Graklink Guides

What Graklink tracks when your code gets scanned, and what it doesn't

Updated July 24, 2026

What Graklink tracks when your code gets scanned, and what it doesn’t

A QR code scan takes about a tenth of a second. In that tenth of a second, a phone requests a redirect, gets sent to your destination, and one row gets recorded in your analytics. Here’s exactly what’s in that row, and just as importantly, what isn’t.

What actually gets recorded

Every scan logs a handful of things, all tied to the code. None of it is a name, an email address, or an account:

  • When it happened. A timestamp, nothing more.
  • A one-way visitor code instead of the real IP address. The actual address is never stored. It becomes a code computed with a secret key we hold, and that code is what makes unique-scanner counts possible (and it is why those counts are an estimate rather than a headcount, which we explain in total scans versus unique scans). The key never travels with the data, so the code cannot be turned back into an address by anyone who obtains the data. We hold the key, though, which is the part worth being precise about: the code is a pseudonym for a device, not a fact about nobody. It is closer to a locker number than to a name, and further from a name than it is from nothing.
  • Country and city. Coarse, network-level location, not GPS, not a street address. Enough to know your audience is mostly local, or surprisingly not.
  • Device type and operating system. Phone, tablet, or desktop, iOS or Android. Parsed from the same technical information every website already receives when a browser makes a request.
  • Where the scan came from. Whether it followed a link from somewhere, or was a direct scan with nothing in between.

That’s the whole list. It’s what makes the analytics on your dashboard possible, total scans, unique scans, timing, device mix, top locations, and nothing more than that.

What deliberately isn’t there

No cookies. No fingerprinting. No cross-site tracking that follows a scanner anywhere after they land on your page. Nobody has to log in, hand over a name, or agree to anything to scan a code, because nothing about scanning it requires knowing who they are.

The unique-scanner count is a direct result of this choice, not a limitation of it. Since there’s no cookie or device ID following people around, uniques are estimated from those one-way visitor codes instead, which can blur slightly on shared Wi-Fi. That’s a real tradeoff, and it’s the one worth making: a number that’s a close approximation instead of a person who’s being tracked.

Whose data this actually is

The scan data belongs to whoever owns the code, full stop. It’s never sold, and your specific scan history, which code, when, from where, is never shared with anyone else or shown outside your own account. Pro accounts can export the full scan history as CSV or JSON straight from the dashboard, the exact same data the charts are already built from, nothing summarized away, nothing extra bolted on.

If you’re deciding whether to put a QR code somewhere a customer will see it, this is the actual answer to “what happens when someone scans it”: a handful of technical facts land in your own analytics, none of them a name, and nothing about the person who scanned it goes anywhere else.

Make one that scans

Point it anywhere. Change it anytime. Print it forever. $7.99, once.

Where should it point?

Your website, menu, listing, anything on the web.

Customize the look
Quick styles
Primary color

Secondary color

Background

Shape
Premium Customization $4.99
Add your logo
Frame
Personalize your address from $1.99
solidqr.co/

Leave blank for a free random address.

Choose your analyticschoose one

✓ Scan-checked: strong contrast, reads at print size

solidqr.co/•••••

One payment, one time,
scans forever.

Powered by Stripe

30 day money back guarantee

Common questions

Does Graklink track the people who scan my code?

Not by name. Each scan records the timestamp, a one-way visitor code computed with a secret key we hold instead of the actual IP, coarse location (country and city, not an exact address), device type, operating system, and where the scan came from. Nothing here is tied to a name, an email, or an account, and nothing follows that person anywhere else after the scan. The visitor code is a pseudonym for a device rather than an anonymous number, because we hold the key that made it.

Does scanning a Graklink code use cookies?

No. There are no cookies, no fingerprinting scripts, and no cross-site tracking on the scan itself. The data comes entirely from the request the phone makes when it hits the redirect, nothing installed, nothing that persists on the scanner's device.

How exact is the location data?

Country and city level, from the network the phone was on at the moment of the scan, not GPS and not a street address. It is coarse by design, enough to tell you which city your audience is scanning from, not enough to point to a specific person or place.

Who owns the scan data?

The code's owner. It is never sold, and Pro accounts can export their own scan history as CSV or JSON directly from the dashboard, the same data the dashboard charts are built from, nothing extra added or held back.

Search Graklink