Static vs Dynamic QR Codes: Which Ones Track You

Two QR codes can look identical, encode the same apparent destination, and differ completely in what happens when someone scans them.

One is a piece of paper. The other is a measurement instrument owned by a third party. Nothing on the printed square tells you which you are holding.

Static: the code is the payload

A static QR code contains the actual data. Scan it and you get exactly what was encoded — a URL, a phone number, a Wi-Fi credential, a block of text.

The properties follow directly:

  • It cannot be changed. The destination is in the pattern. Changing it means printing a new code.
  • Nobody is counting. There is no intermediary. The scan is between the phone and the destination, and the only party who learns anything is the destination itself, exactly as if the address had been typed in.
  • It works forever. There is no service to keep paying, no account to lapse, no company to go out of business. A static code printed today resolves in ten years.
  • It is larger. More data means a denser pattern. A long URL produces a busy code that needs to be printed bigger to scan reliably.

Dynamic: the code is a doorway

A dynamic QR code does not contain your destination. It contains a short URL on somebody else’s domain, which redirects to wherever you have currently pointed it.

  • It can be changed after printing, without reprinting.
  • Every scan is logged and attributed. This is the entire commercial proposition.
  • It is smaller — a short redirect URL makes a sparse, robust pattern.
  • It depends on a service. If the account lapses or the provider disappears, every printed code stops working, and the destination is not recoverable from the pattern because it was never in it.

That last point deserves more weight than it usually gets. A poster campaign, product packaging, a plaque on a building — all can be silently killed by a missed subscription renewal, and the printed artefact gives no clue what it was ever meant to point at.

What a scan actually reveals

When someone scans a dynamic code, the redirect service records the request before passing it on. From an ordinary HTTP request it can derive:

  • IP address, and from it approximate location and the network or carrier
  • Time, to the second
  • User agent — operating system, version, browser
  • Language settings
  • Referrer, in some flows
  • Which code, uniquely — this is the part that distinguishes it from ordinary web analytics

That last one is what makes it a tracking system rather than a link. Print the same campaign as ten codes across ten locations and each scan is attributed to a physical place. Print unique codes per item and each scan is attributed to a specific object — and, once that object is associated with a buyer, to a person.

None of this requires cookies, an app, or consent from the person scanning. They photographed a square.

This is not an accusation

Dynamic codes are a reasonable product solving a real problem. A restaurant whose menu changes weekly should not reprint table cards. A campaign that needs to know which billboard performed has a legitimate question. A manufacturer who must redirect a support code after a site migration would otherwise have to recall the packaging.

The problem is not that the capability exists. It is that the two are indistinguishable to the person scanning, and one of them silently collects while the other does not. There is no convention, no marking, nothing on the printed code to tell them apart.

Telling them apart

Scan with a plain text QR reader rather than letting the camera act on the code, and read the string.

  • A recognisable destination — example.com/menu — is static, or at least honest about where it goes.
  • A short opaque URL on a domain you do not recognise, especially with a random-looking path, is a redirect service.

You can also follow it and watch what happens: a redirect passes through the intermediary before landing. On a desktop browser this is visible in the network log; on a phone you will often see the address bar change.

Neither check tells you what is being logged. Both tell you whether anything is in a position to log.

Choosing, if you are printing them

Use static when the destination is stable, you do not need per-scan measurement, and longevity matters — plaques, product documentation, contact details, Wi-Fi credentials, anything that must still work when nobody is maintaining it.

Use dynamic when you genuinely need to change the destination after printing, or when scan measurement is the point. Then say so. A line reading “scans are counted” next to the code costs nothing and is the difference between analytics and surveillance-by-omission.

Never use dynamic for anything that must survive independently of a vendor relationship. Anything printed on a physical product that will outlive a marketing budget wants a static code pointing at a domain you own.

There is a middle path worth knowing: a static code pointing at a short path on your own domain, which you redirect server-side. You keep the ability to change the destination and you keep the logs, rather than handing both to a third party. The code stays static, the pattern stays yours, and if you ever stop redirecting, the URL is still yours to fix.

What ours does

Our QR generator produces static codes only. It has to — it runs entirely in your browser, with no server behind it. There is nothing to redirect through and nothing to log, because there is no back end at all.

Whatever you encode is what is in the pattern. You can confirm that by decoding the finished image with any reader and comparing it to what you typed, which is exactly the check we run in our own build.

Questions worth asking a dynamic QR vendor

If you are going to use a redirect service, the difference between a reasonable one and a bad one is answerable in advance.

What is retained, and for how long? IP addresses are personal data in most regulatory frameworks. A vendor who cannot tell you their retention period has not thought about it.

Is scan data shared, sold or aggregated across customers? Some platforms build audience data across every code they host. Your poster becomes a data source for somebody else’s product.

What happens when the account lapses? The good answer is that codes continue resolving, or that you get a long grace period and an export. The common answer is that they break immediately.

Can the destination be exported? You want a record of what each code points at, held by you, so that a printed artefact is recoverable if the service disappears.

Where is the data processed? Relevant if you operate anywhere with data-residency requirements.

Can you use your own domain? Some services allow a custom domain for the redirect, which is a meaningful improvement — the URL is recognisable, the code is not obviously a third-party redirect, and you retain the option to take over the redirection yourself later.

Tell people, and lose nothing

There is a version of dynamic codes that is entirely honest, and it costs one line of text.

Print “scans are counted” or “this link is tracked” beside the code. Almost nobody will care. Those who do can choose not to scan, which is the point.

The reason this matters is not regulatory compliance, though depending on jurisdiction it may help. It is that the alternative — collecting silently because the medium happens to make silence easy — is the sort of thing that reads badly when it eventually becomes visible. And it does become visible, because someone always decodes the string.

The asymmetry is the whole argument. Disclosure costs a line of small print. Non-disclosure costs your credibility on the day somebody notices, and buys you nothing in the meantime.


Generate static QR codes for links, Wi-Fi, contact cards, email, phone and SMS with our QR generator. Nothing is uploaded and nothing is counted.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top