Scratcher.io
Denmark · owned by Independent (Denmark) · scratcher.io · 20 vendors
Scratcher.io is a cloud-based gamification marketing software solution provider that offers an interactive platform. The platform provides over 20 interactive formats, such as scratch cards and quizzes, to help businesses engage audiences, generate leads, boost conversions, and drive sales. It is designed for marketers, e-commerce, and various businesses to create interactive customer experiences.
Resilience scores
- Digital Sovereignty: 20
- Digital Resilience: 8
- Financial Resilience: 5
Disruption prediction
Scratcher.io has an estimated 40% probability of disruption in the next 6 months.
11 of Scratcher.io's 20 vendors monitored for disruptions.
Technology vendors
- Cookiebot (Cybot A/S) — Technology — Denmark
- HubSpot, Inc. — Technology — United States
- Stripe, Inc. — Financial Services — United States
- and 17 more
Services catalogue
3 services in catalogue across 2 categories; runs on 20 sub-vendors.
- Digital Promotions/Scratch Cards
- Gamification
- Marketing/Engagement Platform
Insights
Last updated 2026-09-13 · revision 2
20 direct vendors, 267 subvendors
Direct vendors by controlling owner country (sample)
- Germany: 1
- Israel: 1
- Denmark: 1
Subvendors by controlling owner country (sample)
- Norway: 2
- South Korea: 2
- France: 7
Migration Readiness: 6/10
Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.
Scratcher.io exhibits a moderate level of migration readiness. Key strengths include its existing European-hosted cloud infrastructure and a strong commitment to regulatory compliance, as demonstrated by ISO 27001 certification and GDPR adherence. These factors provide a structured environment for managing data and security during a migration. The tech stack also features modern integration capabilities such as REST API, webhooks, and Zapier, which can facilitate the decoupling of services and a more modular approach to re-platforming. However, several significant challenges impact its migration readiness. The presence of WordPress and Elementor in the internal tech stack suggests a potential reliance on more traditional, possibly monolithic, architectural patterns that could complicate a transition to a fully cloud-native, containerized, or microservices-based environment. A critical unknown is the "Vendor Lock-in Risk," which, if high, could severely impede the ability to switch providers or migrate away from vendor-specific technologies, adding significant cost and complexity. The high number of "Total Services: 25" also indicates a substantial dependency landscape that would require careful mapping and migration planning. Furthermore, the lack of data on financial stability (revenue concentration, growth history) makes it impossible to assess the company's capacity to fund a potentially extensive migration project. While data residency requirements are "Not specified," the existing GDPR-compliant European hosting implies a strong regional data focus that would need to be maintained or carefully managed during any migration.
Compliance
7 in-scope frameworks identified; showing 3.
ePrivacy Directive — Partially Compliant
Risk is High because: (1) Scratcher's own website uses Facebook Pixel, Google Analytics, and other third-party tracking technologies that require valid prior consent under the Danish Cookie Order (implementing ePrivacy Directive 2002/58/EC). (2) More critically, Scratcher's platform enables its customers to embed interactive campaigns on their websites and collect user data — the platform itself may set cookies or tracking technologies on end-user devices, requiring compliant consent mechanisms. (3) The Privacy Policy (dated February 2021) describes cookie use but does not reference a compliant consent management platform or describe how prior consent is obtained before non-essential cookies are set. (4) Datatilsynet and the Danish Business Authority (Erhvervsstyrelsen) actively enforce cookie rules. (5) The upcoming ePrivacy Regulation (expected to replace the Directive) will further tighten requirements. Risk is High due to the dual exposure: Scratcher's own website and the campaigns it enables for customers.
Evidence: https://scratcher.io/privacy-policy/, https://scratcher.io/, https://www.datatilsynet.dk/english, https://www.retsinformation.dk/eli/lta/2011/1148
Danish Marketing Practices Act — Assessment Required
Risk is Medium because Scratcher's core business — gamification marketing campaigns including prize draws, scratch cards, competitions, and loyalty mechanics — is directly regulated by Danish marketing law. The Danish Marketing Practices Act (Consolidated Act No. 426 of 3 May 2017, as amended) governs promotional competitions, prize draws, and marketing communications. As a platform enabling these activities for third-party brands, Scratcher and its customers must comply with rules on fair marketing, prize draw transparency, and consumer protection. Non-compliance could expose both Scratcher and its customers to enforcement by the Danish Consumer Ombudsman (Forbrugerombudsmanden). Risk is Medium because Scratcher operates as a platform/tool provider rather than directly running campaigns, but platform-level design choices (e.g., dark patterns, misleading game mechanics) could create liability.
