Skip to contentFree 30 minute call with Pali

SaaS · 2026

UrusPro and HelloStay

UrusPro left a vendor-locked no-code prototype for an owned SaaS that now sells paid plans per listing.

UrusPro and HelloStay are a property-management and short-stay booking platform that I own, design and build. I moved the product off a vendor-locked no-code prototype onto an owned backend on Cloudflare. HelloStay takes guest bookings, UrusPro runs hosts, staff and the platform itself, and per-listing paid plans are live at uruspro.com.

Live
  • Own product
  • SaaS
  • Hospitality

Last updated

Visit live site: uruspro.com (opens in a new tab)

What were the results?

Commits authored
997
As of Oct 2026
Paid pricing
Per listing, live
As of Oct 2026
Roles
Guest, host, staff, super-admin
As of Oct 2026
A minimal white house form with a silver key leaning against it on a light grey studio background

Screens

Real pages from the live product.

What problem did it solve?

The product began as a no-code prototype locked inside a vendor: fine as a demo, but the business could not own its backend, secure it properly or run paid plans.

What was built?

  • Two products, one platform: HelloStay is the guest booking app; UrusPro is the operator platform for hosts, staff and the platform super-admin.
  • Security from the ground up: row-level security and a single writer for booking status, so two people cannot double-book the same night.
  • Payments the operator controls: per-organisation Billplz and CHIP gateways that stay inert until keys are added, plus manual bank, QR and cash.

How is it engineered?

Measured from the source repository, not estimated. As of Oct 2026.

Architecture

Server-rendered TanStack Start (React) app on Cloudflare Workers, backed by Supabase Postgres plus 28 Deno edge functions, wrapped as iOS and Android apps with Capacitor.

Data and isolation

Postgres with 339 schema migrations, 522 row-level security policies over 138 RLS-enabled tables, organisation-scoped access helpers (is_org_member alone appears 160 times), money held as fixed-point numeric(10,2) and numeric(12,2) ringgit columns, and a database exclusion constraint that makes double bookings impossible.

Security and privacy

  • Payment callbacks verified per organisation: each webhook is checked against that organisation's own gateway key, and processed events are recorded for idempotency
  • Per-organisation gateway and AI secrets encrypted at the application layer with AES-256-GCM
  • Database-backed brute-force throttle on walk-in sign-in (5 attempts, 15-minute lockout) that survives stateless edge calls
  • Server-side schema validation with zod in 19 modules; identity-card access written to an audit log

Regulatory rules in code

Implements PDPA 2010 rights: analytics only after explicit consent, self-service account erasure that anonymises personal data while keeping booking and payment rows for statutory retention, and automatic deletion of guest ID photos 30 days after checkout.

Quality evidence

Automated tests581 passing, 0 failing (2,684 assertions, 49 files)Full test suite run on the main branch
Build gatesESLint plus 9 custom checks block every buildBuild script in the repo
Schema migrations339Count of versioned migration files
Commits1,028 hand-authoredGit history of the main branch, excluding commits made by the starter-template bot

Operations

Deployed to Cloudflare Workers from git, with a sandbox flag for payment webhooks, 11 scheduled Postgres jobs (rent reminders, auto-pricing, iCal sync, retention purges) and a merge hook that blocks stale branches from landing on main.

What was my role?

Product owner, designer and engineer. I migrated the app off Lovable onto an owned backend and Cloudflare, then kept building.

What else shaped the build?

  • Operations that fit real hosts. iCal feed sync with booking platforms, BM and English, and a done-for-you setup offer.
  • Fast at the edge. Server-rendered on Cloudflare Workers.

Where does it stand now?

UrusPro and HelloStay are live at uruspro.com and hellostay.uruspro.com, with per-listing paid pricing live for homestays and rooms.

Built with
  • Pali UI
  • Asset Library
  • Pattern Library

Next case study

MITEAn institute's brochure site now takes enrolments for 18 programmes, with CRM and finance on one platform.

Want something like this built?

Get a price in two minutes, or talk it through on a free call.