Every scan of a dynamic QR code is recorded, on the free plan as much as on Pro.
Where the data comes from
A dynamic code points at a redirect. That redirect is an ordinary web request, and the server handling it can see what any web server sees: when it happened, what kind of device asked, and an approximate location worked out from the IP address.
That is the entire mechanism. No app, no camera access, nothing installed on the scanner's phone. It also explains why a static code records nothing: there is no server in the middle to do the seeing.
Three questions it answers honestly
Is this code being found at all? A poster with zero scans after a week is telling you something about placement or size, and it is telling you cheaply.
Did something change? Trends survive the noise even when absolute numbers do not. Scans doubling the week you moved the sign is a real answer.
Which platform and roughly where? Useful for deciding whether an Android store rule is worth adding, or whether a market you did not expect is scanning.
Four it does not, however it is presented
How many people scanned. Scans are events, not humans. One person testing a poster five times is five. A commuter passing a shop window every morning is one person and twenty scans.
Who they are. Nothing in the request carries identity. Approximate location comes from the IP address, which puts someone in a city and frequently the wrong one on mobile data or a VPN. Any tool implying it can tell you who scanned is describing something it cannot do.
Whether it led to a sale. That happens on the other side of the redirect. Someone scanning a pack in a shop without buying looks exactly like someone scanning it at home after buying. To connect scans to outcomes, the destination has to measure: a UTM-tagged URL and analytics on the landing page.
Whether a person was involved. Link previews and security scanners fetch URLs automatically. Paste a code's link into a group chat and every client that renders a preview card requests it. Unless the service separates those, a link shared in a work channel reads as a small crowd of customers. Toolember counts recognised previews and bots in their own column rather than in the scan total.
Recording and reading are different things
Most services gate collection behind the paid tier, so a free user upgrades and opens an empty chart with a note about history starting today. That is the worst possible first minute of a paid plan, and it is a product decision rather than a technical limit.
Toolember records every scan of every code regardless of plan, and Pro unlocks reading the detail. An account that upgrades finds the history already there. What plan does change on the scanner side is cosmetic: a Pro owner's password or scheduling pages carry no Toolember wordmark.
It is personal data, and it should be treated that way
An IP-derived location plus a device type is personal data under GDPR even with no name attached. That has three practical consequences: it belongs in a privacy policy in plain words, it needs a retention window rather than being kept forever, and the code owner should see aggregates rather than a log of individuals.
Toolember prunes scan events older than two years, and shows owners counts and breakdowns rather than identities. Our privacy policy spells out what is recorded, and scanner-facing pages link to the same explanation so the person scanning can read it too.
Frequently Asked Questions
What data does a QR code scan actually record?▾
Whatever the redirect server can see from the request: the time, the device type and operating system, an approximate location derived from the IP address, and which of your codes was scanned. It does not record who the person is, and there is no camera or app involvement. A static QR code records nothing at all, because nothing sits between the scan and the destination.
Does the scan count equal the number of people?▾
No. One person testing a poster five times is five scans. A code in a shop window scanned by the same commuter every morning is one person and twenty scans. Treat it as an interest signal that trends usefully over time, not as a headcount.
Can I see who scanned my QR code?▾
No, and be wary of any tool implying otherwise. The scan is an ordinary web request; it carries no identity. Approximate location comes from the IP address, which places someone in a city or region and often in the wrong one when they are on mobile data or a VPN.
Do previews and link scanners inflate the numbers?▾
They can, badly. Pasting a QR link into a chat app makes it fetch the URL to build a preview card, and security scanners follow links to check them. Those look like scans unless the service separates them. Toolember counts recognised previews and bots in their own column rather than in the scan total, so a link shared in a group chat does not read as twenty customers.
Does a scan tell me anything about a sale?▾
Only that someone reached the destination. Whether they bought, or already had, happens on the other side of the redirect. Someone scanning a pack in a shop and not buying looks identical to someone scanning it at home after buying. To connect scans to outcomes you need the destination to do the measuring, usually with a UTM-tagged URL and analytics on the landing page.
Is scan tracking a paid feature?▾
Recording is free on Toolember and always has been: every scan of every code is captured whatever plan the owner is on. Pro unlocks reading the detail rather than starting the collection, so an account that upgrades finds history already there instead of an empty chart.
Is any of this personal data?▾
Some of it is. An IP-derived location and a device type are personal data under GDPR even without a name attached, which is why it belongs in a privacy policy and why the retention window matters. Toolember prunes scan events older than two years rather than keeping them indefinitely, and the code owner sees aggregates, not identities.