Skip to content

Custom software development · Mecca

Custom Software Development Company for Mecca

We build group and permit tracking, fleet dispatch, occupancy and vendor-logistics systems for the licensed operators and businesses serving Mecca’s pilgrim economy, delivered remotely from Ahmedabad, India, on Saudi hours. QalbIT holds no office and no legal entity anywhere in the Kingdom, and this page sets out exactly what that changes.

It also sets out what we never touch: religious content, ritual guidance, religious licensing or doctrinal matters sit outside every engagement we take on, at any size, for any client. What follows covers the two legal questions that decide whether you can hire us at all: ZATCA e-invoicing and PDPL cross-border data.

  • 2018

    Building software since

  • 5.0

    Clutch rating

  • 50+

    Clients served

  • 5.0

    Clutch rating

Get your free estimate

Three quick questions: scope, approach and a price range back within 48 hours. No sales call required first.

What do you need built?
When do you want to start?
Where should we send the estimate?

Answer all three questions above, then send.

NDA-friendly · IP yours from day one

Definition


What a remote software partner actually builds for a Mecca operator

QalbIT builds operational software, group and permit tracking, transport dispatch, accommodation-capacity and vendor systems, for licensed businesses serving Mecca’s pilgrim economy, as a remote engineering partner rather than a Kingdom-based firm. We do not build, advise on or claim any authority over religious content, ritual guidance or religious licensing: our work stops at the business system a licensed operator runs behind it. The same two national rules apply as anywhere in the Kingdom: ZATCA Phase 2 e-invoicing, whose Wave 25 threshold of SAR 187,500 reaches almost every VAT-registered business by 1 February 2027, and PDPL Article 29, governing personal data that leaves Saudi Arabia. Delivery runs from Ahmedabad, India, on Mecca working hours.

Mecca does not run on one steady economic rhythm. A short annual peak, the days of Hajj, carries volumes few operations anywhere are built to absorb, set by a government-managed quota no operator can expand on its own. The rest of the year moves differently: Umrah traffic that never fully stops but never spikes the same way either. Software built for one of those shapes rarely survives the other.

A systems provider registered inside the Kingdom knows this rhythm from the inside. It staffs up in Mecca through the peak, contracts in Arabic, and can be reached from a nearby office the moment a screen goes dark during Hajj week. A remote partner cannot offer that. What it can offer is a system engineered around the underlying scale problem: capacity that grows by an order of magnitude for a fixed window, then shrinks back without leaving infrastructure nobody wants to keep paying for the rest of the year.

That trade is not automatically the right one. It stops being right the moment the job needs a person walking a lodging site alongside your staff in the weeks before the season opens. Everything short of that, group and permit tracking, fleet dispatch, occupancy dashboards, vendor portals, is a defined system with a defined job, and it is the job we are built for.

We say which kind of project yours is before you sign anything, not after the first missed deadline.

At a glance

  • Core focus

    Permit tracking, fleet dispatch, occupancy, vendor portals

  • Engagements

    First builds · legacy rebuilds · integrations · peak scaling

  • Delivery

    Remote from India on Mecca hours, Sunday–Thursday overlap

  • Saudi position

    No local entity. Processor outside the Kingdom under PDPL

Definition


Local Mecca systems provider vs global consultancy vs remote engineering partner

Three ways to staff this, priced and structured differently once the peak-season reality is on the table.

  • Local Mecca systems provider

    Registered in the Kingdom, staffed through the Hajj season, connected to operator associations and the bodies that issue permits. Best when the work needs people physically present during the peak itself.

  • Global consultancy

    Programme-scale delivery with an in-Kingdom presence, usually engaged for a multi-entity transformation with a government body or a large operator group sponsoring it.

  • Remote engineering partner

    A small senior team building a defined system on Mecca hours from outside the Kingdom. No local entity, so the data-transfer question is real and belongs in the contract, not assumed away. Best for a permit-tracking, dispatch or occupancy system you can specify precisely.

We are the third option. Where the honest answer is boots on the ground through Hajj week, we say so before the first estimate rather than after the contract.

Fit


When a remote partner fits a Mecca operator, and when it doesn’t

One line before the list, because it applies regardless of which side you land on: we build the operational software around Hajj and Umrah logistics, and nothing that touches religious content, licensing or ritual guidance, under any engagement model.

