🛍️

QR Codes for Retail — In-Store Analytics Without GDPR Risk

Product pages, promotions, loyalty programs, and in-store WiFi — with privacy-by-design tracking.

How retail & e-commerce use Qrius

Product detail pages from shelf labels
Promotional campaign QR with scan analytics per store
Loyalty programme registration on receipts
In-store WiFi access without password handover

Retail & E-commerce and GDPR — what you need to know

Retail customers have strong GDPR protections. Tracking in-store scan behaviour with raw IP addresses requires consent and a valid DPA. Qrius eliminates this burden by making scan analytics inherently non-personal.

Qrius never stores raw IP addresses, sets no cookies on scan, and keeps all data on EU servers in Stockholm, Sweden. Full GDPR Article 28 DPA available on paid plans.

Full GDPR technical overview →

Recommended QR code types

URL / Dynamic linkWiFi QRvCard

All types available in the free generator and QR explorer.

Frequently asked questions

Can I track which in-store promotions drive the most scans?

Yes. Each QR code has its own analytics — total scans, daily trends, device type. You can A/B test placements (shelf vs. window vs. checkout) by creating separate QR codes for each location and comparing scan volumes.

Do I need customer consent to use QR codes in-store?

With Qrius, no consent is needed for the QR scan itself. We don't set cookies, don't log IP addresses, and don't fingerprint. Customers scan and see your product page. No personal data is created in the process.

Can I run seasonal campaigns and change QR targets without reprinting?

Yes. Dynamic QR codes let you update destinations from your dashboard. Run Black Friday campaigns, then update the same QR code to Christmas promotions — the printed code works continuously.

Is Qrius suitable for multi-location retail chains?

Yes. You can organise QR codes by store location in folders, assign team members per region, and compare performance across locations from one dashboard. Business and Enterprise plans support this workflow.

🇪🇺

GDPR-compliant by design — not by policy

Your visitors' IP addresses are never stored. On each scan we run a geo-lookup, then immediately hash the IP with HMAC-SHA256 and a daily rotating salt. The original address is discarded. No cookies. No fingerprinting. All data stays on EU servers in Stockholm, Sweden.

✓ No raw IP addresses✓ No cookies✓ EU hosting✓ DPA available✓ Schrems II safe

Need documentation for your DPO? Full GDPR overview → · Download DPA →

Ready to get started?

Free plan available. GDPR-compliant from day one. No credit card required.

Create free account →