
QR codes for hotels and hospitality: the agency playbook for a multi-property guest journey
A touchpoint-by-touchpoint guide to running QR codes across a hotel group: static or dynamic per touchpoint, tagging across properties and room types, scheduled menu switching, PMS check-in integration, the guest-room tamper risk, and GDPR-safe guest surveys.
ScanKit · Organization
· 15 min read
Most QR guides written for hospitality are written for a single property: one lobby sign, one room-service menu, one review card. That's not the problem an agency actually has. An agency managing QR for a hotel group is running a programme across a dozen properties, several room types, and touchpoints that span the entire stay, from a pre-arrival email to a review request three days after checkout. Get the structure wrong and you end up with a spreadsheet of static codes nobody can update, a different naming convention per property, and no way to say which touchpoint actually drove a booking.
This is a guide to the operational side: which touchpoints need a dynamic code and which don't, how to structure workspaces and tags so a 40-property group doesn't collapse into chaos, how a room-service menu can switch from breakfast to dinner without anyone reprinting a card, how QR check-in actually talks to the property management system, and the tamper risk that comes with a code sitting in a guest's own room rather than behind a front desk.
Where QR shows up across a stay, and why one property breaks the usual playbook
A single-location restaurant or retail client has one or two QR touchpoints to manage. A hotel has closer to ten, and they don't all belong to the same department. Marketing owns the lobby poster and the post-stay review request. Front-of-house owns check-in and the door hanger. F&B owns the in-room compendium and the restaurant table tent. Facilities owns the wayfinding and evacuation signage. Housekeeping increasingly has its own QR-triggered maintenance requests. An agency running the programme has to coordinate all of it, without each department inventing its own code and its own tracking.
That's a materially different problem from the single-code use cases most QR content is written for, and it's why a chain-scale approach needs a workspace and tagging structure before it needs a single new QR code.
Static or dynamic: map the touchpoint, not the venue
The instinct is to treat "hotel QR code" as one category and pick one approach for all of it. Don't. The right call depends entirely on how often that specific touchpoint's content needs to change, which is a per-touchpoint decision, not a per-property one (see our broader breakdown of dynamic vs static QR codes for the underlying logic).
- Lobby welcome sign: dynamic. It carries a seasonal promotion today and a different offer next quarter, and reprinting it each season is exactly the cost dynamic codes remove.
- Pre-arrival email or check-in kiosk code: dynamic by necessity. It routes to whatever the property management system generates for that specific reservation.
- Room key card or door hanger: dynamic. It links to the digital compendium, which changes far more often than the physical card does.
- In-room room-service menu: dynamic with scheduling, covered in the next section. A paper menu that says "breakfast" at 7pm is a bad guest experience regardless of the code.
- Elevator or hallway wayfinding, including fire evacuation notices: static is genuinely fine. This content isn't supposed to change, and a static code is one less thing that can break if a redirect service has an outage.
- Restaurant table tent: dynamic, and the physical format matters as much as the redirect logic, covered under the tamper risk below.
The pattern across nearly every guest-facing touchpoint is dynamic, with wayfinding the one deliberate exception, worth stating plainly to a client who assumes "QR code" means "print it once."

Structuring QR programmes across a hotel group
A single dynamic code per touchpoint is easy. A dynamic code per touchpoint, per property, per room type, across a group with real turnover in staff and signage, is not, unless the tagging structure is decided upfront. The same logic that applies to any multi-location or franchise business applies here, with one hospitality-specific wrinkle: room type is a real axis, not just property and touchpoint, because a suite's compendium content and a standard room's compendium content genuinely differ.
A workable taxonomy is property, then touchpoint, then variant: amsterdam-canal / room-compendium / suite versus amsterdam-canal / room-compendium / standard. That structure lets a team filter analytics down to one property, roll out a change to one touchpoint type group-wide without touching every property individually, and still keeps room for a workspace-per-client model if the agency manages several unrelated hotel brands rather than properties within one group, along the lines of organising QR codes one workspace per client.
Decide this taxonomy before the first code goes to print. Retrofitting a tagging scheme onto 40 properties' worth of live codes is the kind of cleanup nobody enjoys.
Switching the room-service menu from breakfast to dinner without reprinting a card
The single most common reprint cost in hospitality QR programmes is the menu. Breakfast, lunch and dinner menus differ, and many properties run a late-night or seasonal menu on top. A static code, or a dynamic code that isn't scheduled, forces a choice: one menu card covering all dayparts awkwardly, or reprints on a rotation that never quite matches kitchen hours.