  • Hire a remote partner when

    • You can describe the system precisely: a permit tracker, a fleet-dispatch board, an occupancy dashboard, a vendor portal.
    • Your team owns the day-to-day decisions, so a two-and-a-half hour offset costs nothing.
    • The build is a defined system or rebuild, not an open-ended, operator-wide platform.
    • You want the source code and roadmap in your own hands once the season has passed.
    • Your data-protection position is manageable: business data, group records, or personal data your legal team can cover under the standard PDPL safeguards.
  • Hire locally instead when

    • The work touches religious content, ritual guidance or anything requiring a religious licence: outside what we build, at any price, under any arrangement.
    • The system holds PDPL-defined sensitive data, health, biometric or genetic data, criminal records, better kept inside the Kingdom.
    • You are bidding for government-run Hajj or Umrah infrastructure work through Etimad, where in-Kingdom delivery is a condition.
    • You need staff physically present at a lodging site, transport hub or camp during the season itself.
    • Your procurement rules require a Saudi commercial registration from the contracting party.

We turn down the projects in the second list, including the lucrative ones. Reaching into ritual or licensing territory is not a scope we take on at any price, and a remote build where the honest answer is a local systems provider is an expensive way to arrive at the same place.

Next step


Not sure whether to hire locally?

Tell us what the system needs to do and what data it will hold. We will say plainly which side of that line you are on, including when the answer is a systems provider in Mecca.

Comparison


Remote partner vs local systems provider vs global consultancy

Rates are deliberately absent: this is not a rate comparison. Every row below, including the ones we lose, is a real difference. We will run this against your actual scope, quota numbers and data profile.

Remote engineering partner compared with a local Mecca systems provider and a global consultancy, row by row
Local Mecca systems providerGlobal consultancyQalbIT (remote partner)
Physical Mecca presenceYesUsuallyNo
Arabic-first deliveryYesVariesNo · English delivery, Arabic in the product
PDPL roleController or processor, in-KingdomProcessor, usually in-KingdomProcessor outside the Kingdom · safeguards required
Data residencyIn-Kingdom by defaultIn-Kingdom availableIn-Kingdom hosting, remote engineering
ZATCA Fatoora integrationCommonCommonYes
Working-week overlapFullFullSunday–Thursday, 2.5-hour offset from India
Peak-season capacity engineeringVariesVariesBuilt to your quota and occupancy numbers, not assumed
Source code ownershipVariesVariesYours, full repository
Team size on your accountVariesLarge, layeredSmall and senior, founder-accessible
  • 01

    The rows favouring someone else are worth reading properly.

    Two of the rows above point at a local provider on purpose. A remote partner earns the rest of the table, not all of it, and we would rather a Mecca buyer see that here than four months into a build.

  • 02

    Peak-season scale is a design spec, not a postcode.

    What decides whether a system survives Hajj week is whether it was engineered against your real quota and occupancy figures from day one, not whether the team sits in the city.

  • 03

    The time offset barely moves.

    Mecca runs UTC+3, we run UTC+5:30. Two and a half hours, with four of the Saudi Sunday–Thursday week’s five days overlapping ours in real time.

  • 04

    Etimad eligibility settles the question early.

    A government-run pilgrim-infrastructure tender with an in-Kingdom registration requirement decides the vendor before capability does. Ask us early and we will tell you immediately.

What we build


Custom software we build for Mecca operators

Operational systems for the businesses licensed to move, house and supply people at a scale most software is never asked to hold.

  • Permits

    Group and permit tracking systems

    Digital pilgrim-group registers, permit status and quota allocation for licensed operators, replacing the spreadsheet-and-phone-call process most still run today.

  • Fleet

    Transport and fleet dispatch at scale

    Route planning, driver assignment and live dispatch boards built to hold thousands of vehicle movements across a fixed number of days without falling over.

  • Occupancy

    Accommodation-capacity and occupancy management

    Bed, room and camp-plot occupancy tracked in real time across a property portfolio, so a provider knows what is actually full before a guest finds out the hard way.

  • Crowd data

    Queueing and crowd-flow reporting dashboards

    Operational reporting on movement and density for facility operators managing queues at scale, built from sensor and headcount feeds and nothing touching ritual conduct.

