Comparisons

Static vs dynamic QR codes: the choice that decides whether a price change means a reprint

By Duckhub Team, Restaurant technology team at DuckhubPublished Aug 21, 202614 min read
Updated Aug 21, 2026

The Duckhub team builds AI-powered QR menu and online ordering software used by cafes, bars, and restaurants. We write practical guides based on what we see working across thousands of published menus.

The practical difference is one sentence long. A static QR code has the destination URL baked into the pattern itself and can never be changed. A dynamic QR code encodes a short redirect URL, and you repoint that redirect whenever you like. For a menu, that means a static code turns a price change into a reprint of every table tent, and a dynamic code turns it into an edit.

That summary is where most comparisons stop, which is a problem, because almost every one of them is published by a company selling dynamic QR subscriptions. This guide covers the technical difference from the specification, the arithmetic on reprints, what dynamic scan analytics can and cannot actually see, what happens when the subscription lapses, and the third option that vendor comparisons leave out because it does not sell anything.

The comparison table

Criterion Static QR code Dynamic QR code
Can the destination be changed? No, ever Yes, at any time
Requires an ongoing service or subscription No Yes
Still works if the provider disappears Yes, as long as the destination is live No, until the code is replaced
Updating a price Reprint every printed code Edit the page
Marking an item sold out Not possible Immediate
Different menus by daypart Not possible Yes, scheduled
Scan analytics None at the code level Timestamp, device, coarse location
Pattern density for a long URL Higher, harder to scan Lower, easier to scan
Cost at the start Free to generate Subscription
Cost over time Recurring reprints Fixed subscription
Privacy footprint Minimal, no intermediary Third party logs IP addresses
Best for Permanent destinations, one-off events, Wi-Fi credentials Anything whose content changes

Bottom line: if the thing behind the code changes more than once a year, use a dynamic code or an equivalent redirect you control. If the destination is genuinely permanent, static is simpler, free, and has fewer failure modes.

What a static QR code actually is

A static QR code encodes the complete destination string directly into the arrangement of black and white modules. Scanning it reads that string off the pattern; there is no lookup, no server, and no intermediary. This is why a static code cannot be edited: the URL is not stored alongside the image, it is the image.

QR codes are governed by ISO/IEC 18004, the international symbology specification, and were engineered by Denso Wave in 1994. Symbols run from Version 1 at 21 × 21 modules up to Version 40 at 177 × 177 modules, with each version adding four modules per side. More characters force a higher version, and a higher version packs more, smaller modules into the same printed square.

That has a direct consequence for restaurants. A static code pointing at something like https://www.yourrestaurant.com/locations/downtown/dinner-menu-autumn-2026.pdf is a long string, so it produces a dense, high-version pattern. Print that at table-tent size in a dining room lit at a level designed for atmosphere rather than for camera sensors, and phones with older optics or a smudged lens will struggle. A dynamic code encoding a twenty-character short link produces a low-version pattern with physically larger modules, which scans faster in exactly those conditions.

Two more specification details matter more than most design decisions:

  • Error correction. ISO/IEC 18004 defines four correction levels — roughly 7%, 15%, 25% and 30% of codewords recoverable, with 15% the most commonly selected. Higher correction survives scratches and spills but adds redundancy codewords, pushing the version and the density up again.
  • The quiet zone. Denso Wave specifies a four-module wide margin on all sides. Designers routinely violate it by wrapping “Scan for our menu!” text or a border around the code, and edge-detection then fails to locate the symbol at all. It is the single most common reason a well-generated code will not scan.

There is also a real trade-off hiding in the centre logo everyone wants. There is no provision for logos in the standard. A centre logo works only because error correction recovers the deliberately obscured codewords, which means the logo consumes recovery budget that was meant for real-world damage. A logo covering 15% of a Level H code leaves roughly half the correction capacity for spills, glare and print wear.

What a dynamic QR code adds

A dynamic QR code encodes a short URL owned by a provider. When a guest scans it, their browser requests that short URL, the provider’s server logs the request and issues an HTTP redirect to your current menu address. The pattern never changes; the destination behind it can change as often as you like.

That indirection buys three things.

