The first call came on a Saturday morning at 7:14 a.m. "Mr. Kowalski? This is Heather from MaxAir Solar — we noticed your zip code qualifies for…"
Andrew Kowalski is a name partner at a 14-attorney mid-Atlantic litigation firm. His personal cell number — the one his teenage daughter calls from school — got into Heather at MaxAir Solar's CRM in the spring of 2023, when he attended a Continuing Legal Education conference in Charlotte and handed out 60 business cards over two days.
He handed them out the modern way: a QR code on the back of each card that opened a digital "vCard" with his name, firm, email, and his cell number. Convenient. Painless.
He counted 47 unique spam callers in the 14 months after that conference.
It is not Heather at MaxAir Solar's fault. It is the way the QR vCard ecosystem was built.
How a vCard QR turns into a spam-list entry
Here is the path your personal contact information takes between the moment someone scans your QR business card and the moment it lands in the lead-scraping pipeline that powers most outbound call centers:
Step 1 — the scan. Whoever scans your QR — could be a fellow attorney, could be a vendor lurking at the back of the conference room, could be a recruiter — gets a URL on their phone. That URL serves them a vCard file.
Step 2 — the dump. The vCard file is plaintext. Every field — FN:Andrew Kowalski, TEL:+15555550199, EMAIL:andrew@firm.com — is there in clear text. Their phone parses it and saves it to their contacts. That is the advertised use case.
Step 3 — the secondary use. Most scanners, including the camera apps on iPhone and Android, log the URL they opened. Some QR-scanner apps from the App Store do worse: they save the full destination, including the vCard payload, in a "scan history" feature.
Step 4 — the silent inclusion. A handful of QR-generator services log every scan event, including the IP address of the device that scanned, the timestamp, the city, and the user-agent. These services typically have a "marketing analytics partner" listed somewhere in their terms of service. Two of the largest QR-generator services in 2024 had data-sharing agreements with B2B intent-data brokers. That is how Heather at MaxAir Solar got Andrew's number — not by buying his name from the conference, but by buying the scan-event stream of every QR scanned in a Charlotte hotel ballroom during a 48-hour window in May.
Step 5 — the enrichment. Once a phone number is in one broker's pipeline, it gets cross-referenced against LinkedIn, voter registrations, and property records. Within six weeks, Andrew is on call lists for solar, life insurance, "Medicare adjacent" plans, and three different roofing companies. The data brokers don't know he is a litigation partner. The call centers calling him don't care.
Andrew did not consent to any of that. He just handed out a business card.
The thing nobody told him about QR vCards
The convenience of a QR business card comes from one feature: the receiver does not need to type anything. They scan, they save the contact, they move on. It is friction-free in a way that paper business cards never were.
But that friction was load-bearing. The reason it took someone 15 seconds to type your phone number into their phone is the same reason your phone number didn't end up in a database somewhere. The friction made you a private person. The QR code removed it.
This is not theoretical. This is happening in nearly every industry where people hand out business cards to strangers.
A 2023 audit of seven popular QR-vCard-generator services found:
- 6 of 7 stored vCard contact data in plaintext on their servers
- 5 of 7 retained scan-event IP addresses indefinitely
- 4 of 7 had "analytics partnerships" that allowed third-party access to scan events
- 0 of 7 offered a "private mode" or a "request reveal" flow
- 0 of 7 offered an instant data-deletion / token-rotation feature
The default for every one of these services was: here is your phone number. Here is the world. Have at it.
What "private by default" actually looks like
Imagine the following flow:
You print a QR on your business card. Same as always.
When someone scans it, their phone gets a URL — same as always.
The URL takes them to a page that says: "Andrew Kowalski, Litigation Partner at Foster & Klein. Tap to request his direct contact information."
That is it. Your name, your title, your firm. Nothing else. No phone, no email, no address.
If the person scanning is someone you actually want to talk to, they tap "request" and you get a notification on your phone. You see their name. If it is the right person, you tap approve and now they get your contact information.
If it is someone you do not want to talk to — a vendor, a recruiter who has no business contacting you, a stranger who picked up your card at the lost-and-found — they get nothing. No phone number. No email. They will not call you. They will not appear on a spam list. They do not have the data to sell.
That is what a privacy-first QR vCard looks like. The friction goes back where it belongs.
Why this is not how it works today
The reason it does not work this way at every QR-generator service is that the analytics partnerships are profitable. A typical QR-generator service charges $5 to $15 per month for a paid plan and sells scan-event data to brokers for a substantial multiple of that on the back end. Putting the cardholder in control of who sees their contact information breaks the data pipeline.
The few services that do let you toggle privacy on a vCard tend to bury the toggle three menus deep. The default is public. The default has always been public.
The fix is one feature: an opt-in reveal
If you are a lawyer, doctor, financial advisor, executive, recruiter, real-estate agent, or any other professional who hands out a business card and then wonders why they get spam calls — it is not your imagination, it is not "the post-pandemic spam wave", it is your QR code.
The fix is a QR vCard that is private by default, with a reveal-on-request flow, encrypted at rest, and a rotate-the-token kill switch you can hit the moment you change firms.
That is exactly what SealedQR is. It is free for five cards (which is more than most professionals need), $9 a month if you want the full Pro Identity feature set, and the data export is one click — exactly like the data deletion is one click. We do not have analytics partnerships. Our terms of service do not have an "or marketing partners" clause. The decryption key for your data lives in a single environment variable on a single server we run.
This is not the cheapest QR-vCard service. The cheapest QR-vCard service is the one selling your scan events to data brokers. That one is free because you are the product.
If you have been getting more spam calls since you started using a QR business card, hand the URL of this post to whoever is in charge of marketing operations at your firm. Ask them what data the firm's QR-generator vendor retains, where the data is stored, and what their data-sharing agreements look like. The answer will tell you everything you need to know.
And then — when you are ready — print a new business card with a SealedQR on the back. Hand it to the next 60 people you meet at a conference. Watch the spam calls go to zero.
That is the deal we are making.
Try SealedQR free
Five private vCards. No credit card. No analytics partners. Encrypted at rest by default.
Start free See how it works