  • Vendors

    Vendor and catering-logistics portals

    Ordering, delivery tracking and reconciliation for the caterers, laundry and supply vendors keeping a large camp or property portfolio running through the peak.

  • Backend

    Custom backends and APIs

    Laravel, Node.js and NestJS services, integrations, queues and scheduled jobs, sized to scale up for a fixed peak and back down without a rebuild.

Cost


How much does custom software development cost in Mecca?

Custom software development cost for a Mecca operator is set by scope, integration count and how far the system has to scale for a fixed peak, not by headcount or an hourly rate. A permit tracker built for a modest group size and one built to hold a full Hajj-season quota are different projects before a single screen is designed. We scope before quoting and estimate phase one on a fixed basis.

We do not publish a price range, and would treat any firm that does with some caution.

A quick search turns up figures from $10,000 to $500,000. That range describes nothing in particular: a single-property occupancy tracker and a multi-camp dispatch and vendor platform sized for peak season are not comparable projects.

What we do instead is a scoping call, a load and quota conversation, and a fixed-scope estimate for phase one before you commit past discovery. Below is what actually moves the number, so you can check any quote against it, ours included.

Try the software development cost calculator

What moves the number

  • Scope of phase one

    The single largest driver. One system built to hold your real quota numbers beats three built thinly across the operation.

  • Peak-load engineering

    Designing a system that scales cleanly for a fixed multi-day peak and returns to a fraction of that load the rest of the year is genuine architecture work, priced as such rather than assumed away.

  • Integration count and quality

    A modern REST API with OAuth is straightforward. A permit or licensing-authority interface with no event support needs a middleware and reconciliation layer.

  • ZATCA integration depth

    Reporting simplified invoices is not the same job as clearing standard invoices. Clearance means CSID onboarding, XAdES signing, hash chaining and a failure-handling path.

  • Data protection architecture

    Where pilgrim and staff personal data lives, what crosses the border, and what is tokenised at the boundary. Cheap to design early, expensive to retrofit mid-season.

  • Data migration depth

    Moving current-season masters is routine. Reconciling several seasons of group, occupancy or transport history is a project of its own.

How we work with Mecca operators


A delivery process built around a fixed peak

The 2.5-hour offset is the easy part. The part that matters is a season with a hard start date and a hard end date, and planning the calendar backwards from it.

  1. Discovery and quota mapping

    Walk through how groups, vehicles, beds or vendor orders move through your operation today, and pin down the real numbers, quota, fleet size, property count, the system has to hold at peak.

    Process map, system roadmap, realistic phase-one estimate, written data-transfer position.

    1–2 weeks

  2. Architecture and load design

    Design the data model, screens and integration contracts against your real peak numbers rather than an average. Decide what is hosted in-Kingdom and what never leaves.

    Approved data model, screen designs, integration plan, hosting and residency decision, a stated peak-capacity target.

    2–3 weeks

  3. Build phase one

    Develop in weekly increments, demoing against real group, vehicle or property records rather than sample data. Demos land in your Sunday–Thursday week.

    Working modules validated against real operational scenarios and peak-load tests.

    6–14 weeks, scope-dependent

  4. Migration, load testing and parallel run

    Migrate current records, load-test against your quota numbers ahead of the season, and run the new system alongside the old one until it reconciles.

    Confident go-live before the season starts, with reconciled data and trained users.

    2–4 weeks

  5. Stabilise through the season, then extend

    Support through the peak itself, then tune performance, add reporting and automations once volume returns to its normal range.

    A system proven at your actual peak, not only in a demo.

    Ongoing, month-to-month

The Saudi working week runs Sunday to Thursday. Mecca sits at UTC+3 against our UTC+5:30, a two-and-a-half hour offset, with four of your five working days overlapping ours in real time. The season itself, not the working week, is what the calendar is built around: builds finish and load-test before a Hajj or Ramadan Umrah peak, never during it.

Book a scoping call

Where we fit best


Mecca projects we take on

These are the engagements that work well remotely. The ones that don’t are listed higher up the page.

  • First build

    Replacing spreadsheets with a real permit or group system

    Operators running pilgrim-group registration, permit status or vehicle assignment on spreadsheets and phone calls who need a system that holds up at ten times the normal load. For Hajj and Umrah operator businesses.

