Free tier, no card requiredDynamic QR codes that update after printGDPR-compliant scan analyticsBuilt for agencies, freelancers & in-house teamsFree tier, no card requiredDynamic QR codes that update after printGDPR-compliant scan analyticsBuilt for agencies, freelancers & in-house teamsFree tier, no card requiredDynamic QR codes that update after printGDPR-compliant scan analyticsBuilt for agencies, freelancers & in-house teamsFree tier, no card requiredDynamic QR codes that update after printGDPR-compliant scan analyticsBuilt for agencies, freelancers & in-house teams
All posts
A QR code linking to a feedback card with a five-point mood rating scale and an NPS-style gauge.
Guide

QR code feedback surveys: how to turn every touchpoint into a response (and actually act on it)

How to run QR code feedback surveys that agencies can defend: the right survey type for the moment, how many questions actually get answered, and how to route responses without breaking Google's review policy or the FTC's rules.

ScanKit

ScanKit · Organization

· 16 min read

QR code feedback surveys: how to turn every touchpoint into a response (and actually act on it)

A feedback QR code sits on a receipt, a table tent, a hotel keycard sleeve or a clinic's exit signage, and it asks one question: how did we do? For an agency running campaigns across dozens of client locations, that small sticker is one of the highest-value codes you'll ever print, because it closes the loop between a physical touchpoint and a number a client can act on. Done well, it replaces guesswork with a stream of structured, timestamped, location-tagged feedback. Done badly, it becomes a compliance liability or a stack of unread responses nobody reads.

This guide covers what actually moves response rates (and what doesn't, despite what most QR vendor blogs claim), which survey format to use for which moment, how to route the responses you collect without breaking Google's review policy or the FTC's 2024 rule on incentivised reviews, and how to run this across many client locations from one workspace.

Why QR codes work for feedback, and why the "3x more responses" claim doesn't hold up

Most articles on this topic repeat a version of "QR codes get 3-5x more survey responses than email." It's a comforting number for anyone selling QR-code tools, but the one controlled study that actually tested it found the opposite: in a 2018 Gallup experiment with roughly 7,500 respondents, offering a QR code alongside a printed URL produced no statistically significant lift in response rate over the URL alone, and only 4% of people who did respond chose to scan rather than type. If you're citing a response-rate multiplier to a client, ask where the number comes from. In most cases it traces back to a single vendor's self-reported user base, not an independent study.

That doesn't mean QR feedback surveys are a bad idea. It means the value isn't "a QR code makes people 3x more likely to answer." The real value is capturing feedback at a moment when no other channel exists: a diner at a table with no email address on file, a hotel guest checking out at 6am, a patient leaving a clinic. A QR code turns a physical moment into a digital one without the friction of a written URL, a scavenger hunt through a website, or a follow-up email that arrives two days after anyone remembers the visit. You're not competing with email response rates; you're competing with silence, because without the code, most of that in-the-moment feedback would never be collected at all.

NPS, CSAT and CES: pick the survey type to match the moment

Three survey formats cover almost every feedback use case, and they measure different things. Using the wrong one for the moment is the most common mistake agencies make when setting up a client's first feedback code.

Net Promoter Score (NPS) asks a single relationship question: "On a scale of 0 to 10, how likely are you to recommend [business] to a friend or colleague?" Respondents scoring 0-6 are detractors, 7-8 are passives, and 9-10 are promoters. The score is the percentage of promoters minus the percentage of detractors, giving a range from -100 to +100. NPS measures loyalty and is best run infrequently, for example once per stay, once per quarter, or once per major service interaction, not after every single transaction.

Customer Satisfaction (CSAT) asks about one specific interaction: "How would you rate your satisfaction with [the service/product] you just received?", usually on a 1-5 scale. CSAT is transactional and works well immediately after a specific event, a meal, a repair, a checkout, because it measures that moment rather than the overall relationship.

Customer Effort Score (CES) asks respondents to rate agreement with a statement like "[Business] made it easy for me to handle my issue," typically on a 1-7 scale. CES is the right tool after support interactions, returns, or anything where the real question is "was this a hassle?" rather than "were you happy?"

For a QR code on a receipt or table tent, CSAT is usually the right default: it's transactional, fast, and tied to the visit that just happened. Save NPS for a lower-frequency touchpoint like a post-stay email-to-QR follow-up, and reserve CES for service and support flows.

Keep it short: what the data says about question count and completion

An analysis of over 21,000 surveys collected across 50+ industries in 2025 found completion rates fall steadily as question count rises: 85.7% for a single-question survey, 80.7% for two questions, 77.4% for three, dropping into the low 70s by five or six questions. There's no single magic number, but the pattern is consistent: every additional question costs you a measurable slice of respondents, and the cost is front-loaded, the drop from one question to two is steeper than the drop from five to six.

