Custom software development · Mecca
Custom Software Development Company for Mecca
We build group and permit tracking, fleet dispatch, occupancy and vendor-logistics systems for the licensed operators and businesses serving Mecca’s pilgrim economy, delivered remotely from Ahmedabad, India, on Saudi hours. QalbIT holds no office and no legal entity anywhere in the Kingdom, and this page sets out exactly what that changes.
It also sets out what we never touch: religious content, ritual guidance, religious licensing or doctrinal matters sit outside every engagement we take on, at any size, for any client. What follows covers the two legal questions that decide whether you can hire us at all: ZATCA e-invoicing and PDPL cross-border data.
2018
Building software since
5.0
Clutch rating
50+
Clients served
5.0
Clutch rating
Get your free estimate
Three quick questions: scope, approach and a price range back within 48 hours. No sales call required first.
Definition
What a remote software partner actually builds for a Mecca operator
QalbIT builds operational software, group and permit tracking, transport dispatch, accommodation-capacity and vendor systems, for licensed businesses serving Mecca’s pilgrim economy, as a remote engineering partner rather than a Kingdom-based firm. We do not build, advise on or claim any authority over religious content, ritual guidance or religious licensing: our work stops at the business system a licensed operator runs behind it. The same two national rules apply as anywhere in the Kingdom: ZATCA Phase 2 e-invoicing, whose Wave 25 threshold of SAR 187,500 reaches almost every VAT-registered business by 1 February 2027, and PDPL Article 29, governing personal data that leaves Saudi Arabia. Delivery runs from Ahmedabad, India, on Mecca working hours.
Mecca does not run on one steady economic rhythm. A short annual peak, the days of Hajj, carries volumes few operations anywhere are built to absorb, set by a government-managed quota no operator can expand on its own. The rest of the year moves differently: Umrah traffic that never fully stops but never spikes the same way either. Software built for one of those shapes rarely survives the other.
A systems provider registered inside the Kingdom knows this rhythm from the inside. It staffs up in Mecca through the peak, contracts in Arabic, and can be reached from a nearby office the moment a screen goes dark during Hajj week. A remote partner cannot offer that. What it can offer is a system engineered around the underlying scale problem: capacity that grows by an order of magnitude for a fixed window, then shrinks back without leaving infrastructure nobody wants to keep paying for the rest of the year.
That trade is not automatically the right one. It stops being right the moment the job needs a person walking a lodging site alongside your staff in the weeks before the season opens. Everything short of that, group and permit tracking, fleet dispatch, occupancy dashboards, vendor portals, is a defined system with a defined job, and it is the job we are built for.
We say which kind of project yours is before you sign anything, not after the first missed deadline.
At a glance
Core focus
Permit tracking, fleet dispatch, occupancy, vendor portals
Engagements
First builds · legacy rebuilds · integrations · peak scaling
Delivery
Remote from India on Mecca hours, Sunday–Thursday overlap
Saudi position
No local entity. Processor outside the Kingdom under PDPL
Definition
Local Mecca systems provider vs global consultancy vs remote engineering partner
Three ways to staff this, priced and structured differently once the peak-season reality is on the table.
Local Mecca systems provider
Registered in the Kingdom, staffed through the Hajj season, connected to operator associations and the bodies that issue permits. Best when the work needs people physically present during the peak itself.
Global consultancy
Programme-scale delivery with an in-Kingdom presence, usually engaged for a multi-entity transformation with a government body or a large operator group sponsoring it.
Remote engineering partner
A small senior team building a defined system on Mecca hours from outside the Kingdom. No local entity, so the data-transfer question is real and belongs in the contract, not assumed away. Best for a permit-tracking, dispatch or occupancy system you can specify precisely.
We are the third option. Where the honest answer is boots on the ground through Hajj week, we say so before the first estimate rather than after the contract.
Fit
When a remote partner fits a Mecca operator, and when it doesn’t
One line before the list, because it applies regardless of which side you land on: we build the operational software around Hajj and Umrah logistics, and nothing that touches religious content, licensing or ritual guidance, under any engagement model.
Hire a remote partner when
- You can describe the system precisely: a permit tracker, a fleet-dispatch board, an occupancy dashboard, a vendor portal.
- Your team owns the day-to-day decisions, so a two-and-a-half hour offset costs nothing.
- The build is a defined system or rebuild, not an open-ended, operator-wide platform.
- You want the source code and roadmap in your own hands once the season has passed.
