Client Collaboration Portal for a Custom Travel Agency
Budget: $15.0 - $50.0
HOURLY / FULL_TIME
⭐ 5.00 (31)
United States
database-development, node.js, web-application, app-development
Gewenste kwalificaties
- Ervaring: Expert
We're a custom travel agency looking for someone to build a client collaboration portal (web applicaiton). Today we plan trips in Travel Joy and collaborate with clients over email, phone, and copy-pasted Google Sheets, which leaves no record of what was agreed and no way for clients to respond to what we propose. We need a portal where each itinerary item — hotel, flight, activity, transfer — carries an approval status: the client either approves it or requests a change with a required comment, we're notified, we make the edit, and a client-visible revision log shows what changed. Behind that we need a CRM for clients and trips, an itinerary builder with typed items and a reusable template library, planner-to-client messaging, notifications, and branded PDF output. Two requirements rule out most platforms: 1. no per-user pricing for clients, we may be planning 100+ trips at a time and a group trip can have 50+ travelers who each need a login to submit their own passport and preference details (i.e., we may have 5,000+ people on the portal at once or), and 2. two-axis record permissions enforced server-side, where everyone on a trip sees the shared itinerary but each traveler sees only their own room and flights, never another traveler's. We haven't picked a platform, but Stacker.ai, Noloco, and Softr have major limitations so more than likely a vibe code/no code platform will not work, and CMS’s like Wordpress also cannot render the capabilities we need. We do have a dedicated enterprise architecture resource on our team that tested this but also does not have the bandwidth to fully architect a platform and implement, so we have a full spec ready below covering the data model, permission matrix, and build phases.
⭐Please read full spec attachment to learn more about this project
Problem: Our current itinerary tool has no way for clients to give us structured feedback. So when we propose a hotel or a day plan, the response comes back by phone, email, or a copy-pasted spreadsheet. There's no approval status, no record of what changed or why, and no single place either side can look to see where things stand. On a trip with dozens of moving parts, that costs us hours per client and creates real risk of something being missed.
What we need:
A client-facing portal with:
- A CRM: holding client records, trips, travel preferences, and trip history
- An itinerary builder: with typed items including lodging, flights, activities, transfers, restaurants, cruises, rail, car rental — each with its own fields, plus a library of reusable blocks our planners can drop into any trip
- An approval workflow: where each itinerary item moves through In Progress → Pending Approval → Approved, or gets sent back as Change Requested with a mandatory comment explaining why
- A revision log: clients can see, so after we make a change they know exactly what changed
- Comments and messaging: between planners and clients, on individual items and generally
- Notifications: in-app and by email, with the ability to turn email off per event type
- Branded PDF output: of the final itinerary, generated from the portal data
These are non-negotiable and they rule out several popular platforms:
1. **No per-user pricing for clients.** A single group trip can have 50+ travelers, each needing their own login to submit passport details and travel preferences. Per-seat pricing for external users doesn't work for us at any tier.
2. **Two-axis record permissions, enforced server-side.** Everyone on a trip sees the shared day-by-day itinerary. But each traveler sees only *their own* room assignment, flights, and personal data — not the other 49 travelers'. This has to be enforced at the data layer, not by hiding elements in the interface.
Required experience
● 6+ years building and shipping production web applications end to end
● 3+ years specifically on multi-tenant applications where different users see different subsets of the same data — client portals, SaaS platforms, marketplaces, healthcare or legal software, or similar
● Demonstrated experience designing and implementing authorization models, not just authentication. You've built systems where "which records can this user see" was a hard problem, and you can talk about how you solved it
● Experience handling PII in production — passport data, dates of birth, payment references — including encryption at rest, access logging, and least-privilege design
Core technical skills
● Strong backend proficiency in one of: Laravel/PHP, Ruby on Rails, Django/Python, or Node/TypeScript. We're stack-agnostic and will defer to your recommendation, but you should be deeply fluent in whichever you propose rather than learning it on our project
● Relational database design — normalized schema, indexing, migrations. PostgreSQL preferred
● Row-level authorization implemented at the data layer. Postgres RLS, policy objects (Pundit/CanCanCan), Laravel Policies and Gates, Django Guardian, or an equivalent approach you can defend
● Modern frontend: React, Vue, or a server-rendered equivalent (Inertia, Hotwire, Livewire). The interface needs to be genuinely good — planners use it daily and clients judge us by it
● Role-based access control with field-level granularity, not just page-level gating
● Audit logging and change tracking — PaperTrail, django-simple-history, Laravel Auditing, or a custom implementation. We need a client-visible record of what changed on each itinerary item
● REST/webhook integrations: Stripe, JotForm, Kit (ConvertKit)
● Transactional email at production quality — Postmark, SES, or SendGrid, with deliverability configured properly
● Server-side PDF generation from application data with real design fidelity (Puppeteer, Playwright, WeasyPrint, or a rendering service)
● File upload and storage with access control — S3 or equivalent, with signed URLs
● Deployment, environments, and CI/CD. You own staging and production, not just the codebase
Nice to have
● Supabase or similar experience, particularly with Postgres Row-Level Security
● Prior work in travel, hospitality, events, or another domain with group bookings and per-participant data
● Experience with document generation templates at scale
● Background in security review or penetration testing
● Comfort with SOC 2 vendor requirements and compliance documentation
What we're not looking for
● No-code or low-code implementers. We evaluated Stacker, Noloco, and WordPress and decided against them for this build
Openen op Upwork
AI proposal draft
Generate a short cover letter for this job. Edit before sending.
Sign in to generate an AI proposal draft.
Inloggen