  • Modernisation

    Rebuilding a system that could not survive last season

    Old desktop or early web systems that slowed or fell over under peak volume, rebuilt as modern applications engineered to the real numbers this time. For operators whose current system failed under load.

  • Compliance

    ZATCA and PDPL retrofit

    Bringing an existing invoicing or booking system to Fatoora clearance and restructuring where pilgrim and staff personal data sits. Often a Wave 25 notification is what starts the project. For companies with a Wave 25 notification.

  • Peak scale

    Systems built to scale up and back down on schedule

    Occupancy, dispatch and vendor-logistics platforms sized for a fixed multi-day peak and a much smaller baseline the rest of the year, without a redesign each cycle. For operators with a hard annual peak.

Industries


Sectors we build for in Mecca

Operational software is industry-shaped. These are the sectors where the process knowledge transfers.

  • Hajj and Umrah operator services

    Group registration, permit and quota tracking, transport assignment and reporting for the licensed businesses that move and house pilgrims, built strictly as operational software.

  • Hospitality and accommodation

    Multi-property occupancy, booking and rate management for hotels, serviced apartments and camp operators whose demand swings harder across the year than almost any other market we serve.

  • Transport and fleet operations

    Dispatch, route planning and vehicle-utilisation tracking for fleets moving large, time-boxed volumes between fixed points across a short season.

  • Retail, catering and vendor services

    Ordering, delivery tracking and reconciliation for the vendors, caterers and suppliers keeping a large operator or property portfolio provisioned through the peak.

Next step


Your peak season is the reason the off-the-shelf tool doesn’t fit.

That is usually the actual case for a custom build. Describe how the load changes across the year and we will tell you honestly whether it justifies the project.

Saudi compliance


Building software for Mecca: ZATCA, PDPL and data residency

The same two regulations decide this everywhere in the Kingdom. What differs in Mecca is the data behind them: group, permit, driver and guest records moving through systems built for a volume that spikes hard, once a year, on a fixed schedule.

  1. ZATCA e-invoicing (Fatoora)

    ZATCA’s Phase 2 requires a direct connection to the Fatoora platform. Standard B2B and B2G invoices clear before you send them; simplified B2C invoices report afterwards. Every invoice carries UBL 2.1 XML, a UUID, a cryptographic stamp and a QR code. Wave 25, announced 24 July 2026, reaches taxpayers whose VAT-subject revenue passed SAR 187,500 in any of 2022, 2023, 2024 or 2025, with integration due by 1 February 2027. That figure is half of Wave 24’s SAR 375,000 threshold and lines up with the Kingdom’s voluntary VAT registration floor, so it effectively catches almost every registered operator, from a single-property hotel to a multi-camp logistics provider. Penalties for non-compliance run from SAR 5,000 to SAR 50,000. Where it usually breaks: CSID onboarding, XAdES signature validity, and a rejected clearance snapping the previous-invoice-hash chain, which quietly invalidates every invoice issued after it. Sources: ZATCA Wave 25 e-invoicing announcement, zatca.gov.sa · Zakat, Tax and Customs Authority.

    Phase 2 · Wave 25

  2. PDPL and cross-border data

    The Personal Data Protection Law was enacted by Royal Decree M/19, amended by M/148, and has been fully enforceable since 14 September 2024. It reaches beyond the Kingdom’s borders: an organisation abroad processing the personal data of people inside Saudi Arabia is in scope, us included. For a Mecca operator that usually means pilgrim-group records, driver and staff details, and property-guest data sitting inside a permit, dispatch or booking system. Article 29 allows moving that data outside the Kingdom under SDAIA’s approved safeguards, including Saudi Standard Contractual Clauses, with a risk assessment where those apply. Sensitive categories, health, biometric, genetic or criminal-record data, carry tighter limits again. In practice you hold the controller role and we hold the processor role. The transfer needs a documented basis and a contract, never an assumption. Sources: Regulation on Personal Data Transfer Outside the Kingdom, v2.0, August 2024, dgp.sdaia.gov.sa · Saudi Data & AI Authority.

