How QR Attendance Works on mysmartaccesscard
A clear explanation of how QR code-based attendance is recorded, verified, and stored — and why it's more reliable than paper registers or biometric systems.
Every user on mysmartaccesscard is issued a unique QR code tied to their account. This code cannot be duplicated, shared, or used by anyone else — it is cryptographically linked to your user ID.
The check-in flow
- 1
An employee, student, patient, or member opens their mSAC app and shows their QR code.
- 2
A supervisor, security officer, or authorised staff member opens the Scanner tab on the business dashboard.
- 3
They scan the QR code using the in-app camera scanner.
- 4
mSAC's backend verifies the code against the Firestore database in real time.
- 5
The attendance record is created — timestamped, linked to the user and the business, and visible immediately in the Attendance tab.
Why proxy attendance is impossible
Each QR code is unique to one person and one device session. Sharing a screenshot of the code with someone else would require them to physically hold your phone — and even then, QR codes used for attendance on mSAC are dynamic (they refresh periodically), so a static screenshot becomes invalid quickly.
Geo-fencing
Businesses can enable geo-fenced attendance. When active, the scanner captures the GPS location of the device at the moment of scan. If the scan occurs outside the authorised zone, it is flagged. Location is captured only at the moment of the scan — it is not tracked continuously.
What gets recorded
- User ID and full name
- Business ID
- Timestamp (date and time of scan)
- GPS location (if geo-fencing is enabled)
- Attendance status (present, late, absent)
- Scanner device info
Data retention
Attendance records are retained for 12 months after the last activity. After that they are automatically purged. You can export attendance data as a PDF at any time from the Attendance or Analytics tabs.
Published 15 April 2026 · mysmartaccesscard
Back to Blog