Tracking

How to Track QR Code Scans in Google Analytics 4

The clean setup uses two measurement layers: the QR platform records that a specific printed code was scanned, and GA4 records what the visitor did after arriving on your site. They answer different questions, they will not agree on the numbers, and trying to make one behave like the other is where most QR tracking setups go wrong.

Written by
VastQR Product & Editorial Team
Last updated
On this page
  1. The two-layer setup
  2. Decide naming first
  3. Step-by-step setup
  4. A UTM template
  5. Separating placements
  6. Why the numbers differ
  7. Editing a live destination
  8. GA4 and static codes
  9. FAQ

The two-layer architecture

  1. Printed QR
  2. VastQR redirect
  3. Tagged destination URL
  4. Your website
  5. GA4
VastQR measures the handoff at step two. GA4 measures the visit at step five.

An example destination:

https://example.com/menu?utm_source=offline&utm_medium=qr&utm_campaign=spring_menu&utm_content=richmond_table_14

Nobody sees that URL. The printed artwork encodes the short redirect, so the parameters can be long and descriptive without making the QR pattern denser or harder to scan.

The questionAnswered by
Did Table Tent 14 get used?QR redirect analytics
Which placement produced the most scans?QR redirect analytics
Did those visitors read the menu?GA4
Did the campaign produce orders?GA4
How many requests never became a page view?The gap between the two

Decide the naming convention before you print

The most common GA4 mistake is not a missing parameter. It is three people using qr, QR and print for the same thing, and someone spending a day cleaning it up in a spreadsheet six weeks later.

Being precise about what is and is not recoverable here matters, because the two halves behave differently. A dynamic QR code’s destination stays editable after printing, and so do the UTM parameters attached to it — you can fix a convention at any point, and every scan from then on arrives under the corrected names. What no product can do is go back and rename the sessions GA4 already filed. Those months stay split across whatever names were in use at the time.

So the cost of deciding late is not a reprint. It is a gap in the record. Pick once, write it down, and apply it to every destination in the batch:

ParameterWhat it should carryExample
utm_sourceThe origin familyoffline
utm_mediumThe mechanismqr
utm_campaignThe business campaignfall_menu_2026
utm_contentThe physical placementrichmond_table_14
utm_termUsually unnecessary for QRleave empty unless you have defined a use
Use the taxonomy you already have
If your organisation already has campaign naming rules for paid and email, extend them. Inventing a QR-only scheme means your offline channel cannot be compared with anything else in the same report.

Setting it up, step by step

  1. Confirm GA4 is already working on the destination site

    Open the page and check the property is receiving ordinary web activity. Do this first — otherwise you will spend an afternoon blaming QR attribution for a missing tag.

  2. Build the tagged destinations

    One row per placement, each with the same campaign and a distinct utm_content. A spreadsheet is the right tool here: it is easy to see at a glance whether the taxonomy was applied consistently.

  3. Create the dynamic codes from that list

    Paste or upload the CSV so each tagged URL becomes the destination of one managed code. The parameters live in the destination, not in the printed pattern.

  4. Scan one before printing anything

    On a real phone. Confirm the redirect resolves, the final URL loads, the parameters survived the redirect, and GA4 registered the session.

    Parameters surviving the redirect is the step people skip and the step that most often breaks.

  5. Verify traffic-source reporting in GA4

    Check Traffic acquisition, or build an exploration on the session-scoped source, medium, campaign and content dimensions. Be explicit about whether you are looking at user-, session- or event-scoped dimensions; they will not agree, and that is by design.

  6. Print a physical proof and scan that

    At final size, from the distance people will actually stand. A browser test proves the tagging; only the printed proof proves the deployment.

Have your tagged destinations ready?

Paste the list, see which rows validate, and preview the whole batch before you pay for anything.

