Trackingplan

Spain · www.trackingplan.com · 7 vendors

Resilience scores

Technology vendors

Services catalogue

1 service in catalogue across 1 category; runs on 7 sub-vendors.

Insights

Last updated 2026-07-30 · revision 5

7 direct vendors, 133 subvendors

Direct vendors by controlling owner country (sample)

Subvendors by controlling owner country (sample)

Migration Readiness: 8/10

Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.

Trackingplan exhibits high migration readiness, largely due to its cloud-native architecture and mature infrastructure management practices. The company's tech stack, built on AWS (PaaS) and ClickHouse Cloud, is inherently flexible for cloud environments. The extensive use of Terraform for Infrastructure as Code (IaC) is a significant advantage, enabling automated provisioning and replication of environments, which greatly simplifies potential migrations. The presence of CI/CD pipelines further indicates mature deployment processes that would facilitate a smooth transition. Existing robust data residency controls, with EU clients' data in EU data centers and US clients' data in US data centers, demonstrate a capability to manage complex data location requirements, although these strict requirements would need to be meticulously maintained during any migration, adding a layer of complexity. Modern security practices, including TLS 1.2+, AES-256 encryption, AWS WAF, and AWS Cognito, also contribute to a secure migration pathway. The primary challenges for migration readiness stem from the unknown financial stability (due to missing revenue and employee data), which could impact the ability to fund a significant migration effort. Furthermore, while the "Total Vendors: 0" data point is contradictory to their tech stack, their reliance on AWS PaaS and ClickHouse Cloud implies a degree of platform-specific vendor lock-in. Migrating away from these core services would likely require substantial refactoring and data migration. The lack of formal SOC2 and ISO 27001 certifications, while not a direct impediment, could become a requirement for new environments or enterprise clients post-migration, necessitating additional effort. Despite these challenges, the strong cloud-native foundation and IaC capabilities position Trackingplan well for future migrations.

Compliance

3 in-scope frameworks identified; showing 3.

SOC 2 (source) — Assessment Required

As a cloud-based SaaS provider handling customer data, SOC2 compliance would be highly beneficial for Trackingplan to demonstrate security controls to enterprise customers. While not legally mandatory, SOC2 Type II certification is increasingly expected by enterprise clients for vendor risk management. The medium risk reflects potential business impact from lack of formal SOC2 certification when competing for enterprise accounts, though their documented security practices suggest they may already meet many SOC2 requirements.

Evidence: https://www.trackingplan.com/docs/privacy-and-security

ISO 27001 (source) — Assessment Required

ISO 27001 certification would be valuable for Trackingplan as an information security management standard, particularly given their role in processing customer analytics data. While not mandatory, ISO 27001 certification demonstrates systematic information security management and is often required by enterprise customers. The medium risk reflects potential competitive disadvantage and customer requirements, though their documented security practices suggest alignment with ISO 27001 principles.

Evidence: https://www.trackingplan.com/docs/privacy-and-security

GDPR (source) — Compliant

Trackingplan demonstrates strong GDPR compliance with privacy-by-design architecture, on-device anonymization, data minimization principles, and explicit GDPR compliance documentation. As an EU-based company (Spain) processing personal data, GDPR is mandatory and they have implemented comprehensive technical and organizational measures including DPAs, data retention limits (90 days), and data subject rights procedures. Their privacy-first approach and documented compliance measures significantly reduce regulatory risk.

Evidence: https://www.trackingplan.com/privacy-hub, https://www.trackingplan.com/docs/privacy-and-security

Financials

Three-year financials

Financial Resilience Score: 5/10

Trackingplan is a young (founded 2021) Spain-based B2B SaaS company in the MarTech/analytics observability space. No audited revenue, EBIT, or equity figures are publicly disclosed, which limits quantitative assessment. However, qualitative signals are moderately positive: the company has achieved product-market fit with 485+ customers including named enterprise logos (El Corte Inglés, Schneider Electric, Dentsu, Havas, ISDIN, Cofidis), operates a recurring SaaS subscription model with predictable ARR characteristics, and has diversified vertical exposure across retail, travel, industrial, media agencies, and finance. The company benefits from non-dilutive ENISA public financing (Spanish Ministry of Industry-backed instrument), which provides patient capital runway. International customer footprint spans Spain, EU, and US, reducing dependence on a single geography. The AI-driven, zero-config technology offers real differentiation versus legacy QA tools. However, as a typical early-stage Spanish SaaS company, Trackingplan is likely still cash-burning with funding dependency on equity rounds and ENISA debt. It faces intense competition from better-capitalized rivals (ObservePoint, Avo, Amplitude/Iteratively, Segment Protocols, Snowplow), platform-dependency risk on third-party analytics ecosystems (GA4, Meta, Adobe), and key-person risk given small founding team. The overall profile suggests moderate resilience appropriate for a Series A-stage SaaS company with public sector backing but limited financial transparency.

Key strengths: Product-market fit with 485+ customers including named enterprise/agency buyers, Recurring SaaS subscription revenue model with predictable ARR, Diversified vertical exposure (retail, travel, industrial, media, finance), International customer footprint across Spain, EU, and US, ENISA non-dilutive public financing from Spanish Ministry of Industry, Defensible AI-driven, zero-config technology differentiation, Dedicated agency partner GTM motion alongside direct sales, Self-reported scale: ~1M users, ~2.2B events monitored daily

Risk factors: Early stage (founded 2021), likely still cash-burning with no confirmed profitability, Funding-dependent on equity rounds and ENISA debt, Crowded competitive landscape with much larger-balance-sheet rivals (ObservePoint, Amplitude, Segment, Adobe), Platform-dependency on third-party analytics APIs (GA4, Meta Pixel, TikTok, Adobe), Browser/OS privacy rule changes (ITP, ATT, cookieless) could disrupt underlying telemetry, Undisclosed customer concentration; churn of few enterprise accounts could materially affect ARR, Key-person risk with small founding team concentrated in technical roles, Geographic skew toward Spain may limit USD-denominated enterprise ACVs vs US competitors, No public disclosure of revenue, EBIT, equity, headcount, or funding details

Revenue by geography

Revenue by product/service

Workforce by country

Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.

View the full interactive report