Scheduled redirects solve this properly. The same physical card carries the same QR code all day; only the destination changes on a schedule, so a 7am scan lands on the breakfast menu and a 7pm scan on the dinner menu with no reprint and no staff intervention, the same mechanism covered in our guide to time-based QR codes and scheduled redirects. Build it into the initial spec rather than treating it as a later upgrade. The one property-specific detail to get right is timezone: a group spanning several time zones needs each property's schedule set to its own local time, not a group-wide default, or a menu switches over mid-service.
Hilton Omaha ran an early version of this from late 2019, placing QR-coded, contactless dining menus in every guest room for bar pickup and delivery orders alongside contactless payment, well before contactless became a pandemic-era default. The mechanics have only got easier since.
How QR check-in actually talks to the property management system
QR check-in only works because it sits on top of an API-level integration with the property's PMS, not because the QR code itself is doing anything clever. The code is just a delivery mechanism for a link; the useful work happens in the handoff between the booking engine, the PMS, and whatever generates the guest's mobile key or check-in confirmation.
The mainstream PMS platforms, including Mews, Cloudbeds, Apaleo, Opera, Maestro and Impala, expose this through open APIs and, in Mews' and Cloudbeds' case, certified marketplace integrations. A reservation is created or confirmed in the PMS, that event fires to a check-in or smart-lock system via the API, a mobile key or check-in link is generated with a defined check-in and check-out window, and that link reaches the guest by SMS, email, or a QR code at a kiosk, with room status synced back to the PMS in both directions.
Two real examples show the range. THIS HO(S)TEL in Amsterdam runs on Mews and lets guests check in by entering their last name or scanning a QR code sent pre-arrival, skipping reception entirely via a self-service kiosk; the property reports 36% higher direct-booking value and zero chargebacks on iDEAL payments across ten Mews Marketplace integrations. JustStay, a reception-less hotel group, issues a four-digit code roughly 24 hours before arrival and lets guests complete registration online or via an on-site QR code, with no staffed desk at all.
The takeaway for an agency: a QR check-in code is only as good as the PMS integration behind it. Confirm which PMS the property runs and whether it has a certified integration for the check-in system in question before promising a rollout, because the code itself is the easy part.
The guest-room tamper risk: why a hotel code is an easier target than a parking meter
QR phishing, often called quishing, is one of the fastest-growing phishing variants the FBI has flagged, and the mechanism is simple: a scammer prints a sticker that looks identical to a legitimate code and sticks it over the real one, redirecting scans to a fake payment or login page. The FTC has issued consumer advisories on exactly this pattern, and both agencies name hotel receptions and restaurant tables specifically, alongside parking meters, as documented tamper targets: all three are codes posted somewhere anyone can walk up to and swap.
The scale is real, even where the specific numbers repeated across hospitality blogs mostly aren't. UK Action Fraud data, analysed by the BBC, shows QR-related scam reports rising from around 100 in 2019 to 1,386 in the most recent full year on record, a roughly fourteenfold increase over five years. That's a genuinely sourced trend line worth citing to a sceptical client. Treat other widely repeated figures, such as specific dollar-loss totals attached to individual incidents, with more caution; several are unsourceable, and a wrong number undermines an otherwise solid argument (our broader guide to QR code security for agencies covers the defence checklist in more depth).
A hotel room is less public than a parking meter, but in one way it's a worse tamper target: housekeeping turns it over daily, guests handle the signage, and nobody from the property walks past the in-room compendium card the way a manager might walk past a lobby poster. That combination of low staff visibility and high guest handling makes an adhesive paper sticker the wrong format for anything guest-facing. A laminated card, an engraved acrylic table stand, or a code embedded directly into printed signage is materially harder to overlay convincingly, because there's no clean adhesive surface to hide the tamper on, and it costs nothing beyond choosing a slightly more durable print format from the start.
Guest surveys, reviews, and the GDPR angle EU properties can't skip
A QR-triggered guest survey or review request collects contact data, even if that's not the obvious intent, and EU data protection law treats that collection like any other. The relevant precedent isn't hospitality-specific but applies directly: the UK's ICO fined a venue check-in provider, Tested.me, for sending 84,000 unsolicited marketing emails using contact data originally collected via QR check-in for an unrelated purpose (contact tracing, reused for marketing without fresh consent). The same fact pattern maps precisely onto a hotel QR survey that quietly opts a guest into a marketing list.
The fix is unglamorous but cheap: state clearly, at the point of scan, what the data will be used for, and don't fold marketing consent into a satisfaction survey or review request by default. The ICO's own guidance for small hospitality businesses covers lawful basis and data minimisation, and is worth a client-facing link if the property's privacy policy doesn't already cover QR-collected data. This applies whether the code routes to an in-house survey or a public review platform; our guides to QR codes for feedback surveys and QR codes for Google reviews cover the mechanics of each, but the consent language sits above both.