Evidence: https://scratcher.io/gamification-marketing-for-online-casino/, https://scratcher.io/game-formats/, https://scratcher.io/terms-and-conditions/, https://www.forbrugerombudsmanden.dk/en/
NIS2 (source) — Assessment Required
NIS2 risk is Medium because: (1) Scratcher.io operates as a SaaS/digital platform provider in the EU, which falls under the NIS2 category of 'digital providers' — specifically potentially as a 'managed service provider' or 'online marketplace/platform' depending on classification. (2) Denmark has transposed NIS2 into national law (Lov om sikkerhed i net- og informationssystemer, effective October 2024). (3) The key uncertainty is whether Scratcher meets the size threshold: NIS2 applies to medium enterprises (50+ employees OR €10M+ annual turnover). Scratcher's employee count and revenue are not publicly disclosed, making threshold assessment uncertain. (4) If thresholds are met, non-compliance risk is meaningful — Danish authorities (Center for Cybersikkerhed / CFCS) can impose fines up to €10M or 2% of global turnover for Important Entities. (5) The ISO 27001 certification provides a strong foundation for NIS2 technical requirements but does not constitute NIS2 compliance itself. Risk is Medium rather than High because the size threshold applicability is uncertain and the ISO 27001 certification demonstrates a mature security posture.
Evidence: https://scratcher.io/iso/, https://scratcher.io/, https://www.cfcs.dk/en/, https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32022L2555, https://www.datatilsynet.dk/english
Financials
Three-year financials
- 2025: gross profit DKK 4.13M, equity DKK 8.43M
- 2024: gross profit DKK 8.41M, EBIT DKK 214K, equity DKK 7.91M
- 2023: gross profit DKK 6.73M, EBIT DKK -1.23M, equity DKK 7.68M
Financial Resilience Score: 5/10
Scratcher ApS is a Copenhagen-based gamification/interactive marketing SaaS company with a credible blue-chip customer base including Burger King (DK/SE), Toyota, Wolt, Continental, POWER, Ecooking, EWII, and BonBon-Land. The company benefits from broad industry positioning across retail, eCommerce, consumer goods, B2B, NGO, sports, travel, and iGaming, which reduces sectoral concentration risk. Its product breadth (35+ interactive game formats and 3,000+ integrations) creates stickiness once embedded into a customer's marketing stack, and ISO 27001:2013 certification supports enterprise sales cycles. However, as a small private Danish ApS, the company likely has a thin equity buffer and potential dependence on a limited number of key customers with founder/owner concentration. The gamification category is highly competitive, facing rivals such as Playable, Drimify, Woobox, Easypromos, and larger all-in-one platforms like Klaviyo and Braze that are integrating gamification features. Marketing-budget sensitivity is a concern since gamification spend is discretionary and cyclical. Without confirmed profitability data, and given that Danish SaaS scale-ups at this stage are frequently loss-making while investing in ARR growth, a mid-range resilience score is appropriate.
Key strengths: Blue-chip customer base including Burger King, Toyota, Wolt, Continental, POWER, Broad industry positioning reduces sectoral concentration risk, Product breadth with 35+ formats and 3,000+ integrations creates stickiness, ISO 27001:2013 certification supports enterprise sales, Multi-language support (EN/DA/DE/ES) indicates international expansion, G2 'Users Love Us' badge validates mid-market SaaS positioning, Recent partnership with LINK Mobility extends distribution channels
Risk factors: Small private ApS with likely thin equity buffer, Potential customer concentration and founder/owner concentration, Highly competitive gamification category with rivals like Playable, Drimify, Woobox, Larger all-in-one platforms (Klaviyo, Braze) integrating gamification features, Marketing-budget sensitivity as gamification spend is discretionary and cyclical, Currency and channel-partner reliance for DE/ES expansion, No confirmed profitability data; likely loss-making at growth stage
Revenue by geography
- DACH: 0%
- Sweden: 0%
- Denmark: 0%
- Spain/LatAm: 0%
Revenue by product/service
- SaaS Platform Subscriptions: 85%
- Professional Services: 15%
Workforce by country
- Denmark: 0
Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.