    Royal Decree M/19

  3. Vision 2030 context

    Saudi Arabia’s digital economy has reached roughly SAR 495 billion, about 15% of national GDP, with the ICT market passing SAR 180 billion by 2024. The Kingdom placed first worldwide in the ITU’s 2025 ICT Development Index. Sources: Ministry of Communications and Information Technology · Communications, Space and Technology Commission.

We build compliant output into the system from the start rather than adding a module to resist it afterwards. If a Wave 25 notification is the reason you are reading this, that date is where the plan starts, working backwards.

Working with us


Hiring a vendor outside the Kingdom: the honest version

Every foreign vendor working in Saudi Arabia carries a handful of exposures. We would rather name them here than have you discover them mid-project.

  1. Data transfer

    You hold the controller role. Every transfer of personal data to us needs a lawful basis under Article 29 and documented safeguards, settled once, in the contract, before the build starts.

  2. Sensitive data

    Health, biometric, genetic and criminal-record data carries tighter limits. If your system holds it, plan for in-Kingdom processing whoever writes the code.

  3. Religious content and licensing

    We do not build, advise on or claim any authority over religious content, ritual guidance or anything requiring a religious licence. That line does not move for any engagement model, and we say so before quoting rather than after.

    Scope boundary

  4. Government and permit-authority procurement

    Etimad tenders and some permit-authority contracts require a Saudi commercial registration from the contracting party. We do not have one.

  5. Physical presence

    Nobody from our team walks a lodging site or a dispatch yard on your behalf during the season. A floor rollout or an on-site cutover needs local hands, and we say so before you sign.

  6. Everything else

    Payment gateways, e-invoicing service providers, accounting products, permit and licensing-authority systems, banking APIs, BI tools.

    Integrations

None of that argues against a remote partner. It argues for handling the contract, and the scope boundary above, properly before the estimate rather than after.

Tech stack


Technology we use for Mecca builds

Permit, dispatch and occupancy systems need to survive one enormous week without buckling, then run quietly the rest of the year. We choose proven technology built for that shape, not for a demo.

  • Backend and business logic

    • Laravel (PHP 8.x) for modular business systems with strong audit trails.
    • NestJS (TypeScript) for event-driven dispatch, queueing and high-volume integration flows.
    • Queues and schedulers for peak-season syncs, alerts and report generation.
  • Frontend and usability

    • Next.js and React for fast, keyboard-first operator dashboards under real load.
    • Bilingual Arabic and English interfaces with correct right-to-left layout.
    • Role-based views for dispatch, occupancy and vendor teams working different shifts.
  • Data and integrations

    • PostgreSQL and MySQL with strict constraints, built to hold season-peak transaction volume without degrading.
    • ZATCA Fatoora clearance and reporting APIs.
    • Integrations with permit and licensing-authority systems, payment gateways and accommodation-booking platforms.
  • Security and residency

    • Role- and location-based permissions with full audit logging.
    • In-Kingdom hosting options where residency is required.
    • Automated backups, staged deployments, monitoring and alerting sized for peak-week traffic.

Running an existing booking system, a fleet tool, or spreadsheets-plus-phone-calls today? We can integrate and extend before we replace: the migration path is part of the plan, not an afterthought.

Outcomes


What the project should actually change

Not projections. These are the operational changes the build is meant to produce, and how you would know whether yours did.

What the project should actually change: what changes and how you would measure it
What changesHow you’d measure it
One source of truth across groups, vehicles and propertiesVariance between system records and physical or ledger count
Compliance output is generated, not assembledHours per filing period
Invoices clear ZATCA first timeRejected-clearance rate and hash-chain breaks
The system holds at your real peak, not only in a demoError and latency rate across the season’s busiest days
Approvals are enforced, not rememberedShare of transactions with a complete audit trail
Owners see position without asking anyoneTime from question to answer
  • A note on sourcing

    A note on sourcing

    We do not quote a headline failure rate for software projects. The widely circulated 55–75% figure attributed to Gartner has no traceable primary source, so we leave it out rather than repeat it to make a point. Every number on this page carries its source and date beside it.

Why QalbIT


Why work with us

  1. Eight years building operational software

    120+ engagements delivered across web, mobile and platform work, with 50+ clients. Clutch 5.0, Google 4.9, Upwork Top Rated. Our GCC delivery today runs white-label for a regional agency, and the operational-software discipline behind that work is what we bring to a Mecca operator’s systems.