A reusable template for a QR campaign

Sixty codes across three stores, one campaign called summer_combo_2026. Every destination shares the source, medium and campaign; only the content changes:

Placementutm_contentEverything else
Richmond, table 1richmond_table_01source=offline · medium=qr · campaign=summer_combo_2026
Burnaby, table 1burnaby_table_01identical
Vancouver, windowvancouver_window_01identical

Now GA4 can report the campaign as one thing and still break it down by placement, while VastQR reports which individual code was scanned. Two systems, one taxonomy, no conflict.

Separating placements without wrecking your reports

There are two strategies, and only one of them scales.

Unique utm_content — use this by default

Right whenever the placements belong to the same campaign. The campaign stays legible and the detail is still there when you want it.

Unique campaign names — only for genuinely separate campaigns

Right when the placements have different objectives and different owners. Wrong as a way of separating three hundred table cards, which turns the campaign report into a directory.

The failure mode
Three hundred campaign names is not granular reporting. It is a report nobody opens twice.

Why redirect counts and GA4 sessions never match

Between a scan and a GA4 session there are seven things that have to happen: the camera recognises the code, the person taps the link, the redirect receives the request, the browser follows it, the destination begins loading, the GA4 tag executes, and consent and browser settings permit measurement. Any of them can fail independently.

Divergence is therefore expected. What matters is that each system is internally truthful about what it measured.

What happenedQR redirect countGA4 session
Person scans, page loads normallyYesLikely yes
Person opens, then closes before the page loadsYesOften no
A link preview or crawler requests the short linkYes, labelled where recognisedUsually no
Page loads but consent is denied or the tag is blockedYesOften no
Visitor refreshes the landing pageNo new requestMore GA4 activity
Same person scans three timesThree eventsDepends on session timing

Do not demand equality between the two. Demand that you can explain the gap — which is exactly what a visible automated-traffic figure on the QR side is for.

What actually counts as a scan →

What happens to attribution when you edit a live destination

A dynamic code lets you change the destination after printing, which creates a reporting decision most guides skip.

  • Same campaign, page moved: keep the taxonomy identical. Changing it splits one campaign into two for no analytical reason.
  • New campaign entirely: update the parameters along with the destination, because the old campaign name no longer describes what the visitor is seeing.

Either way, write down the date. The parameter change applies to traffic from that moment on; the sessions GA4 already recorded keep the names they were filed under. A before-and-after comparison that silently spans both is worse than no comparison.

GA4 does not make a static code dynamic

You can put a tagged URL inside a static QR code and measure the resulting website traffic in GA4. That is genuinely useful, and it is why the claim “static QR codes cannot be tracked” is wrong.

What GA4 does not give the static code:

  • an editable destination;
  • a managed redirect;
  • a pause state;
  • a library of codes to manage;
  • a scan count for the code itself, as opposed to a session count for the page.

That is the exact line between website attribution and dynamic QR operations.

What redirect-level QR tracking shows →

Frequently asked questions

Do I need GA4 to track QR scans?
No. A dynamic QR platform records redirect-level scan events on its own. GA4 adds what happens after the visitor reaches your website — engagement, key events, conversions.
Can a static QR code use GA4?
Yes. Put campaign parameters in the destination URL and GA4 will read them when the page loads. You get website attribution without the code being dynamically managed.
Why are my QR scans higher than my GA4 sessions?
Because the two measure different boundaries. A redirect request is recorded even when the visitor closes the tab before the page loads, when a crawler touches the link, or when consent or an ad blocker stops the GA4 tag.
Should every QR code get a unique UTM?
Not a unique campaign. Use one campaign for the campaign, and a unique utm_content per placement. Three hundred campaign names make GA4 unreadable.
Does VastQR integrate with GA4 automatically?
No. There is no native integration. The connection is the campaign-tagged destination URL you configure — VastQR measures the redirect, GA4 measures the site.
Should utm_source be qr or offline?
Either can be internally consistent. Treating offline as the source and qr as the medium usually extends better, because the same source family can then hold other offline mechanisms. What matters far more is not changing convention halfway through a campaign.

Sources