This applies whether there's a redirect in place or not. If you're in the "False Napkin Restaurant", and they have QR codes that take you to falsenapkin.com, I could just register falsenapkinrestaurant.com and replace the menus. Ordinary people will have no way of knowing the difference.
> doesn't mean that I would like to consent to the privacy policy of or provide any information to the 3rd party they chose
That's an issue regardless of whether there's a direct client-side redirect or if there's just some Javascript inclusion going on that was provided by a third party but without an explicit redirect. Either way, your data can be used by whoever the restaurant has contracted and your ability to consult their privacy policy remains the same.