- Your data-protection position is manageable: business data, group records, or personal data your legal team can cover under the standard PDPL safeguards.
Hire locally instead when
- The work touches religious content, ritual guidance or anything requiring a religious licence: outside what we build, at any price, under any arrangement.
- The system holds PDPL-defined sensitive data, health, biometric or genetic data, criminal records, better kept inside the Kingdom.
- You are bidding for government-run Hajj or Umrah infrastructure work through Etimad, where in-Kingdom delivery is a condition.
- You need staff physically present at a lodging site, transport hub or camp during the season itself.
- Your procurement rules require a Saudi commercial registration from the contracting party.
We turn down the projects in the second list, including the lucrative ones. Reaching into ritual or licensing territory is not a scope we take on at any price, and a remote build where the honest answer is a local systems provider is an expensive way to arrive at the same place.
Next step
Not sure whether to hire locally?
Tell us what the system needs to do and what data it will hold. We will say plainly which side of that line you are on, including when the answer is a systems provider in Mecca.
Comparison
Remote partner vs local systems provider vs global consultancy
Rates are deliberately absent: this is not a rate comparison. Every row below, including the ones we lose, is a real difference. We will run this against your actual scope, quota numbers and data profile.
| Local Mecca systems provider | Global consultancy | QalbIT (remote partner) | |
|---|---|---|---|
| Physical Mecca presence | Yes | Usually | No |
| Arabic-first delivery | Yes | Varies | No · English delivery, Arabic in the product |
| PDPL role | Controller or processor, in-Kingdom | Processor, usually in-Kingdom | Processor outside the Kingdom · safeguards required |
| Data residency | In-Kingdom by default | In-Kingdom available | In-Kingdom hosting, remote engineering |
| ZATCA Fatoora integration | Common | Common | Yes |
| Working-week overlap | Full | Full | Sunday–Thursday, 2.5-hour offset from India |
| Peak-season capacity engineering | Varies | Varies | Built to your quota and occupancy numbers, not assumed |
| Source code ownership | Varies | Varies | Yours, full repository |
| Team size on your account | Varies | Large, layered | Small and senior, founder-accessible |
01
The rows favouring someone else are worth reading properly.
Two of the rows above point at a local provider on purpose. A remote partner earns the rest of the table, not all of it, and we would rather a Mecca buyer see that here than four months into a build.
02
Peak-season scale is a design spec, not a postcode.
What decides whether a system survives Hajj week is whether it was engineered against your real quota and occupancy figures from day one, not whether the team sits in the city.
03
The time offset barely moves.
Mecca runs UTC+3, we run UTC+5:30. Two and a half hours, with four of the Saudi Sunday–Thursday week’s five days overlapping ours in real time.
04
Etimad eligibility settles the question early.
A government-run pilgrim-infrastructure tender with an in-Kingdom registration requirement decides the vendor before capability does. Ask us early and we will tell you immediately.
What we build
Custom software we build for Mecca operators
Operational systems for the businesses licensed to move, house and supply people at a scale most software is never asked to hold.
Permits
Group and permit tracking systems
Digital pilgrim-group registers, permit status and quota allocation for licensed operators, replacing the spreadsheet-and-phone-call process most still run today.
Fleet
Transport and fleet dispatch at scale
Route planning, driver assignment and live dispatch boards built to hold thousands of vehicle movements across a fixed number of days without falling over.
Occupancy
Accommodation-capacity and occupancy management
Bed, room and camp-plot occupancy tracked in real time across a property portfolio, so a provider knows what is actually full before a guest finds out the hard way.
Crowd data
Queueing and crowd-flow reporting dashboards
Operational reporting on movement and density for facility operators managing queues at scale, built from sensor and headcount feeds and nothing touching ritual conduct.
Vendors
Vendor and catering-logistics portals
Ordering, delivery tracking and reconciliation for the caterers, laundry and supply vendors keeping a large camp or property portfolio running through the peak.
Backend
Custom backends and APIs
Laravel, Node.js and NestJS services, integrations, queues and scheduled jobs, sized to scale up for a fixed peak and back down without a rebuild.
Cost
How much does custom software development cost in Mecca?
Custom software development cost for a Mecca operator is set by scope, integration count and how far the system has to scale for a fixed peak, not by headcount or an hourly rate. A permit tracker built for a modest group size and one built to hold a full Hajj-season quota are different projects before a single screen is designed. We scope before quoting and estimate phase one on a fixed basis.
