Your website reports everything; your packaging has historically reported nothing. Scan analytics closes that gap: when the barcode is a URL that resolves through you, every scan, from a phone in a kitchen or a scanner in a warehouse, becomes a data point, with nothing to install and no tracking imposed on anyone.
What the barcode can tell you
Volume and trend. Scans per product per day, live: which SKUs get engagement, when campaigns move the needle, what a recall notice does to scan behaviour.
Geography. Country-level distribution of real-world scans, which is distribution intelligence: where packs actually circulate, including markets your routing did not expect, the classic grey-market tell.
Humans versus machines. Phones ask for pages; tills, warehouse systems and bots ask for data. Counting them separately means marketing reads engagement while operations reads supply-chain activity, from the same code.
Integrity signals. Serialized codes add the anomaly layer: impossible-travel and velocity flags mark likely clones as suspicious rather than letting fakes inflate reach.
The privacy architecture, stated plainly
Scan analytics earns trust only if it is not surveillance. A scan on Onpack records the code, the client kind, the outcome and the country, and nothing else: no stored IP, no cookie on product pages, no ad scripts, no identity. That restraint is publishable, in the privacy page, and it is why the analytics survive GDPR review: there is no personal data in the pipeline to argue about.
From dashboard to systems
The console shows the live picture: totals, a 30-day series, top countries, per-product tables, updating as scans happen. For your own systems, webhooks push each scan event, signed, to your endpoint, and the API serves the aggregates, so the barcode becomes one more instrumented channel in the stack rather than an island.
Why this is the quiet headline of the whole transition
Compliance obligations come and go by category, but measurement compounds: the brand that prints resolvable codes in 2026 has years of scan behaviour by the time competitors print their first. The barcode is the most-scanned object a brand owns; Sunrise 2027 is the once-in-fifty-years excuse to finally get the data from it.
Common questions
What exactly does a scan record?
Four facts: which code, human or machine client, the resolution outcome, and the country. No IP stored, no cookie, no identity, no location finer than country; the privacy page enumerates it.
Can analytics tell shoppers apart from checkout scanners?
Yes, by how the request asks: browsers request pages, POS and inventory systems request data formats. The console reports the two populations separately.
How fast do scans appear in the dashboard?
Within a second or two: each scan is pushed live to the console over a socket, with daily series and country totals accumulating behind it.
Do I need to add any tracking script?
No. The measurement happens at the resolver as a side-effect of answering the scan. Nothing is installed on your site or the shopper's phone.