For a QR-triggered survey specifically, where someone is standing at a till, a table, or a checkout desk rather than sitting at a desk with time to spare, the practical target most agencies converge on is three to five questions completable in under a minute: one rating question (NPS, CSAT or CES depending on the moment), one open-text "what could we improve" field, and at most one or two optional demographic or routing questions. Anything beyond that and you're trading data depth for data volume, and for a QR code specifically, volume is what makes the number statistically meaningful at a single location.

Change the questions without reprinting the sticker

The single biggest practical advantage a dynamic QR code has over a static one in a feedback context has nothing to do with response rate: it's that the destination can change without reprinting the code. A feedback sticker printed once and laminated onto a table can point to a different survey in January than it does in July, run a seasonal question about a new menu item, switch from CSAT to NPS for a quarterly pulse check, or get redirected entirely if a client changes their feedback platform. None of that requires touching the physical sticker. For an agency managing feedback programmes across many client sites, this is what makes the programme maintainable: the print run happens once, the survey content iterates continuously.

Routing responses: what's a good idea and what's a regulatory problem

This is where most feedback QR programmes get into trouble, because a tactic that looks like smart marketing is, in two specific and common forms, against the rules of the platforms and regulators involved.

The tactic in question is star-rating gating: ask a quick rating first, and if it's high, send the respondent on to leave a public review on Google; if it's low, route them to a private feedback form instead so the negative comment never reaches a public page. It's an appealing idea because it seems to protect a client's public rating while still capturing the complaint. It is also explicitly against Google's Business Profile policy, which prohibits businesses from discouraging negative reviews or selectively soliciting positive ones, and against the spirit of the FTC's 2024 Trade Regulation Rule on Consumer Reviews and Testimonials, which took effect in October 2024 and prohibits compensating or otherwise steering reviews based on the sentiment they're expected to express. The FTC rule's own penalty ceiling per violation is set high enough (currently just over $51,000) that "everyone does it" is not a useful defence.

The fix is straightforward and doesn't require giving up either goal. Run two separate, non-gated channels: an open invitation to leave a public review that goes to every respondent equally, routed the same way regardless of what they said in a private survey, and a private feedback form that exists to collect operational detail for the business, not to filter who gets asked publicly. If someone leaves a glowing private survey response, you can still thank them and mention the option to leave a public review; you just can't make that offer conditional on what they said. Incentivising completion of the private survey itself (a discount code, a small offer) is fine under the FTC rule, because it isn't tied to a specific sentiment; incentivising or gating a public review by sentiment is what's prohibited.

Operational feedback tied to a transaction that just happened, a meal, a stay, a repair, is commonly collected under GDPR's "legitimate interest" lawful basis rather than consent, because it's closely tied to delivering the service and falls within what a customer would reasonably expect. This is a different footing to marketing communications, which generally require opt-in consent. The distinction matters in practice: you don't need a customer to tick a marketing checkbox to ask "how was your meal," but if you plan to add that respondent to an email list, quote their comment in a testimonial, or use their answer for anything beyond improving that specific service, that secondary use needs its own, separate consent. Keep the feedback form's stated purpose narrow and match what you actually do with the data to it. If a client wants to build a marketing list from feedback respondents, that's a second, explicit opt-in step, not something bundled into "please rate your visit."

Placement: where the code earns a response

Where you put a feedback code matters more than almost anything else you can optimise. A code buried on a website footer gets ignored; a code at the exact moment a service ends gets noticed because there's nothing else competing for attention. The moments that convert best share a pattern: the interaction has just finished, the customer is briefly stationary, and there's a natural pause before they leave.

  • Receipts and till slips: the code sits at the bottom of a printed or emailed receipt, right after the transaction is confirmed.
  • Table tents and check presenters: for hospitality, placed on the table at the point the bill arrives, when the meal is fresh in mind.
  • Checkout and exit signage: retail and clinics both benefit from a code at the door or point of sale, catching the visit while it's still recent.
  • Room keycard sleeves and checkout folios: hotels can place a code where a guest naturally looks during checkout.
  • Packaging inserts: for shipped goods, a small card in the box works, though response rates drop the further the code gets from the actual moment of service, since a card found days later competes with a much colder memory of the experience.

Avoid stacking a feedback code next to a review-request code with near-identical artwork. If a customer can't immediately tell which one is "tell us privately" and which is "tell the world," you'll get noisy, mismatched responses on both.

Reading the results across many client locations

An agency running feedback codes for ten or fifty client sites isn't just collecting responses, it's comparing them. The most useful view isn't a single location's raw score in isolation, it's that score against the same client's other locations and against its own trend over time. A location that dips from its usual CSAT average after a menu change or a staffing shift is a more actionable signal than a single low absolute number, because it points at a specific, recent cause. Scan analytics already gives you the volume side of this picture, how many people are scanning, when, and from where; pairing that with the response data tells you not just that a location is under-scanned, but whether the people who do scan are unhappy, and since when.