We do not publish a price range, and would treat any firm that does with some caution.
A quick search turns up figures from $10,000 to $500,000. That range describes nothing in particular: a single-property occupancy tracker and a multi-camp dispatch and vendor platform sized for peak season are not comparable projects.
What we do instead is a scoping call, a load and quota conversation, and a fixed-scope estimate for phase one before you commit past discovery. Below is what actually moves the number, so you can check any quote against it, ours included.
Try the software development cost calculatorWhat moves the number
Scope of phase one
The single largest driver. One system built to hold your real quota numbers beats three built thinly across the operation.
Peak-load engineering
Designing a system that scales cleanly for a fixed multi-day peak and returns to a fraction of that load the rest of the year is genuine architecture work, priced as such rather than assumed away.
Integration count and quality
A modern REST API with OAuth is straightforward. A permit or licensing-authority interface with no event support needs a middleware and reconciliation layer.
ZATCA integration depth
Reporting simplified invoices is not the same job as clearing standard invoices. Clearance means CSID onboarding, XAdES signing, hash chaining and a failure-handling path.
Data protection architecture
Where pilgrim and staff personal data lives, what crosses the border, and what is tokenised at the boundary. Cheap to design early, expensive to retrofit mid-season.
Data migration depth
Moving current-season masters is routine. Reconciling several seasons of group, occupancy or transport history is a project of its own.
How we work with Mecca operators
A delivery process built around a fixed peak
The 2.5-hour offset is the easy part. The part that matters is a season with a hard start date and a hard end date, and planning the calendar backwards from it.
Discovery and quota mapping
Walk through how groups, vehicles, beds or vendor orders move through your operation today, and pin down the real numbers, quota, fleet size, property count, the system has to hold at peak.
Process map, system roadmap, realistic phase-one estimate, written data-transfer position.
1–2 weeks
Architecture and load design
Design the data model, screens and integration contracts against your real peak numbers rather than an average. Decide what is hosted in-Kingdom and what never leaves.
Approved data model, screen designs, integration plan, hosting and residency decision, a stated peak-capacity target.
2–3 weeks
Build phase one
Develop in weekly increments, demoing against real group, vehicle or property records rather than sample data. Demos land in your Sunday–Thursday week.
Working modules validated against real operational scenarios and peak-load tests.
6–14 weeks, scope-dependent
Migration, load testing and parallel run
Migrate current records, load-test against your quota numbers ahead of the season, and run the new system alongside the old one until it reconciles.
Confident go-live before the season starts, with reconciled data and trained users.
2–4 weeks
Stabilise through the season, then extend
Support through the peak itself, then tune performance, add reporting and automations once volume returns to its normal range.
A system proven at your actual peak, not only in a demo.
Ongoing, month-to-month
The Saudi working week runs Sunday to Thursday. Mecca sits at UTC+3 against our UTC+5:30, a two-and-a-half hour offset, with four of your five working days overlapping ours in real time. The season itself, not the working week, is what the calendar is built around: builds finish and load-test before a Hajj or Ramadan Umrah peak, never during it.
Book a scoping callWhere we fit best
Mecca projects we take on
These are the engagements that work well remotely. The ones that don’t are listed higher up the page.
First build
Replacing spreadsheets with a real permit or group system
Operators running pilgrim-group registration, permit status or vehicle assignment on spreadsheets and phone calls who need a system that holds up at ten times the normal load. For Hajj and Umrah operator businesses.
Modernisation
Rebuilding a system that could not survive last season
Old desktop or early web systems that slowed or fell over under peak volume, rebuilt as modern applications engineered to the real numbers this time. For operators whose current system failed under load.
Compliance
ZATCA and PDPL retrofit
Bringing an existing invoicing or booking system to Fatoora clearance and restructuring where pilgrim and staff personal data sits. Often a Wave 25 notification is what starts the project. For companies with a Wave 25 notification.
Peak scale
Systems built to scale up and back down on schedule
Occupancy, dispatch and vendor-logistics platforms sized for a fixed multi-day peak and a much smaller baseline the rest of the year, without a redesign each cycle. For operators with a hard annual peak.
Industries
Sectors we build for in Mecca
Operational software is industry-shaped. These are the sectors where the process knowledge transfers.
Hajj and Umrah operator services
Group registration, permit and quota tracking, transport assignment and reporting for the licensed businesses that move and house pilgrims, built strictly as operational software.
