Sponsored
Travel
Boarding pass, guest Wi-Fi, luggage tag: using QR codes properly when travelling
Wi-Fi for guests, a digital guest folder, a luggage tag with contact details: when travelling, QR codes are practical helpers. Which data belongs in the code, which is better left out — and why some codes work even without a network.

Hardly any situation in life is as riddled with QR codes as travelling: the boarding pass is one, the rail ticket too, the menu at the holiday destination in any case, and one hangs at reception for the Wi-Fi. It is worth distinguishing two perspectives — the codes travellers are presented with, and the ones they can create themselves. Both have their peculiarities, and with both a little background knowledge decides whether the code helps or becomes a risk.
First to the codes you are given. Boarding passes from airlines and rail tickets carry machine-readable codes generated by the providers' booking systems — every ticket a one-off. Strictly speaking, incidentally, the code on the rail ticket is not a QR code at all but an Aztec code: a related square format without the three prominent corner squares. For practical purposes the difference is immaterial; in any case such tickets can only be generated by the transport companies themselves.
More important is another point: the code on the boarding pass contains booking data — name, booking reference, flight details. Anyone who photographs their pass before departure and shows it on social networks publishes more than the picture suggests: with the booking reference, bookings can be viewed or even changed at some providers. Boarding passes therefore belong treated like documents — not like holiday decoration.
For practical handling of such tickets a few habits have proved themselves. Wallet apps on the telephone keep boarding passes and, increasingly, rail and event tickets available offline — the code then works in flight mode and in the mobile dead spot before the security check as well. Anyone working with screenshots instead should put them in an album of their own, so that nobody has to scroll through hundreds of holiday pictures at the gate, and should turn the screen brightness up when showing them: the readers at gates and platforms have trouble with dark displays, and with cracked ones even more. A paper printout as a fallback weighs nothing — and batteries, experience shows, run flat at exactly the moment you need them.
At check-in, too, the square is encountered ever more often: hotels put registration forms and check-in routes behind codes, landlords send directions and key information in advance by link. Travellers need nothing more for that than a working camera app — and the certainty that the code comes from a trustworthy source, from their own booking confirmation for instance. That is precisely what distinguishes the code sent to you from the sticker on the lamp post: the context decides the trust.
Now to the productive side: the codes travellers and hosts create themselves. The most useful is the Wi-Fi code. Instead of spelling out a sixteen-character password from the back of the router, guests scan a square on the noticeboard and are connected — the network name and password sit directly in the code. This works, note, without an internet connection, because the data is in the image itself; precisely after arrival, when the data allowance is empty or roaming is expensive, that is the decisive advantage. Anyone letting a holiday flat can create such a code in the web browser, print it out and laminate it.
One property of this code type should be known, however: the password sits in plain text in the code. Every person who scans the square, or even merely photographs it, knows the credentials afterwards. The Wi-Fi code therefore belongs inside the flat, not in the window facing the street; and anyone wanting to be on the safe side changes the password at sensible intervals. For a home network with network storage and smart home devices a separate guest network is advisable anyway — its access can then be displayed as a code without a second thought.
The route to that is done in half an hour and deserves a brief step-by-step look. First a guest network is set up in the router — most devices offer this in their settings — with its own name and a password that is used nowhere else. The network name, the encryption type and the password then go into the generator; a trial scan with your own telephone shows immediately whether the entries are correct, before anything at all has been printed. Only after that is it printed out and laminated, ideally matt, because glossy film reflects under the ceiling light. A final test through the finished film, ideally with a second, older telephone, rounds the matter off. What remains to be borne in mind is the static nature of this code type: anyone who changes the Wi-Fi password later has to print anew — the old notice knows only the old details.
The second classic for hosts is the digital guest folder. Directions, key handover, waste separation, restaurant tips, emergency numbers: all of it moves onto a web page whose address hangs in the hallway as a code. If the code is set up dynamically — that is, with a destination that can be changed afterwards — the laminated printout stays valid for years while the content behind it is updated every season. Prices change, restaurants close, the bus timetable is reorganised: the code on the wall stays the same, only the destination is maintained.
