Featured Project

Boticum CRM — Multi-Tenant SaaS CRM (Web & Mobile)

A multi-tenant SaaS CRM where WhatsApp and Instagram DMs flow into one shared inbox. Sales teams claim conversations, build customer profiles, manage leads and deals, and send invoices and campaigns — from a Next.js web app or a React Native mobile app running on the same backend.

The source code is in a private GitHub repository because the system runs in production. Access is available on request.

Request Code Access by Email

Technology Stack

Next.js 16 (App Router) TypeScript React Native + Expo Expo Router Supabase (Postgres, Auth, Realtime, Vault) Row Level Security Inngest (background jobs) Meta WhatsApp Cloud API Instagram Graph API OpenAI API Stripe next-intl (i18n) Zod Vitest pnpm Monorepo Vercel EAS Build

Screenshots — Web App

Captured from a local environment with demo data. Some modules are blurred because the product is in commercial use.

Screenshots — Mobile App (iOS)

The React Native app running on an iPhone simulator, connected to the same backend.

Boticum CRM mobile app — Inbox
Inbox
Boticum CRM mobile app — Conversation
Conversation
Boticum CRM mobile app — Customers
Customers
Boticum CRM mobile app — Pipeline
Pipeline
Boticum CRM mobile app — Leads
Leads

Context & Background

Small and mid-sized businesses in the UAE sell mostly through WhatsApp and Instagram. In practice this means several salespeople replying from one shared phone, customers getting answered twice (or not at all), and no record of who talked to whom. Boticum CRM was built to fix that: every message arrives in a shared inbox, one agent locks the conversation, and everything the team learns about the customer is saved on a single customer card.

It is a SaaS product, so many companies (tenants) use the same system while their data stays fully separated. Each company can have branches, and the owner decides what managers and agents are allowed to see and do. Its first market is Dubai, but the product was designed from the start so that language, currency, and tax rules can be configured per country.

I started with the architecture: locked design decisions, around 40 use cases, an ERD, and a security model. I then built the system in seven phases. The web apps and the database run in production, and a real WhatsApp Business number already receives and sends messages through the live system.

Web Application

Two separate Next.js apps deployed on Vercel. Keeping them apart means a tenant login can never reach the platform back office.

  • Tenant app (the CRM itself, served per company subdomain): dashboard, shared inbox, customers, leads, sales pipeline, tasks, invoices, campaigns, reports, exports, notifications, and settings.
  • Admin back office (for the Boticum team): tenant management and suspension, platform billing, audit logs, and the platform's own WhatsApp number used to send one-time codes.
  • Server components and server actions handle all data access, and every query goes through the permission engine. There is no separate backend service.

Mobile Application

A single React Native + Expo codebase for iOS and Android, built with EAS. It uses the same shared packages (core and db) as the web, so permission and validation logic is written once.

  • Tab navigation for Inbox, Customers, Leads, Pipeline and More (tasks, invoices, campaigns, team, search, account).
  • Live chat with image and document attachments, creating and editing customers, lead status changes, and approving deletion requests on the go.
  • A separate admin area in the same app for platform staff (tenants, audit log, platform WhatsApp).
  • No payments on mobile: the app never shows prices or purchase links. This keeps it compliant with App Store and Google Play in-app purchase rules. Billing is only available on the web.

Realisations

The delivered system includes the following modules:

Architecture & Security

What I Learned — Hard Skills

  • Designing a multi-tenant SaaS architecture and data model from scratch
  • PostgreSQL Row Level Security, JWT claims, and Supabase auth hooks
  • Next.js App Router with server components, server actions, and route handlers
  • Building a cross-platform mobile app with React Native, Expo Router, and EAS
  • Sharing code between web and mobile in a pnpm monorepo
  • Integrating the Meta WhatsApp Cloud API and Instagram Graph API with webhooks
  • Storing secrets in Supabase Vault and building rotation flows
  • Event-driven background jobs with Inngest
  • Subscription billing and usage metering with Stripe
  • REST API design with versioning, rate limiting, and outgoing webhooks

What I Learned — Soft Skills

  • Turning a business problem into written specifications before writing code
  • Planning a large build in phases and keeping a detailed progress log
  • Debugging production problems with third-party platforms from logs and documentation
  • Weighing security, cost, and app store rules when making product decisions
  • Gathering feedback from partners who tested the live system and turning it into features

My Role

This is my own product and I built it end to end. I wrote the architecture and the database schema, implemented the web apps, the mobile app, and all the integrations, and handled deployment and production debugging. The most valuable lesson was that connecting to real platforms like Meta and Stripe takes as much work as building the features themselves: webhook subscriptions, token lifecycles, message templates, and delivery rules all had to be understood and handled correctly.

Back to Projects