the same as one that bought.

To see what people did after the scan, you need analytics on the destination page. That's where UTM tags come in.

Why do QR code scans show up as Direct in GA4?

Google Analytics 4 files a visit as Direct when it arrives "via a saved link or by entering your URL", with the source set to "(direct)" (Google Analytics Help). A visit from a QR scan usually arrives the same way, with no referring page. Without tags, GA4 usually counts it as Direct.

The missing piece is the Referer header. When you click a link on a web page, the browser usually tells the next site which page you came from. A camera app pointed at a poster has no web page to report. We haven't found Apple or browser documentation that promises either behavior, so treat "usually empty" as a working assumption. Don't build reporting that depends on it.

The fix is to tag the destination URL your QR code points to:

https://example.com/spring?utm_source=flyer&utm_medium=qr&utm_campaign=spring-sale

GA4 reads those tags and credits the visit to your flyer instead of Direct. Add utm_content to tell placements apart, such as utm_content=window and utm_content=counter. A UTM builder keeps your naming consistent, which matters because QR and qr end up as separate rows.

What inflates or blurs your scan count?

Automated traffic is a normal part of any web count. Imperva's 2026 Bad Bot Report says automated traffic made up 53% of all web traffic in 2025, up from 51% in 2024 (Imperva, 2026). On Cloudflare's network, humans made 47% of HTML requests as of December 2, 2025 (Cloudflare, 2025).

Neither figure is your QR code's bot rate. Imperva's blog doesn't publish its sample or method, and Cloudflare's figure covers HTML requests only, with non-AI bots at 44% and AI bots averaging 4.2%. What they do show is that a request count and a human count are different numbers. For short links behind QR codes, these are the usual suspects:

SourceWhat it doesEffect on your numbers
Microsoft Safe LinksScans URLs in email before delivery. Links without a valid reputation are "detonated asynchronously in the background", and rewritten links are checked again at click time (Microsoft Learn, 2026)Requests from Microsoft's systems if your tracked link also appears in an email
Slack link previewsSlackbot fetches links posted in channels and caches the result for about 30 minutes (Slack)About one extra request per URL per 30 minutes while it's being shared
Meta link previewsThe facebookexternalhit crawler fetches links shared on Facebook, Instagram and Messenger to build a title and thumbnail (Meta)Requests with no person behind them
iCloud Private RelaySafari traffic leaves through relay IPs that may be shared by several users and show a coarse city-level location, or only country and time zone (Apple)Blurred location, and several people can look like one
Apple Mail Privacy ProtectionDownloads an email's remote content in the background "regardless of whether you engage with the email" (Apple, 2025)Anything in the email that loads from a tracking server can register activity from nobody
Carrier-grade NATMobile carriers often put many subscribers behind one public IP address (EDPB Guidelines 2/2023, 2024)Different people share one IP, which blurs location and unique counts

Messaging apps differ in how they build previews. In a study published in October 2020, Mysk found that iMessage, WhatsApp, Viber and Signal built previews on the sender's device. Discord, Messenger, Instagram, LinkedIn, Slack and Zoom built them on a server (Mysk, 2020). That study is six years old, so apps may have changed. Our reading: a preview built on the sender's phone comes from a real phone, so it may be harder to tell apart from a scan.

A printed code on a shop counter is mostly scanned by people holding phones. The same link pasted into Slack or an email picks up machines. That's the best reason to keep the two apart.

Why is "unique scans" only an estimate?

We found no neutral standard for counting unique scans, so each vendor sets its own rules. One method, used by QR Planet, hashes part of the IP address: it drops the last part of the IP and hashes it with SHA-256, with the User-Agent as an option. QR Planet says this "might make the number of unique visitors smaller" (QR Planet).

Any IP-based method breaks in two directions:

What happensExampleEffect on uniques
Different people share one IPCustomers behind their carrier's shared IP, or Private Relay users on the same relaySeveral people merge into one
One person's IP changesSomeone scans on coffee-shop Wi-Fi, then again on mobile dataOne person splits into two

So a unique count can be too low and too high at once, and you can't tell which error is bigger for a given code. Compare uniques across your own codes, counted the same way. Don't compare them with another tool's uniques.

Is QR code analytics a privacy risk?

QR codes aren't a special privacy threat. After scanning 948 QR codes found in public and testing 37 generators, University of Illinois Chicago researchers found "no evidence that QR codes are a substantial or unique privacy threat" compared with other ways of sharing links (Siddiqi et al., 2023). A scan is still a web request, though, so the usual rules on IP addresses and tracking apply.