Before rolling out a new question set or incentive structure across a client's whole location network, test it on a subset first. A shorter question list, a different rating scale, or a small completion incentive can each move response volume in ways that are easy to measure at one or two locations before committing every client site to the change. And because the whole programme lives in one workspace per client, you can hand a client their own view of the results without exposing another client's data, or your own working notes, alongside it.

The two-funnel structure at a glance

The diagram below shows the difference between the routing pattern that gets agencies into trouble and the one that's both compliant and more useful: gating who gets asked to leave a public review, versus running two open, parallel channels.

Diagram of a four-step QR feedback flow: scan, a short rating question, a shared open invitation to a public review, and separately a private feedback dashboard.
Four steps: (1) the customer scans the code, (2) answers a short rating question, (3) everyone gets the same open invitation to leave a public review, and (4) separately, the rating goes to a private feedback dashboard.
  1. A customer scans the feedback code after their visit.
  2. They land on a short rating question (CSAT, NPS or CES, depending on the moment).
  3. Regardless of their answer, they see the same open invitation to leave a public review, not a gated one.
  4. Separately, their rating and any comments go to a private feedback form or dashboard the business actually reads and can act on.

Frequently asked questions

Do QR code surveys really get more responses than email?

Not reliably, according to the only controlled study on the question: a 2018 Gallup experiment found no statistically significant difference in response rate when a QR code was offered alongside a printed survey URL. The real advantage of a QR code isn't a response-rate multiplier over email, it's reaching people at a moment (a table, a till, a checkout) when email isn't an option at all.

How many questions should a QR code feedback survey have?

Three to five questions, completable in under a minute, is the practical target most agencies use for point-of-service QR surveys: one rating question, one open-text field, and at most one or two optional extras. Completion-rate data across more than 21,000 surveys shows completion falling steadily as question count rises, with the steepest drop happening early, between one question and two.

What's the difference between NPS, CSAT and CES?

NPS ("how likely are you to recommend us?", 0-10 scale) measures overall loyalty and is best run infrequently. CSAT ("how satisfied were you with this visit/service?", usually 1-5) measures satisfaction with one specific interaction and works well immediately after it. CES ("was it easy to resolve your issue?", usually 1-7) measures friction and is best suited to support and service-recovery moments.

Can I change the questions on a QR feedback code without reprinting it?

Yes, if the code is dynamic rather than static. A dynamic code's printed artwork never changes; only the destination behind it does, so you can swap the survey it points to as often as needed, seasonally, per campaign, or to switch survey formats, without touching the physical sticker.

No. Google's Business Profile policy explicitly prohibits businesses from discouraging negative reviews or selectively soliciting positive ones, and the US FTC's 2024 rule on consumer reviews prohibits steering or compensating reviews based on the sentiment they're expected to express. The compliant approach is to offer the public review option to everyone equally and run a separate, non-gated private feedback channel alongside it.

Do discounts or incentives improve QR survey completion rates?

Incentivising completion of a private feedback survey (a discount code, a small offer for finishing the form) is a widely used and legally uncomplicated tactic, since it isn't conditioned on what the respondent says. It becomes a problem only when the incentive, or the routing, is tied to sentiment, for example offering a reward only for a positive public review, which is what the FTC's 2024 rule and Google's review policy both prohibit.

Usually not for its original purpose. Operational feedback tied to a recent transaction is commonly collected under GDPR's legitimate interest basis rather than consent, because it's closely tied to service delivery. Marketing consent becomes necessary the moment you reuse that data for something else, adding a respondent to a mailing list or quoting their feedback publicly, since that's a separate purpose from the operational one the data was originally collected for.

Where should I place a feedback QR code for the best response rate?

At the exact moment a service interaction ends, while the customer is still briefly stationary: on the receipt or till slip, on a table tent when the bill arrives, at checkout or exit signage in retail and clinics, or on a keycard sleeve at hotel checkout. Response quality drops the further the code gets from that moment, a card found days later in a shipped package competes with a much colder memory of the experience.

The short version

A feedback QR code's real value isn't beating email on response rate, it's catching feedback at a moment when no other channel is available. Match the survey type to the moment (CSAT for a single transaction, NPS for the relationship, CES for support), keep it to three to five questions, and use a dynamic code so the questions can change without a reprint. Route every respondent to the same open public-review invitation regardless of their rating, keep the private feedback channel separate and genuinely private, and treat the operational feedback itself as legitimate interest, not a marketing list, unless you've asked separately. Set that structure up once per client workspace, then let the scan and response data tell you which locations need attention.

Share

Keep reading

QR code feedback surveys: how to turn every touchpoint into a response (and actually act on it) | ScanKit