Collect only what a QR journey actually needs
Opening the linked page can start analytics, cookies or a tailored view. Collect the minimum the service requires, and show a clear consent step before any personalised content.
Signals that may appear after a scan
A usual trail logs when the scan happened, the kind of device, the referrer and UTM tags. Personalisation can add an identifier in the URL or a cookie. The static image does not watch anyone by itself. Those records appear on the landing page or the analytics tool the link reaches.
How to stay fair
Keep the parameter list short and drop extras you do not need. Say why each piece of data is requested. Ask for consent before you personalise, never afterwards. Where the flow allows it, let people refuse tracking and still reach the main content.
What to change in the build
Hash or anonymise identifiers, cut cookie lifetime and restrict who can open raw logs. Leave names and phone numbers out of the query string. On dynamic flows in QRcode Global, check which events the analytics cabinet actually stores.
Where the law steps in
Consent rules, privacy notices and data-subject rights depend on the jurisdiction. Treat this page as general guidance, not legal advice. Have counsel or your DPO review the policy text and banners before a campaign that processes personal data.
A poster that shows the trade
The poster opens an offer page at once, so the base content is immediate. A personal discount appears only after an explicit consent to processing. People see what they give and what they get, and a plain scan is not mixed with profiling.
Try the consent gate
The interactive controls live only in the Ukrainian block, so element IDs in materials.js stay unique.