RuleWhat it saysWhat it means for scan data
Breyer, CJEU case C-582/14 (2016)A dynamic IP address is personal data for a site operator with the legal means to identify the visitor through the internet provider. A site may have a legitimate interest in storing it to guard against attacks (CJEU)Assume scan logs with IP addresses can be personal data in the EU. The ruling came before GDPR
EDPB Guidelines 2/2023 (v2.0, October 2024)Tracking links sent through messaging, and IP-based tracking, can fall under ePrivacy Article 5(3), the EU's cookie rule. That "does not systematically mean that consent needs to be collected" (EDPB)The board didn't analyze the exemptions, so whether a scan counter needs consent is unsettled
CNIL audience-measurement exemptionFrance exempts measurement from consent if it's limited to measurement and A/B testing, for one publisher, not combined with other data, with the last byte of the IP dropped, trackers kept 13 months at most, and users told and able to object (CNIL)A useful checklist, though the guidance covers cookies and trackers and doesn't mention server logs
CCPA, Cal. Civ. Code §1798.140(v)(1)Lists "Internet Protocol address" as an identifier, along with geolocation data and internet activity (California Legislature)Scan logs with IP addresses can be personal information for businesses the law covers
EU Digital Omnibus (proposed November 19, 2025)Would move the cookie rules into GDPR and allow some low-risk uses without consent, reportedly including aggregated first-party audience measurement (European Commission, Taylor Wessing)Only a proposal. Nothing has changed yet

The low-risk habits line up with CNIL's list. Count only what you'll use, keep scan data for a limited time, don't combine it with other personal data, drop or truncate IP addresses once geolocated, let people object, and say in your privacy notice that you count scans by location and device.

*This is general information, not legal advice. If your business depends on the answer, ask a privacy lawyer in your market.*

How to read your scan numbers

  1. Tag every destination with UTMs. Your analytics tool can then credit scans to the right campaign instead of Direct, and you can see what people did after the scan.
  2. Use one code per placement. A code on the window and another on the counter tell you which spot works. One shared code only tells you that something did. Our dynamic QR code guide covers setting them up.
  3. Compare scans with an outcome. Sales, form fills, bookings or coupon redemptions matter more than scans. If scans rise and outcomes don't, look at the page or the offer.
  4. Rely on country, treat city as a guess. By MaxMind's figures, country is right 99.8% of the time, and city lands within 50 km about two times in three.
  5. Read trends, not single spikes. A steady weekly count means more than one busy afternoon. Check any spike against when you shared the link in Slack, email or a social post.
  6. Keep print codes and shared links separate. If you email or post the short link your poster uses, previewers and security scanners land in the poster's count. Use a second link for digital sharing.
  7. Scan your own code before launch, then remember you did. Your test scans are in the total too.

What Whooshly shows for scans

Whooshly counts each dynamic QR code's scans against that code, separately from ordinary link clicks, with daily totals, breakdowns by country, device, referrer, UTM source and UTM campaign, and CSV export. The free plan keeps 7 days of analytics, and Core, a one-time $35, keeps 120 days. It doesn't know who scanned, and the limits in this post apply to it as they do to any tracker. Read the numbers with that in mind: a scan count is a signal, not a headcount.

Frequently asked questions

How accurate is QR code scan tracking?

The time and the code scanned are recorded exactly. Location is an estimate from the IP address: MaxMind states 99.8% accuracy for country, about 80% for US state and about 66% for city within 50 km. Counts can also include email security scanners and link previews, and unique scans are an estimate.

Can a QR code tell me who scanned it?

No. A scan gives the redirect server an IP address, a device and browser description, and a time, with no name or email. MaxMind says IP location is never precise enough to find a household or street address. You only learn who someone is if they tell you on your page, for example through a form.

Why do QR code scans show as Direct traffic in Google Analytics?

GA4 labels visits Direct when they arrive via a saved link or a typed URL, with no referring page. Scans usually appear to arrive without a Referer; no browser vendor documents this, so they often land in Direct. Add UTM tags to the destination URL your code points to and GA4 will credit the right campaign.

Do bots inflate QR code scan counts?

A bot can't scan a poster. It can request the link behind it, though. If that link is emailed or shared in chat, tools like Microsoft Safe Links, Slackbot and Meta's preview crawler can fetch it. Keep print codes and shared links separate. Imperva estimates automated traffic was 53% of all web traffic in 2025, though that isn't a QR bot rate.

What is the difference between total scans and unique scans?

Total scans count every request. Unique scans are each vendor's estimate of distinct people, made, for example, by hashing part of the IP address, sometimes with the device details. People sharing one IP merge into one unique, and one person whose IP changes becomes two, so compare uniques only within the same tool.

Is QR code tracking legal under GDPR?

It can be done lawfully, but scan logs with IP addresses can be personal data under the EU's Breyer ruling. EU regulators say tracking links and IP-based tracking can fall under the ePrivacy cookie rule, without that automatically requiring consent, and the exemptions are unsettled. This is not legal advice; ask a privacy lawyer for your case.

Keep Whooshly in your Google results

If our link and QR guides are useful, add Whooshly as a Preferred Source in Google.

Add as a preferred source on Google

Tap. Whoosh. You're there.

Buy Whooshly once and own your campaign links for good.

Quincy R. · Whooshly AI assistantAsk Quincy

Answers about products, pricing, and setup.

Make the QR work in the real world.

Ask about editing, printing, styling, scan tracking, or permanence.

Don't share passwords or private data. Privacy