With an international clientele the language question also arises — and it can be solved more elegantly than with several codes side by side. A single code leads to a page with a choice of language; which languages are maintained behind it is for the host to decide, without anything on the notice ever changing. A fixed rhythm helps with the upkeep: plan half an hour before every season for a reconciliation — are the prices right, does the bus timetable still hold, is the recommended restaurant open, are the emergency numbers current? Experience shows that it is precisely the small details that go out of date fastest, and little looks more careless than a digital folder pointing to an establishment that has long since ceased to exist.
The third use case travels with you: the luggage tag. A vCard code on the tag saves the owner's contact details straight into the address book of honest finders. Here it is worth thinking about which data belongs in it: telephone number and email address are enough — the full home address on the suitcase also reveals, in case of doubt, which flat is standing empty for weeks. Anyone preferring more flexibility uses a dynamic code instead, leading to a small contact page; its content can be adapted to each trip without replacing the tag.
At this point a technical aside is worthwhile, one that can be worth real money on the road: QR codes fall into two families. The one carries its data itself — Wi-Fi access, contact details, short texts, telephone numbers. They work everywhere, in the mobile dead spot and in flight mode too. The other contains a web address and depends on an internet connection; abroad without a data package they stay mute. Anyone wanting to pass on travel information by code that is guaranteed to arrive therefore chooses the text type in case of doubt — an overview of the code types shows what can be encoded in each case.
How much this difference matters is shown by the typical day of arrival. Directions from the station to the accommodation as a text code work even when the telephone has not yet registered on the foreign network; so does the landlord's telephone number as a call code. The guest folder with photographs and maps, by contrast, needs a connection — it sensibly comes into its own only once the accommodation's Wi-Fi has been reached. Hosts who combine the two stagger the information: the essentials offline in the text code of the booking confirmation, the depth online behind the code on the noticeboard. That way nobody is left standing outside the door because a web page will not load.
Caution is part of travel practice too: tourist hotspots are a popular hunting ground for forged codes — parking machines stuck over, manipulated hire scooters, stickers over menus. Abroad, the destination address after a scan is harder to assess, because unknown domains are the normal case there. The basic rules stay the same as at home: read the preview of the destination address, use the provider's official app for payments and never enter card details lightly after a scan.
A special case on the road is hire cars, rental bikes and electric scooters, whose unlocking regularly runs via a code on the vehicle. A simple check helps here: the scan should lead into the provider's official app, or start from it — if a page opened in the browser suddenly demands credit card details although the app is installed and payment has long since been stored there, that is the moment to break off. The condition of the sticker gives clues as well: original codes are as a rule integrated into the vehicle's lettering or lie behind film, rather than being stuck on crooked. In case of doubt the vehicle can be selected directly via the map in the app — the code is only the shortcut, never the only route.
Hosts using dynamic codes get a picture along the way of what their guests actually use: scan analyses by time of day, device and region show whether the guest folder is being read, and when. Here too the classification belongs with it: these are aggregated reach figures from a small number of guests — they hardly bear robust conclusions, and as soon as analytics tools of your own are running on the destination page, the usual data protection obligations apply, including visitors' consent.
Anyone looking after several properties or changing notices also benefits from a little order in the account: meaningful names for every code — “wifi-flat-strandweg”, “guest-folder-townhouse” — and a short list of which printout hangs where. One detail deserves particular attention: a dynamic code that is deleted in the account dies on all printouts at the same time — the laminated notice in the holiday flat then leads nowhere, without anyone noticing. After the end of the season, redirecting the destination to a neutral page is therefore almost always the better choice than deleting it. And where several people share the administration, in a family business for instance, the account's login details belong documented rather than merely remembered.
The effort for all this is small. QR2GO's free tier comprises 20 code slots with basic styling and PNG export — more than enough for a Wi-Fi code, a guest folder and a few luggage tags. The premium tariff at 5.99 euros a month, with 200 slots, full scan analysis and high-resolution exports, is aimed more at commercial landlords with several properties. The data is hosted in Germany. Before laminating, the rule applies in every case: test the freshly printed code with several telephones — behind film and in backlight, scanning is harder than at the desk.
So a sober conclusion remains about the QR code when travelling: it is neither a gimmick nor a security risk in itself, but a means of transporting information — and as with every means of transport, the cargo decides. Anyone who briefly asks themselves before printing which data belongs in the code and which is better left out has got most of it right. The rest is convenience: no spelling out of passwords on arrival day, a guest folder that never goes out of date, and a luggage tag that knows the way home.