QRCode SuiteQR platform
Privacy

Privacy-First QR Code Analytics

QRCode Suite tracks QR code scans without ever storing a raw IP address. Every IP goes through an HMAC-SHA-256 hash keyed by a deployment secret before anything is written, so the original address cannot be recovered from what we keep. Bot traffic is filtered out of your counts, no advertising or cross-site tracking cookies are set on scanners' devices, and a background worker purges scan events automatically once your plan's retention window elapses. Your scan data is first-party: it is never sold, never shared with an ad network and never enriched by a third-party tracker.

Privacy-first analytics included on all plans, including Free.

Start free See pricing

Keyed HMAC-SHA-256 IP hashing

Before any scan event is stored, the scanner's IP address is put through an HMAC-SHA-256 hash keyed by a deployment secret, and only a truncated hash is written. The original IP cannot be recovered from it, and the key makes precomputed rainbow-table lookups useless.

No raw IP storage

Raw IP addresses are never written to the database — not even temporarily. The hash is computed in memory on the redirect path and only the hash is persisted. This applies to every scan on every plan, including Free.

Bot detection and filtering

Every scan is matched against 26 known bot, crawler, scraper and link-preview user-agent patterns. Matching scans are flagged as bot traffic, excluded from your reported counts, and never forwarded to integrations or webhooks.

No advertising or tracking cookies

Scan analytics are recorded server-side from the redirect, using the hashed IP and a hashed session value rather than a cookie. QRCode Suite sets no advertising and no cross-site tracking cookies on scanners' devices.

Automatic, plan-based retention

Retention is enforced by the platform rather than left to you to remember. A background worker purges scan events once your plan window elapses — 30 days on Free, 12 months on Pro, 24 months on Business, 36 months on Agency — which is GDPR Article 5(1)(e) storage limitation applied by default.

First-party data, never resold

Scan events live in QRCode Suite's own database, scoped to your workspace. They are never sold, never shared with an ad network and never enriched by a third-party tracker. Nothing reaches GA4 or Meta unless you connect that integration yourself.

Frequently asked questions

How does QRCode Suite handle IP addresses?

QRCode Suite never stores raw IP addresses. Before any scan event is recorded, the IP is put through an HMAC-SHA-256 hash keyed by a deployment secret, and only that hash is written. The original IP cannot be recovered from it.

Does QRCode Suite filter bot traffic?

Yes. Scans are matched against 26 known bot, crawler, scraper and link-preview user-agent patterns. Matching scans are flagged as bot traffic, excluded from your reported counts, and never forwarded to integrations or webhooks.

Is QRCode Suite compliant with GDPR?

QRCode Suite is built with GDPR in mind: raw IP addresses are never stored, only a keyed hash; bot traffic is filtered out; scan events are purged automatically once your plan retention window elapses; and nothing is forwarded to a third-party platform unless you connect it. Consult your legal team for your specific compliance obligations.

How long is scan data kept?

Retention is enforced automatically per plan — 30 days on Free, 12 months on Pro, 24 months on Business, 36 months on Agency. A background job purges events past that window, so old scan data does not accumulate.

Does QRCode Suite use tracking cookies?

No advertising or cross-site tracking cookies are set. Scan analytics are recorded server-side from the redirect itself, using a hashed IP and a hashed session value rather than a persistent identifier.

Track QR scans without ever storing a raw IP

Keyed IP hashing and bot filtering on every plan, including Free.

Start freePrivacy & data handling