Missing User Warnings
Medium
- Confidence
- 86% confidence
- Finding
- The deployment guidance explicitly recommends scan tracking via UTM parameters or QR analytics platforms without any mention of notice, consent, retention, or minimizing collected data. In a QR deployment context, this can normalize privacy-invasive implementations that collect behavioral or location-linked scan data without appropriate disclosure, creating compliance and trust risks.
