QR code payments: a checkout anywhere you can stick a square
A payment QR code encodes a link to a secure checkout: the customer scans with their camera, a payment page opens with the amount or catalogue ready, and they pay by card or wallet on their own phone. Static codes point to a fixed destination and cost nothing to print; dynamic codes are generated per transaction with the amount embedded. The pattern's power is deploying checkout where hardware is impractical: tables, counters, vehicles, posters, invoices and events.

Scope: For restaurants, services, nonprofits and retailers who want payment capability on surfaces instead of just at terminals.
What actually happens at the scan
Every phone camera now reads QR codes natively, and a payment QR simply encodes a URL: your hosted checkout. The customer scans, the page opens on their phone with your branding and either a preset amount, an open amount field or a small catalogue, and they pay with a tapped wallet or typed card. Confirmation lands on both sides; the transaction settles and reports like any other online payment.
The elegance is in what is absent: no app for the customer, no hardware at the point of scan, no card changing hands. The merchant's 'device' is ink, a screen or a sticker, which is why the pattern deploys anywhere a rectangle fits.
Static versus dynamic codes
A static code points at a fixed destination and never changes: print it once, use it forever. It suits fixed-purpose surfaces, a donation stand, a tip jar, a 'pay your invoice' link on statements, a menu board with pay-at-table, and open-amount pages where the customer enters what they owe.
A dynamic code is generated per transaction, usually displayed on a screen or printed on a bill, with the exact amount and reference embedded. It suits per-sale contexts: a restaurant bill with the table's total, a service invoice, a checkout screen mirroring the cart. Dynamic codes reconcile perfectly, because each scan is born tied to its transaction, at the cost of needing a screen or printer in the loop.
Most merchants end up with both: static codes on the surfaces, dynamic codes in the receipts and bills, all pointing into the same payment account.
The deployments that actually convert
• Pay-at-table: a code on the table tent lets guests settle when they are ready, tips included, without flagging staff; table turns improve without anyone hovering.
• Invoices and statements: a QR next to the payment link serves the customer who received paper or a PDF on a desktop; the phone becomes the payment device either way.
• Field and vehicle: a code on the truck door or the work order collects deposits and balances where taking hardware is a hassle.
• Donations and events: stands, posters and screens at fundraisers and venues convert impulse generosity that would never survive a 'visit our website' instruction.
• Queue-busting and curbside: signage lets waiting customers pay before they reach the counter.
In each case the QR is not replacing a terminal; it is putting a checkout where no terminal was ever going to be.
Security: yours and your customers'
The transaction itself rides the hosted checkout's security: PCI-scoped card fields, AVS and CVV checks, wallet tokenization. The QR-specific risk is physical: sticker fraud, someone overlaying your printed code with one pointing at their page. Defend with routine: inspect public-facing codes as part of opening checks, use tamper-evident stock for permanent placements, and frame codes with your branding so an overlay is visually obvious.
Coach the customer-facing detail too: the checkout your code opens should carry your name and a recognizable payment domain, and staff should be able to say so. A customer who glances at the URL and sees the brand they are standing in is a customer the overlay attack fails against.
With RapidCents, QR payments are the payment-pages and payment-links products in scannable form: generate static or dynamic codes from the dashboard, brand the checkout behind them, and watch scans settle into the same reporting as your terminals. The whole setup, first code to first payment, fits inside an afternoon.
Frequently asked questions
Do customers need an app to pay by QR code?
No. The phone's native camera reads the code and opens your hosted checkout in the browser, where the customer pays by card, Apple Pay or Google Pay. Nothing is installed and no account is created.
What is the difference between static and dynamic QR codes?
A static code points to a fixed page, an open-amount checkout, a donation page, and is printed once. A dynamic code is generated per transaction with the amount and reference embedded, ideal on bills and screens, and reconciles automatically to its transaction.
Are QR code payments safe?
The payment itself uses the same secured hosted checkout as any online sale. The specific risk is fraudulent sticker overlays on printed codes; routine inspection, tamper-evident printing, branded frames and a recognizable checkout domain defeat it.
What do QR payments cost the merchant?
They process as card-not-present transactions at your normal online rates; the codes themselves cost nothing to generate. There is no separate QR fee with RapidCents.
Can tips work through a QR payment?
Yes: the hosted checkout can present tip options exactly as a terminal does, which is why pay-at-table QR flows preserve, and often improve, tip rates while freeing staff from the payment shuttle.