  2. We say what we are, and what we are not

    No Mecca office, no Saudi entity, no implied presence, and no claim to any special standing on Hajj or Umrah operations beyond the software engineering itself. We would rather lose a deal at the scoping call than have a client assume we speak with a religious authority we do not have.

  3. You own the code

    Full source ownership, documented, in your own repository. No licence, no per-seat fee, no restriction on hiring a different team once the season is over.

  4. Senior team, founder-led

    A small senior team with direct access to the people writing the code. Nobody hands you to an account manager who relays questions to engineers you will never meet.

  5. We’ll tell you to hire locally

    When a Mecca-based systems provider, or a question that has drifted into religious-licensing territory, is genuinely the better answer, we say so on the first call. It costs us a project and saves you a season.

QalbIT did a great job turning my idea into a real product. What I really appreciate is how well they understand my requirements, even when I'm not fully sure how to explain or finalize things. They listen patiently, guide me when I'm stuck, and always try to find the right solution. I really enjoy working with their team and I'm definitely looking forward to continuing our work together in the future.
Kundan Raval, CEO of Hellory Reminder App

FAQs · Custom software development in Mecca


Frequently asked questions from Mecca teams

These are the questions operators, hospitality managers and finance leads actually ask when they weigh a remote partner against a Kingdom-based systems provider.

Talk to the team
No. QalbIT has no office or legal entity anywhere in Saudi Arabia. Delivery runs remotely from Ahmedabad, India, on Mecca working hours. We say this plainly because implying a local presence creates a problem for both of us the first time it is checked.
Yes, with the data-protection position handled properly. Under PDPL you are the controller and we are the processor. Transferring personal data outside the Kingdom is permitted under Article 29 with approved safeguards, including Saudi Standard Contractual Clauses. That is contract work done once, before the build starts.
Yes. Phase 2 requires direct integration with the Fatoora platform: UBL 2.1 XML, UUID, cryptographic stamp and QR code, with standard invoices cleared before sending and simplified invoices reported afterwards.
Wave 25 covers VAT-subject revenue above SAR 187,500 in any of 2022 to 2025, with integration required by 1 February 2027. Treat the notification you received from ZATCA as authoritative for your own date, and confirm your status directly rather than relying on any article, this one included.
Mecca is UTC+3 and we are UTC+5:30: a two and a half hour offset. Your Sunday to Thursday week overlaps ours on four days out of five. Demos and decision calls are scheduled in your hours; Thursday afternoon through Saturday runs on written updates.
Your organisation, in full, in your own repository, once project payments are complete. No licence, no per-seat fee, no restriction on hiring another team afterwards.
We build the business software behind a licence: group and permit tracking, fleet dispatch, occupancy and vendor logistics for licensed operators. We do not build, advise on or claim any authority over religious content, ritual guidance or licensing itself, and we say so before quoting rather than after.
That is the central design question for a Mecca build, not a side consideration. Capacity, queueing and reporting are built against your actual quota and occupancy numbers from day one, and the system is load-tested against your real peak figures ahead of the season, not discovered to be short during it.
Yes. Route planning, driver assignment and live dispatch boards are sized for that shape of load: a short, fixed, extreme peak rather than a steady year-round volume, which is a different engineering problem to solve than most scheduling systems are built for.
Yes. Ordering, delivery tracking and reconciliation for the vendors and caterers behind a large operator’s catering and supply chain is one of the systems we build most often for this market, usually connected to the same occupancy and group data driving the rest of the operation.
Usually, provided the integration is documented. We ask for the integration spec at the scoping call rather than assume familiarity with a specific permit, licensing-authority or payment platform, because a documented API matters more than whether we have touched that exact system before.
Our current GCC delivery is a white-label engagement, so we cannot name the end client. We can share detailed case studies from comparable high-volume booking and scheduling builds in Europe and India, and we would rather tell you that than manufacture a Mecca reference.

Next step


Let’s scope the first system.

Tell us how groups, vehicles, beds or vendor orders move through your operation today. We will map the process, name the system that earns its place first, and give you an honest, phased estimate. If a Mecca-based provider is the better answer, we will say that instead. Typically a reply within 24–48 hours, with questions rather than a brochure.