The Redirect Trap: How Middle-Man QR Codes Track You
Dynamic QR codes route every scan through a server that can log who, where and when. How QR redirect tracking really works.
Every time you scan a dynamic QR code, your tap may pass through a stranger's server first — and that server can quietly note when you scanned, roughly where you were, and what phone you used. This is the redirect trap, and most people never know it's there.
QR codes feel wonderfully direct: point, scan, arrive. But a whole category of codes puts an invisible middleman between you and the page you think you're visiting. If you're a business, that middleman is sold to you as "analytics." If you're the person scanning, it's tracking you didn't consent to and can't see. Let's open up how QR redirect tracking actually works, what it can and can't capture, and what it means for privacy on both sides of the code. 🐾
The two kinds of code, one more time
A static QR code encodes your destination directly. Scanning it sends your phone straight to the real URL — no server sits in between, so there's nothing to log. A dynamic QR code instead encodes a short link on the vendor's domain, which redirects to the real destination. That redirect step is the whole trick: for a fraction of a second, your request lands on the vendor's server before bouncing onward, and in that moment it can be recorded. Our overview of static vs dynamic QR codes covers the basics; here we focus on the tracking.
How a redirect turns a scan into data
When your phone opens a link, it doesn't just receive a page — it also hands over some information as part of the ordinary mechanics of the web. A redirect server can read and log:
- Time and date of the scan, down to the second.
- Approximate location, derived from your IP address — usually accurate to a city or region, not your exact spot.
- Device and software, from the user-agent string your browser sends: phone type, operating system, browser.
- Referring context in some cases, and repeat-visit signals if cookies or identifiers are set.
None of this requires anything sneaky or illegal. It's the normal exchange every web request makes — the redirect just positions the vendor to capture it before passing you along. Multiply that by every scan of every code they host, and you get a large, continuous stream of behavioral data.
A static code is a signpost: it points and says nothing. A dynamic code is a turnstile: everyone who passes through is counted, timed, and noted.
What the redirect cannot see
Fairness matters, so let's be precise about the limits. A QR redirect is not a wiretap. It generally cannot:
- Read your precise GPS location — IP gives a rough area, not a pin.
- See other apps, your contacts, your files, or your messages.
- Install anything or "hack" your phone just by redirecting. (For what codes genuinely can't do, see QR codes and malicious URLs.)
- Necessarily identify you by name, unless the destination page itself asks for and links that information.
So the redirect trap is about silent, aggregate behavioral tracking, not surveillance of your device's contents. That's less alarming than the scare stories — but it's still data collection the scanner never agreed to.
Why this matters to the person scanning
If you're just trying to read a menu, you probably don't expect a third-party company to log your visit. Yet with a dynamic code, that's exactly what can happen — and you have no way to tell by looking. The code gives no visible sign of whether it's static or dynamic. The privacy concerns are real:
- No consent, no notice. There's no cookie banner on a QR code. You're logged before you've seen a single word.
- Profiles over time. If the same vendor hosts codes across many businesses, your scans across all of them can, in principle, be correlated.
- Data you can't reach. The log lives on the vendor's servers, under their policies, not the business you thought you were dealing with.
Why this matters to the business, too
If you own the code, tracking sounds like a feature — and sometimes it genuinely is. But it comes with quiet liabilities. You're routing your customers' scans through a third party whose data practices you don't control, and you're staking your printed materials on that third party staying alive (the dependency we cover in what a dynamic QR code is really costing you). If your brand markets itself as privacy-respecting, a silent redirect tracker sits awkwardly with that promise.
How to protect yourself as a scanner
You can't always avoid dynamic codes, but you can scan more mindfully:
- Preview the link. Most phone cameras show the URL before opening it. A short link on an unfamiliar domain is a sign of a redirect.
- Watch the address bar. If you land somewhere different from where the link seemed to point, you passed through a redirect.
- Use privacy tools. A VPN blurs your IP-based location; tracker-blocking browsers limit what follows you after the redirect.
- Be extra cautious with unexpected codes. Our QR code safety checklist helps you decide when to scan at all.
How to respect people as a code owner
If you're making codes, the privacy-friendly path is straightforward: use a static code so there's simply no redirect to log anyone. Your customers go straight to your page, and no third party sits in between. You can create a free static QR code that does exactly this — no account, no tracking, no expiry.
If you genuinely need analytics or an editable destination, prefer to run the redirect on your own domain, under your own privacy policy, rather than handing your visitors' data to a vendor. You get your numbers, your customers know who's collecting them, and nobody can hold the code hostage — the approach we describe in the case for static, open QR codes.
The honest summary
Dynamic QR codes aren't spyware, and analytics aren't evil. But a redirect quietly turns a simple scan into a logged event, on someone else's server, with no notice to the person scanning. When you don't need that — which is most of the time — a static code is the cleaner, kinder, and more honest choice. It's a core reason QR Puppy makes only static codes, as our manifesto explains.
Frequently asked questions
Can a QR code track my exact location?
Not on its own. A dynamic code's redirect can log an approximate location from your IP address — typically a city or region — but not a precise GPS pin. Precise location would require the destination page to ask for it and you to grant permission.
How do I know if a QR code is tracking me?
You often can't tell just by looking, but previewing the link helps. If it points to a short URL on an unfamiliar domain that then redirects elsewhere, you're passing through a middleman that can log the scan. A link straight to the real destination is static and logs nothing.
Does a static QR code track anything?
No. A static code sends your phone directly to the destination with no server in between, so there's nothing to record the scan. Any tracking after that comes from the destination website itself, exactly as if you'd typed the address in.
Is QR redirect tracking legal?
Generally yes — it uses the same request data every website receives. The concern is transparency and consent: the person scanning usually has no idea a third party is logging them, and depending on the region, silent collection can bump against privacy regulations.
Can I get scan analytics without tracking my customers through a vendor?
Yes. Run the redirect on your own domain under your own privacy policy, so any data collected stays with you and your customers know who's behind it. Or skip analytics entirely with a static code and keep the whole interaction private.
Make a QR code the honest way 🐾
Free forever, no tracking, no expiry — generated right in your browser.