What problem did it solve?
The product began as a no-code prototype locked inside a vendor: fine as a demo, but the business could not own its backend, secure it properly or run paid plans.
What was built?
- Two products, one platform: HelloStay is the guest booking app; UrusPro is the operator platform for hosts, staff and the platform super-admin.
- Security from the ground up: row-level security and a single writer for booking status, so two people cannot double-book the same night.
- Payments the operator controls: per-organisation Billplz and CHIP gateways that stay inert until keys are added, plus manual bank, QR and cash.
How is it engineered?
Measured from the source repository, not estimated. As of Oct 2026.
Architecture
Server-rendered TanStack Start (React) app on Cloudflare Workers, backed by Supabase Postgres plus 28 Deno edge functions, wrapped as iOS and Android apps with Capacitor.
Data and isolation
Postgres with 339 schema migrations, 522 row-level security policies over 138 RLS-enabled tables, organisation-scoped access helpers (is_org_member alone appears 160 times), money held as fixed-point numeric(10,2) and numeric(12,2) ringgit columns, and a database exclusion constraint that makes double bookings impossible.
Security and privacy
- Payment callbacks verified per organisation: each webhook is checked against that organisation's own gateway key, and processed events are recorded for idempotency
- Per-organisation gateway and AI secrets encrypted at the application layer with AES-256-GCM
- Database-backed brute-force throttle on walk-in sign-in (5 attempts, 15-minute lockout) that survives stateless edge calls
- Server-side schema validation with zod in 19 modules; identity-card access written to an audit log
Regulatory rules in code
Implements PDPA 2010 rights: analytics only after explicit consent, self-service account erasure that anonymises personal data while keeping booking and payment rows for statutory retention, and automatic deletion of guest ID photos 30 days after checkout.
Quality evidence
| Automated tests | 581 passing, 0 failing (2,684 assertions, 49 files) | Full test suite run on the main branch |
|---|---|---|
| Build gates | ESLint plus 9 custom checks block every build | Build script in the repo |
| Schema migrations | 339 | Count of versioned migration files |
| Commits | 1,028 hand-authored | Git history of the main branch, excluding commits made by the starter-template bot |
Operations
Deployed to Cloudflare Workers from git, with a sandbox flag for payment webhooks, 11 scheduled Postgres jobs (rent reminders, auto-pricing, iCal sync, retention purges) and a merge hook that blocks stale branches from landing on main.
What was my role?
Product owner, designer and engineer. I migrated the app off Lovable onto an owned backend and Cloudflare, then kept building.
What else shaped the build?
- Operations that fit real hosts. iCal feed sync with booking platforms, BM and English, and a done-for-you setup offer.
- Fast at the edge. Server-rendered on Cloudflare Workers.
Where does it stand now?
UrusPro and HelloStay are live at uruspro.com and hellostay.uruspro.com, with per-listing paid pricing live for homestays and rooms.


