Privacy & scan data
What a scan actually records.
See exactly what Lynkarr keeps, what it throws away, and how privacy controls work.
- No card required
- Free plan available
- Privacy controls included
What Lynkarr records
These details help you understand your audience and performance.
What Lynkarr does NOT record
These details are never stored with a scan.
The scan data pipeline
A quick look at how a scan is processed from start to finish.
- Scan request arrivesSomeone scans your QR code with their device.
- Location is derivedThe network the request came in on gives a country, region and city (city-level at finest).
- Repeat-visit hashThe network address and browser are hashed with a secret salt, to recognize a returning visit without identifying a person.
- IP is discardedThe IP address is discarded before the analytics row is written.
- Analytics row storedOnly the details listed above are saved to your analytics. No personal information is stored.
Returning visitors without identity
Lynkarr can recognize repeat visits without knowing who you are.- A hash of the network address and browser, with a secret salt
- Cannot be reversed into the original inputs
- Lets us show unique visitors without identifying anyone
EEA privacy window
For scans in the EEA, the salt used for returning-visitor detection rotates on a schedule.- Salt rotates on a regular schedule
- Old salt is permanently destroyed
- Returning visitors eventually stop being recognizable
- Outside the EEA the salt does not rotate
Strict privacy mode
Want even less data? Turn on strict privacy mode in your account settings.- The EEA’s rotating salt, for all of your scans
- Old salts are destroyed on the same schedule
- A returning visitor stops being recognizable when the window closes
What you can still learn
Get valuable insights without compromising anyone’s privacy.
- Total scans over time
- Top countries, regions and cities
- Device and browser breakdowns
- Referrers and campaign performance
- Which QR codes and destinations perform best
Frequently asked questions.
Do I need a cookie banner for my QR codes?
A scan sets nothing on the visitor's device, so there is nothing for a cookie banner to consent to. Whether your wider use needs a notice depends on your purpose and jurisdiction, and that judgement is yours. This is not legal advice.
Can I identify an individual scanner?
No, and neither can we. The hash recognizes a repeat visit and cannot be reversed into the inputs that made it.
What is different in the EEA?
The salt rotates on a schedule and the old one is destroyed, at which point a returning visitor stops being recognizable. It is a deliberate loss of data quality in exchange for a bounded window. Outside the EEA the salt does not rotate.
What if I want to record even less?
Turn on strict privacy mode in your account settings. Every scan then uses the rotating salt, wherever it comes from, so a returning visitor stops being recognizable when the window closes.
This describes what the product does. Whether your use of it needs a notice, a lawful basis or a record of processing depends on your jurisdiction and your purpose. That judgement is yours, and this page is not legal advice. Our privacy policy is here.
Try it with one code.
Create a QR code, explore your analytics, and see how Lynkarr keeps privacy at the forefront.
- No card required
- Free plan available
- Privacy controls included