Destination agility. You change where the code points from a dashboard, and every printed code in the building follows instantly. This is what makes seasonal menus, dayparted brunch and dinner menus, and mid-service changes possible without touching a single physical item.

Scan analytics. Because traffic passes through the redirect, the provider can record timestamps, device and operating system from the user-agent string, coarse city-level location from IP geolocation, and total versus unique scans. Daypart analysis is the genuinely useful output: you can see when your menu is actually being read, which is rarely when you assume.

And a privacy obligation. The same redirect that produces the analytics collects IP addresses, and under GDPR an IP address logged by a service provider is treated as personal data. If you operate in the EU or serve EU visitors, running dynamic QR analytics means you are processing personal data through a third party and need a lawful basis, a privacy notice naming that provider, and consent handling for any cookies used to count unique scans. If you have no intention of managing that, turn the analytics off or pick a route that does not collect them. Our QR code menu statistics page covers what the published scan data shows, and what it does not.

Two things dynamic codes categorically cannot capture, despite frequent claims otherwise: personally identifiable information, unless the guest types it into a page afterward, and precise GPS location, unless the landing page requests it and the guest grants the operating-system permission. A QR scan on its own identifies nobody and cannot tell you which table a guest is sitting at.

Why this matters for a menu specifically

Generic static-versus-dynamic articles are written for business cards and packaging, where the destination genuinely does not change. A menu is close to the opposite case. Five things change it, and four of them change it faster than any print cycle:

  1. A price moves. Suppliers reprice, and the correction should be live the same week. The National Restaurant Association projects $1.55 trillion in industry sales for 2026 against 1.3% real growth, which means most top-line movement in the market is price rather than covers. Our guide to pricing a restaurant menu covers the recosting cycle itself.
  2. An item gets 86’d at 7pm. With a static code, the only correction available is a server apologizing at every table for the rest of service.
  3. The menu changes by daypart. Brunch until two, dinner from five. A static code can point at one destination, so either the guest sorts it out or you print two sets of codes.
  4. A seasonal menu launches. If your static code points at a dated PDF filename, every seasonal change breaks every printed code in the building.
  5. A new drinks list arrives. Bar menus rotate faster than kitchen menus, because cocktails change, draught lines change, and stock runs out mid-evening.

Point 4 is the trap worth naming clearly, because it is self-inflicted and common. If you generate a static code pointing at menu-october.pdf, you have permanently coupled your printed table tents to a filename. Our guide to converting a PDF menu into a QR menu covers how to break that coupling.

The reprint arithmetic

The reason “static is free” is misleading is that the cost moves from the code to the card stock. Here is a transparent model. Use your own printer’s quote; the figures below are one published example, not a market average.

UPrinting lists 4.25 × 6 inch vertical table tents at $95.81 for 25 units, or $3.83 each, at default stock and finish as of August 2026. Volume pricing brings the unit cost down substantially, and lamination or acrylic holders push the effective cost back up. Running the model at a conservative $0.60 per unit at volume:

Venue Printed codes Cost per reprint at $0.60/unit Menu changes per year Annual reprint cost
Cafe, 12 tables 15 $9 4 $36
Bistro, 30 tables 40 $24 6 $144
Casual dining, 60 tables 80 $48 6 $288
Bar, 40 tables plus bar top 60 $36 12 $432

Two honest observations about that table. First, at the small end the numbers are modest, and a twelve-table cafe changing its menu quarterly is not being ruined by $36 of card stock. Second, the printing cost is the smallest part of the real total. The larger costs are the design time on every reprint, the days or weeks between deciding on a price and the new tents arriving, and the changes you simply do not make because a reprint is involved. That last one has no invoice and is usually the expensive one.

Do dynamic QR codes expire?

This is the fear that keeps operators on static codes, and the honest answer is: the printed pattern never expires, the redirect behind it absolutely does.

Uniqode states plainly that static codes last indefinitely while dynamic codes depend on platform infrastructure, and that “a single missed subscription renewal can deactivate every dynamic QR Code on an account simultaneously, including codes already printed and distributed.” Renewing restores the redirect with no change to the printed code. Other providers word it differently but the mechanic is the same: no subscription, no redirect, and no visible warning on the table tent to tell your staff that scanning now produces an error page.

