Resources

What a scan actually records

Specifically, and including what it deliberately does not. If you are putting a code on something the public will scan, you are the one who has to be able to answer this.

What is recorded

The time. The country, region and city, derived from the network the request came in on. The device type, operating system and browser, with versions. The referrer, when the browser sends one. Which code was scanned, and where it forwarded to.

What is not

No IP address is stored against a scan. It is used to derive the location and then discarded — the row that reaches the database never had one.

No precise location is recorded, and no analytics figure anywhere in this product came from a phone's location sensor. City-level from the network is as fine as it gets, and in some countries that is a very large city.

A scanner is asked in exactly one place, and never for reporting: a code with a rule about a place asks, uses the answer to send that one person, and does not keep it. Refusing is fine.

No name, no email, no advertising identifier, and nothing that follows somebody to another site. Scanning a code sets nothing any other site could read.

Why precise location is not in the reports

Several competitors offer it as a switch that shows every scanner a permission prompt. We have decided against it. The browser's prompt names a web address, not who is collecting or what for, so it is not the consent this needs; most people never answer it anyway, which makes the figures a self-selected slice shown as the whole picture; and a granted permission can still return a position accurate to kilometres, drawn on a map as a precise pin.

Returning visitors, without identity

To say "this is the same person as an hour ago" we hash the signals above with a rotating secret salt. The result identifies a visit as a repeat without identifying a person, and cannot be reversed into the inputs.

For scans from the EEA the salt is rotated on a schedule and the old one destroyed, at which point a returning visitor stops being recognisable. That is a deliberate loss of data quality in exchange for a bounded window.

Strict privacy mode

Available per account. It drops the fingerprint entirely, so everything is counted as an anonymous visit and "unique visitors" stops being reported rather than being reported wrongly.

This describes what the product does. Whether your use of it needs a notice, a lawful basis or a record of processing depends on your jurisdiction and your purpose — that judgement is yours, and this page is not legal advice. Our privacy policy is here.

What you can do with it

The address is used and then gone

It derives the country the edge reported and a salted fingerprint, and is then discarded. The row that reaches the database never had an IP address in it, which is a stronger guarantee than a policy promising not to look at one.

Nobody is ever asked where they are

The browser's location permission is never requested, so there is no prompt and no precise coordinate. City-level from the network is as fine as it gets, and in some countries that is a very large city.

Nothing follows anybody to another site

No advertising identifier, nothing readable by any other site, and nothing written to the visitor's device by a scan.

More in the same place

Country and city From the network, never from a prompt.
Device and browser Type, system and version.
Referrer When the browser chooses to send one.
No IP stored The column does not exist.
Rotating salt EEA fingerprints stop being recognisable.
Strict mode Drops the fingerprint entirely, per account.

Questions

Do I need a cookie banner for my QR codes?

A scan sets nothing on the visitor's device, so there is nothing for a cookie banner to consent to. Whether your wider use needs a notice depends on your purpose and jurisdiction, and that judgement is yours — this is not legal advice.

Can I identify an individual scanner?

No, and neither can we. The fingerprint recognises a repeat visit and cannot be reversed into the inputs that made it.

What is different in the EEA?

The salt rotates on a schedule and the old one is destroyed, at which point a returning visitor stops being recognisable. It is a deliberate loss of data quality in exchange for a bounded window.

What if I want to record even less?

Turn on strict privacy mode. Everything is then counted as an anonymous visit, and "unique visitors" stops being reported rather than being reported wrongly.

Try it with one code

The free plan has no expiry and asks for no card, and the analytics behind it are the same ones a paying customer gets.

Free forever for one person. No card, and 10,000 scans a month included.