Measuring ROI across dozens of properties, not just one code
Scan counts alone tell an agency almost nothing useful at chain scale. The metric that matters varies by touchpoint: a check-in code should be measured as scan-to-completed-check-in rate, not raw scans, because a scan that doesn't finish the flow is a UX problem worth flagging. A room-service code should be measured as scan-to-order conversion, ideally split by daypart. A review-request code should be measured as scan-to-completed-review rate, since a scan that bounces off the platform's own login wall is a lost review, not a captured one.
Rolling these up by property, not just by touchpoint type, is what lets an agency show a general manager how their location performs against the group average, which tends to be the report that actually gets read. Our broader guide to which QR scan metrics matter covers building that reporting layer; the hospitality-specific point is that property-level rollup belongs in the initial design, not bolted on once a client asks for it.
Frequently asked questions
Should a hotel use a static or dynamic QR code for its room-service menu?
Dynamic, and ideally dynamic with time-based scheduling so the same physical card can serve breakfast, lunch and dinner menus without a reprint. A static code locks the menu to whatever was true on the day the card was printed, which is a bad fit for content that changes daily.
Can a QR code switch automatically between breakfast, lunch and dinner menus?
Yes. The QR code itself never changes; it points to a short redirect URL, and that URL's destination is switched on a time-based schedule set to the property's local timezone. Guests scanning at 7am and 7pm see different menus from the identical printed code.
Is it safe for guests to scan the QR code in a hotel room?
Generally, but not risk-free: the FTC and FBI have both documented tampering (quishing) at public and semi-public codes, including hotel receptions and restaurant tables. The mitigation is format, not guest behaviour: laminated cards or engraved signage are much harder to overlay with a fake sticker than a plain adhesive label.
How do QR check-in codes connect to the property management system?
Through an API-level integration between the PMS (Mews, Cloudbeds, Apaleo, Opera and Maestro all support this) and a check-in or smart-lock system. A reservation event in the PMS triggers a mobile key or confirmation link, delivered by SMS, email, or a kiosk QR code, with status synced back to the PMS.
Do QR-code guest surveys create GDPR problems for EU hotels?
They can, if contact data collected through a QR survey or check-in is later reused for marketing without separate consent, the exact pattern UK regulator ICO has fined a venue check-in provider for. State the data's purpose at the point of scan and don't bundle marketing consent into a satisfaction survey by default.
What's the safest physical format for an in-room QR code?
A laminated card, an engraved acrylic stand, or a code embedded directly into existing signage, all harder to convincingly overlay with a fake sticker than a plain paper label, the tamper method documented in real quishing cases at hotel receptions and restaurant tables.
How should an agency structure QR codes across a hotel chain with many properties?
With a taxonomy set before the first code prints: property, then touchpoint, then variant such as room type, so codes filter per property for reporting, update group-wide by touchpoint type, and sit in separate client workspaces if the agency manages multiple unrelated brands rather than properties within one group.
How do you measure ROI on a hotel QR programme?
By touchpoint-specific completion rate, not raw scans: scan-to-completed-check-in for check-in codes, scan-to-order for room-service codes, and scan-to-completed-review for review requests, rolled up by property so each general manager can see their own location against the group average.
The short version
A hotel QR programme has more moving parts than almost any other vertical an agency will manage: ten-plus touchpoints, several departments, and a guest journey running from a pre-arrival email to a review request days after checkout. The fixes are structural, not clever: map static versus dynamic by touchpoint rather than by property, set a property-touchpoint-variant tagging taxonomy before the first code prints, schedule the room-service menu instead of reprinting it, confirm the PMS integration before promising a check-in flow, and swap paper stickers for laminated or engraved formats anywhere a guest room or restaurant table leaves a code unsupervised. Before the next batch of room cards goes to the printer, audit which of them are still static by accident rather than by choice, that's usually where the easiest win is sitting.
Keep reading

· 16 min read
Do AI crawlers follow QR code redirects? What agencies need to know
Can ChatGPT, Perplexity and Google AI Overviews actually reach the page behind a QR code's redirect? What GPTBot, ClaudeBot and PerplexityBot do with hops, JavaScript and 301s, and the pre-print checklist that keeps a campaign's landing page visible to AI search.
Read more
· 16 min read
Custom domains for QR code links: how white-label redirects actually work
How agencies put their own or a client's domain on a QR redirect link: the CNAME record, automatic SSL via ACME, realistic DNS propagation timing, and what a branded domain actually does (and doesn't do) for trust, SEO, and phishing risk.
Read more