All work
Solo product39 days, idea → production

Onescle — The e-commerce operating system for Bangladesh

A multi-tenant SaaS that gives every merchant a storefront, an owner dashboard, courier booking, local payments, fraud protection, a POS and mobile apps — in Bangla and English.

onescle.com
Onescle website
Onescle on mobile
39days to production
730commits
1,148API routes
178data models
757test files
7apps shipped

My role

Founder-engineer — system design, backend, web, mobile, DevOps, marketing

The problem

Bangladeshi merchants juggle six disconnected tools and lose money on fake cash-on-delivery orders that also poison their Meta ad targeting.

Stack

NestJS 11FastifyPrisma 7PostgreSQL 17RedisRabbitMQNext.js 16React 19FlutterCloudflare R2DokployGemini

Storefront theme templates were contributed by a teammate.

What I built

  • Postgres row-level security per transaction on top of app-level tenant scoping — 65 RLS policies across 178 models.
  • Load-tested at 10,000 tenants / 554k products: 248–308 req/s at p95 ≈ 150 ms, zero errors — after finding and fixing an index that made every tenant pay for every other tenant.
  • RabbitMQ with outbox, retries, dead-letter queue and idempotency keys, in a separate worker process.
  • Fraud Shield: scores orders and holds the Meta CAPI Purchase event until a COD order proves real, so ad spend never optimises for fraudsters.
  • 7 payment providers (bKash, Nagad, SSLCommerz, Stripe, COD…) and 5 couriers (Steadfast, Pathao, RedX, Carrybee) behind single interfaces with reconciliation jobs.
  • One OpenAPI contract generates typed clients for 3 Next.js apps and 2 Flutter apps.
  • Offline-capable Flutter desktop POS with receipt printing, cash drawer via FFI and a CI-built Windows installer.
  • Custom domains with wildcard TLS and one-click Cloudflare DNS setup; Gemini-powered product drafts from a photo.

39 days, phase by phase

Reconstructed from 730 commits between Aug 22 and Sep 29, 2026.

  1. 1
    Day 1–2

    System design

    Monorepo, 59-section architecture doc, tenancy model, outbox + DLQ, first order and inventory modules.

  2. 2
    Day 3–10

    Commerce core

    Orders, inventory reservations, payments, shipping, media — storefront and both dashboards scaffolded.

  3. 3
    Day 11–17

    Platform & launch infra

    Admin platform, auth + 2FA, custom domains, RabbitMQ, brand identity — production on Dokploy by day 17.

  4. 4
    Day 18–24

    Storefront engine

    Theme gallery, page-builder canvas, code registry and merchant onboarding.

  5. 5
    Day 25–31

    Growth & trust

    Meta Pixel + Conversions API, Fraud Shield, SEO, i18n and the marketing site.

  6. 6
    Day 32–39

    Apps & hardening

    Flutter seller app and desktop POS, PWA, security review — live on Google Play.

Architecture

Follow a request from top to bottom: every visitor enters through Cloudflare (custom domains, SSL, security), reaches the apps, then one API and a background worker.

1USERS2EDGE3APPS4API5DATA6INTEGRATIONSShoppersyourbrand.com · shop.store.onescle.comMerchantsapp.onescle.com · mobile & POS appsPlatform adminsadmin.onescle.comCloudflareevery request enters here — merchants bring their own domain, SSL is issued automaticallyCustom domains + auto SSLWildcard *.store.onescle.comWAF + DDoS protectionCDN cache for mediaStorefrontNext.js 16 · SSROwner dashboardNext.js · Bangla/ENPlatform adminNext.jsSeller appFlutter · Android/iOSDesktop POSFlutter · offlineNestJS 11 + Fastify API53 modules · 1,148 routes · one OpenAPI contractBackground workeroutbox · retries · dead-letter queuePostgreSQL 17row-level security per shopRediscache · rate limitsRabbitMQevents · idempotencyCloudflare R2media · backupsPaymentsbKash · Nagad · SSLCommerz · StripeCouriersSteadfast · Pathao · RedX · CarrybeeMeta adsPixel + Conversions APIAI & SMSGemini · SMS gateway

Screens

onescle.com
Onescle screen 2
onescle.com
Onescle screen 3
onescle.com
Onescle screen 4
Next case studyEduQaf