Hospitality and accommodation
Multi-property occupancy, booking and rate management for hotels, serviced apartments and camp operators whose demand swings harder across the year than almost any other market we serve.
Transport and fleet operations
Dispatch, route planning and vehicle-utilisation tracking for fleets moving large, time-boxed volumes between fixed points across a short season.
Retail, catering and vendor services
Ordering, delivery tracking and reconciliation for the vendors, caterers and suppliers keeping a large operator or property portfolio provisioned through the peak.
Next step
Your peak season is the reason the off-the-shelf tool doesn’t fit.
That is usually the actual case for a custom build. Describe how the load changes across the year and we will tell you honestly whether it justifies the project.
Saudi compliance
Building software for Mecca: ZATCA, PDPL and data residency
The same two regulations decide this everywhere in the Kingdom. What differs in Mecca is the data behind them: group, permit, driver and guest records moving through systems built for a volume that spikes hard, once a year, on a fixed schedule.
ZATCA e-invoicing (Fatoora)
ZATCA’s Phase 2 requires a direct connection to the Fatoora platform. Standard B2B and B2G invoices clear before you send them; simplified B2C invoices report afterwards. Every invoice carries UBL 2.1 XML, a UUID, a cryptographic stamp and a QR code. Wave 25, announced 24 July 2026, reaches taxpayers whose VAT-subject revenue passed SAR 187,500 in any of 2022, 2023, 2024 or 2025, with integration due by 1 February 2027. That figure is half of Wave 24’s SAR 375,000 threshold and lines up with the Kingdom’s voluntary VAT registration floor, so it effectively catches almost every registered operator, from a single-property hotel to a multi-camp logistics provider. Penalties for non-compliance run from SAR 5,000 to SAR 50,000. Where it usually breaks: CSID onboarding, XAdES signature validity, and a rejected clearance snapping the previous-invoice-hash chain, which quietly invalidates every invoice issued after it. Sources: ZATCA Wave 25 e-invoicing announcement, zatca.gov.sa · Zakat, Tax and Customs Authority.
Phase 2 · Wave 25
PDPL and cross-border data
The Personal Data Protection Law was enacted by Royal Decree M/19, amended by M/148, and has been fully enforceable since 14 September 2024. It reaches beyond the Kingdom’s borders: an organisation abroad processing the personal data of people inside Saudi Arabia is in scope, us included. For a Mecca operator that usually means pilgrim-group records, driver and staff details, and property-guest data sitting inside a permit, dispatch or booking system. Article 29 allows moving that data outside the Kingdom under SDAIA’s approved safeguards, including Saudi Standard Contractual Clauses, with a risk assessment where those apply. Sensitive categories, health, biometric, genetic or criminal-record data, carry tighter limits again. In practice you hold the controller role and we hold the processor role. The transfer needs a documented basis and a contract, never an assumption. Sources: Regulation on Personal Data Transfer Outside the Kingdom, v2.0, August 2024, dgp.sdaia.gov.sa · Saudi Data & AI Authority.
Royal Decree M/19
Vision 2030 context
Saudi Arabia’s digital economy has reached roughly SAR 495 billion, about 15% of national GDP, with the ICT market passing SAR 180 billion by 2024. The Kingdom placed first worldwide in the ITU’s 2025 ICT Development Index. Sources: Ministry of Communications and Information Technology · Communications, Space and Technology Commission.
We build compliant output into the system from the start rather than adding a module to resist it afterwards. If a Wave 25 notification is the reason you are reading this, that date is where the plan starts, working backwards.
Working with us
Hiring a vendor outside the Kingdom: the honest version
Every foreign vendor working in Saudi Arabia carries a handful of exposures. We would rather name them here than have you discover them mid-project.
Data transfer
You hold the controller role. Every transfer of personal data to us needs a lawful basis under Article 29 and documented safeguards, settled once, in the contract, before the build starts.
Sensitive data
Health, biometric, genetic and criminal-record data carries tighter limits. If your system holds it, plan for in-Kingdom processing whoever writes the code.
Religious content and licensing
We do not build, advise on or claim any authority over religious content, ritual guidance or anything requiring a religious licence. That line does not move for any engagement model, and we say so before quoting rather than after.
Scope boundary
Government and permit-authority procurement
Etimad tenders and some permit-authority contracts require a Saudi commercial registration from the contracting party. We do not have one.
