How it works
The mechanism, not the marketing. If you have been burned by a QR platform before, this is the page that explains why it cannot happen the same way here.
Static codes: the destination is the pattern
A static QR code encodes its destination directly into the black-and-white pattern. The
text https://example.com/menu literally is the code. Nothing sits in
between, which has two consequences that matter.
It can never expire or be switched off — not by us, not by anyone, because there is no server involved in resolving it. And it can never be changed or tracked, for exactly the same reason.
Our generator makes static codes free, with no account, and you can make as many as you like on every plan.
Dynamic codes: the pattern points at a door you control
A dynamic code encodes a short address on our domain, like
scanmeplz.com/s/k3n9xq2. When someone scans it, we look up where that address
currently points and forward them there.
Because the printed pattern only ever contains the short address, you can:
- change the destination as often as you like, with no reprinting;
- see every scan — when, roughly where, on what kind of device;
- send different people to different places by country, device or date (Pro and above).
The trade-off is real and worth stating plainly: a dynamic code depends on our redirect existing. That dependency is why the rest of this page exists.
What happens on a scan, step by step
- The phone's camera decodes the pattern and gets the short address.
- The request hits the nearest Cloudflare edge location — usually within a few dozen milliseconds of wherever the person is standing.
- We do one indexed database lookup on the short address.
- We return a 302 redirect to the current destination, with caching disabled so that editing the destination takes effect immediately rather than when a cache expires.
- After the redirect has been sent, we record the scan: timestamp, country, region, city, device class, operating system, browser family and referring host.
Step 3 is deliberately the whole lookup. The redirect handler does not read your plan, your subscription, or your payment status — it has no reason to, and giving it one is how codes end up dying over billing. Step 5 happening last means a slow or failing analytics write can never delay or break a redirect.
What we record, and what we do not
We do not store the raw IP address of anyone who scans your code, and we do not store full user-agent strings against a scan. To tell a repeat scan from a new one we compute a salted hash that is specific to one code on one day; it cannot be reversed to a person, and it cannot be used to follow anyone between days or between codes.
Link-preview bots and crawlers are redirected like anyone else but are not counted, because a chat app generating a preview is not a customer scanning a sign.
What happens when billing goes wrong
Nothing, to the redirect. Codes over your plan's limit become frozen: still resolving, still counting scans, just not editable until you free a slot or upgrade. We freeze the newest codes first and keep the oldest ones editable, on the assumption that the oldest are the most likely to be printed on something expensive.
The full Permanence Promise, including what happens if we go out of business.
Designing a code that actually scans
Styling a QR code is where most generators quietly break them. Three rules are enforced for you rather than left to chance:
- The quiet zone stays at four modules or more. That blank margin is how a scanner finds the code against a busy background.
- Adding a logo forces error correction to its highest level, and the logo is capped at a share of the code the correction can actually recover.
- The finder, alignment and timing patterns stay square whatever dot style you pick. Rounding those into blobs is the single most common way a designed code stops being readable — they are what a decoder uses to measure the grid.
On top of that, the editor checks contrast as you work and warns you before you export if a code looks likely to fail in print.