So a dynamic code is a permanent operational dependency on a third party. That is a real cost, and it should weigh heaviest on the longest-lived physical assets. Putting a vendor short link on a paper insert you replace quarterly is low risk. Etching one into brass signage or laser-cutting it into a menu board is a decision you may regret at renewal time. Before you commit, check the provider’s terms for what happens on cancellation, whether the account is annual-locked, and whether there is any grace period.

When a static QR code is genuinely the better choice

There are cases where static wins outright, and one where it wins in a way most comparisons never mention.

The owned-subdomain strategy. Generate a free static code pointing at a subdomain you control, such as menu.yourrestaurant.com. Because you own the domain, that code never needs editing and never expires. When the menu changes, you update what the subdomain serves, or set a 301 redirect from it to the current page. This gives you the exact operational agility of a dynamic code with no subscription, no vendor lock-in, no third party logging your guests’ IP addresses, and analytics through your own tooling.

The catch is that it requires someone who is comfortable with DNS and hosting, and it only relocates the problem: something still has to render an up-to-date menu at that address. But if you have that capability, it is the technically cleanest answer, and it is worth knowing that the honest version of this comparison is not “static or dynamic” but “who controls the redirect”.

Short-lifecycle materials. One-night prix fixe menus, wedding and catering inserts, pop-up events, festival stalls. The material is discarded after the event, so permanence is irrelevant and free wins.

Receipt and check codes. A code at the bottom of a check pointing at a stable review or feedback page needs no routing. It also benefits from a static code’s optical simplicity, since thermal printers bleed and destroy fine module edges.

Wi-Fi credentials. Encoding an SSID and password has to be static, because the phone reads the credentials off the pattern and connects without any network access. A redirect cannot work here by definition.

Two claims to stop repeating

“Dynamic QR codes are more secure.” They are not. Neither type carries cryptographic protection, and a dynamic code adds a redirect server to the trust chain, which enlarges rather than shrinks the attack surface. If a provider’s routing infrastructure is compromised, every code depending on it can be repointed at once.

The security risk that actually affects restaurants is physical and affects both types identically. The FBI’s Internet Crime Complaint Center has warned that criminals tamper with physical QR codes, advising the public to check that a code has not been altered, such as with a sticker placed on top of the original. A printed sticker over your table tent routes guests to a credential-harvesting page that looks like your payment flow, and there is no software setting that prevents it. The defences are operational: staff visually check codes during setup, and codes printed as part of a branded, textured or die-cut piece are much harder to cover convincingly than a plain black square on white card.

“You can edit a static QR code with the right tool.” You cannot. The data is the geometry. A tool that appears to do this is generating a new code, or the code was dynamic to begin with.

How to move from static to dynamic without reprinting

You mostly cannot switch a code that is already printed, because the old URL is inside the pattern. What you can do is make the old destination cooperate.

  1. Keep the old address alive. Whatever your existing static codes point at, do not delete it.
  2. Put a 301 redirect on it to your new menu page. Every already-printed static code now lands on the current menu, indefinitely.
  3. Use the new code on everything printed from now on, so the two run in parallel.
  4. Retire the old codes on the next natural reprint cycle, not as an emergency project.

That sequence costs nothing and removes the deadline. If you are still deciding what the destination should be, our guides to making a QR code menu and digitizing a restaurant menu cover the build, and best digital menu software compares the platforms including ours.

Which one you should use

If the destination is permanent and you own the domain, a static code is free, simple and has no expiry mechanic to worry about. If it is a one-night event or Wi-Fi credentials, static is the only sensible answer.

For a menu, the honest recommendation is that you need a redirect layer — and then a second decision about who owns it. Run it yourself if you have the DNS and hosting skills and something to serve the menu from. Use a platform if you would rather the menu, the redirect and the updating be one system. The failure mode to avoid is neither of those: a static code pointing straight at a dated PDF, where every menu change quietly breaks every printed code in the building. How often that bites you depends on your format, and our guide to the types of restaurants covers which formats change their menus fastest.

Duckhub is the platform version. You get a hosted menu with a dynamic QR code, real-time price edits, sold-out flags that appear instantly on every table, multiple languages, and 0% commission on orders. Free plan to start, 30-day trial on the paid tiers.

Frequently asked questions

Ready to bring your restaurant online?