Physical presence
Nobody from our team walks a lodging site or a dispatch yard on your behalf during the season. A floor rollout or an on-site cutover needs local hands, and we say so before you sign.
Everything else
Payment gateways, e-invoicing service providers, accounting products, permit and licensing-authority systems, banking APIs, BI tools.
Integrations
None of that argues against a remote partner. It argues for handling the contract, and the scope boundary above, properly before the estimate rather than after.
Tech stack
Technology we use for Mecca builds
Permit, dispatch and occupancy systems need to survive one enormous week without buckling, then run quietly the rest of the year. We choose proven technology built for that shape, not for a demo.
Backend and business logic
- Laravel (PHP 8.x) for modular business systems with strong audit trails.
- NestJS (TypeScript) for event-driven dispatch, queueing and high-volume integration flows.
- Queues and schedulers for peak-season syncs, alerts and report generation.
Frontend and usability
- Next.js and React for fast, keyboard-first operator dashboards under real load.
- Bilingual Arabic and English interfaces with correct right-to-left layout.
- Role-based views for dispatch, occupancy and vendor teams working different shifts.
Data and integrations
- PostgreSQL and MySQL with strict constraints, built to hold season-peak transaction volume without degrading.
- ZATCA Fatoora clearance and reporting APIs.
- Integrations with permit and licensing-authority systems, payment gateways and accommodation-booking platforms.
Security and residency
- Role- and location-based permissions with full audit logging.
- In-Kingdom hosting options where residency is required.
- Automated backups, staged deployments, monitoring and alerting sized for peak-week traffic.
Running an existing booking system, a fleet tool, or spreadsheets-plus-phone-calls today? We can integrate and extend before we replace: the migration path is part of the plan, not an afterthought.
Outcomes
What the project should actually change
Not projections. These are the operational changes the build is meant to produce, and how you would know whether yours did.
| What changes | How you’d measure it |
|---|---|
| One source of truth across groups, vehicles and properties | Variance between system records and physical or ledger count |
| Compliance output is generated, not assembled | Hours per filing period |
| Invoices clear ZATCA first time | Rejected-clearance rate and hash-chain breaks |
| The system holds at your real peak, not only in a demo | Error and latency rate across the season’s busiest days |
| Approvals are enforced, not remembered | Share of transactions with a complete audit trail |
| Owners see position without asking anyone | Time from question to answer |
A note on sourcing
A note on sourcing
We do not quote a headline failure rate for software projects. The widely circulated 55–75% figure attributed to Gartner has no traceable primary source, so we leave it out rather than repeat it to make a point. Every number on this page carries its source and date beside it.
Why QalbIT
Why work with us
Eight years building operational software
120+ engagements delivered across web, mobile and platform work, with 50+ clients. Clutch 5.0, Google 4.9, Upwork Top Rated. Our GCC delivery today runs white-label for a regional agency, and the operational-software discipline behind that work is what we bring to a Mecca operator’s systems.
We say what we are, and what we are not
No Mecca office, no Saudi entity, no implied presence, and no claim to any special standing on Hajj or Umrah operations beyond the software engineering itself. We would rather lose a deal at the scoping call than have a client assume we speak with a religious authority we do not have.
You own the code
Full source ownership, documented, in your own repository. No licence, no per-seat fee, no restriction on hiring a different team once the season is over.
Senior team, founder-led
A small senior team with direct access to the people writing the code. Nobody hands you to an account manager who relays questions to engineers you will never meet.
We’ll tell you to hire locally
When a Mecca-based systems provider, or a question that has drifted into religious-licensing territory, is genuinely the better answer, we say so on the first call. It costs us a project and saves you a season.
QalbIT did a great job turning my idea into a real product. What I really appreciate is how well they understand my requirements, even when I'm not fully sure how to explain or finalize things. They listen patiently, guide me when I'm stuck, and always try to find the right solution. I really enjoy working with their team and I'm definitely looking forward to continuing our work together in the future.
FAQs · Custom software development in Mecca
Frequently asked questions from Mecca teams
These are the questions operators, hospitality managers and finance leads actually ask when they weigh a remote partner against a Kingdom-based systems provider.
Talk to the teamNext step
Let’s scope the first system.
Tell us how groups, vehicles, beds or vendor orders move through your operation today. We will map the process, name the system that earns its place first, and give you an honest, phased estimate. If a Mecca-based provider is the better answer, we will say that instead. Typically a reply within 24–48 hours, with questions rather than a brochure.