Skip to content

Custom software development · Medina

Custom Software Development Company for Medina

We build reservation and booking platforms, fleet and transport systems, occupancy dashboards and permit records for businesses operating in and around Medina, alongside backend systems for its date-processing and manufacturing trade. We work remotely from Ahmedabad, India, on Saudi hours. There is no QalbIT office in Medina, and no QalbIT entity anywhere in the Kingdom.

The obvious story about Medina is the size of the crowd passing through it every year. The software story is narrower and more useful: the booking, transport, occupancy and permit systems behind the businesses that serve that flow, and the two legal questions any vendor outside the Kingdom has to answer before you hire one.

  • 2018

    Building software since

  • 5.0

    Clutch rating

  • 50+

    Clients served

  • 5.0

    Clutch rating

Get your free estimate

Three quick questions: scope, approach and a price range back within 48 hours. No sales call required first.

What do you need built?
When do you want to start?
Where should we send the estimate?

Answer all three questions above, then send.

NDA-friendly · IP yours from day one

Definition


What a remote software partner actually does for a Medina company

QalbIT builds operational software, booking and reservation platforms, fleet and occupancy systems, CRM and backends, for businesses operating around Medina, as a remote engineering partner rather than a Kingdom-based firm. We build the systems that move people, vehicles and paperwork; we do not build or advise on religious content, ritual guidance or anything doctrinal, and that boundary does not move. The same two constraints apply as everywhere in the Kingdom: ZATCA Phase 2 e-invoicing, reaching almost every VAT-registered business by 1 February 2027 under Wave 25, and PDPL Article 29, governing personal data leaving Saudi Arabia. Delivery is remote from Ahmedabad, India, on Medina working hours.

Medina’s economy looks unusual on paper: a resident population running ordinary businesses, and a visitor population that can multiply the working city several times over for a matter of weeks, then recede almost as fast. Software sized for one crowd breaks under the other.

A firm registered inside the Kingdom can staff a reception desk, walk a hotel floor before a peak, or sit in the transport office when a roster needs revising at short notice. We cannot do any of that. What we can do is build the reservation, occupancy, fleet and permit systems that stand behind that desk, that floor and that roster, and say plainly where a remote build stops being the right tool.

None of that touches what a visit to Medina means to the person making it. That is not a subject we build products around and not one we offer an opinion on: our systems track a booking reference, a vehicle, a room and a permit number, never a rite.

We are that second kind of vendor, and we would rather you read it here than discover it in month two.

At a glance

  • Core focus

    Booking, fleet, occupancy and permit systems, CRM and APIs

  • Engagements

    First builds · legacy rebuilds · integrations · seasonal-scale systems

  • Delivery

    Remote from India on Medina hours, Sunday–Thursday overlap

  • Saudi position

    No local entity. Processor outside the Kingdom under PDPL

Definition


Local Medina operator vs global consultancy vs remote engineering partner

The same three options any Saudi buyer weighs, priced and staffed differently around a season rather than a steady month.

  • Local Medina operator or systems house

    Registered in the Kingdom, close to the booking desk, the transport yard or the packing shed, Arabic-first. Best when the work touches a floor team daily, especially through a peak week.

  • Global consultancy

    Programme-scale delivery with an in-Kingdom presence, usually brought in for a group-wide platform or a multi-entity transformation with a board sponsor.

  • Remote engineering partner

    A small senior team building a defined system on Medina hours from outside the Kingdom. No local entity, so the data-transfer question is real. Best when you already know what the system has to do.

We are the third. Where a Medina operator is genuinely the better fit, for example staffing a reception desk through a peak week, we will say so before you sign anything with us.

Fit


When a remote partner is the right call for a Medina business

A vendor selling into a seasonal city usually argues only the side that gets the contract signed. Here is the version with both.

  • Hire a remote partner when

    • You can describe the system: a reservation platform, a fleet and dispatch tool, an occupancy dashboard, a permit register.
    • Your team can own day-to-day decisions, so a two-and-a-half hour offset costs nothing.
    • The work is a defined build or rebuild, not an open-ended transformation programme.
    • You want the source code and the roadmap in your own hands once it ships.
    • Your data-protection position is manageable under PDPL with the standard safeguards in place.
  • Hire locally instead when

    • The system holds PDPL-defined sensitive data: health, biometric or genetic data, criminal records; keep that in the Kingdom.
    • You are bidding for government, municipal or endowment work through Etimad, where in-Kingdom delivery is a condition.
    • Delivery has to run in Arabic across your whole front-desk and dispatch team, not only at the interface layer.
    • You need people physically present on a hotel floor or in a transport yard during a seasonal cutover.
    • Your procurement rules require a Saudi commercial registration from the contracting party.

We turn down the projects that land in the second list. Building remotely where the honest answer is a Medina-based operator wastes your time and, in the sensitive-data case, creates a legal problem neither of us wants.

Next step


Not sure whether to hire locally?

Tell us what the system needs to do and what data it will hold, guest records included. We will say plainly which side of that line you are on, including when the honest answer is an operator based in Medina.

Comparison


Remote partner vs local operator vs global consultancy

Rates are deliberately absent. This is not a rate comparison, and every row below, including the ones we lose, is a real difference. We will run this against your actual scope and data profile.

Remote engineering partner compared with a local Medina operator and a global consultancy, row by row
Local Medina operatorGlobal consultancyQalbIT (remote partner)
Physical Medina officeYesUsuallyNo
Arabic-first deliveryYesVariesNo · English delivery, Arabic in the product
PDPL roleController or processor, in-KingdomProcessor, usually in-KingdomProcessor outside the Kingdom · safeguards required
Data residencyIn-Kingdom by defaultIn-Kingdom availableIn-Kingdom hosting, remote engineering
ZATCA Fatoora integrationCommonCommonYes
Working-week overlapFullFullSunday–Thursday, 2.5-hour offset from India
Peak-week floor presenceAvailableSometimesNot available · architecture is built peak-ready in advance instead
Source code ownershipVariesVariesYours, full repository
Team size on your accountVariesLarge, layeredSmall and senior, founder-accessible
  • 01

    The rows we lose are still on the table.

    Two or three of the rows above are reasons to hire someone else. We would rather a Medina buyer read that here than discover it a month before a peak week.

  • 02

    A seasonal spike is a specification question, not a location question.

    Whether we have built for your exact peak before matters less than whether the peak is quantified. We ask for last year’s numbers at the scoping call.

  • 03

    The time offset is smaller than it looks.

    Medina runs UTC+3, we run UTC+5:30. Two and a half hours, with the Saudi Sunday–Thursday week overlapping ours on four of five days.

  • 04

    Etimad and endowment eligibility is binary.

    If your buyer is a government body, a municipality or an endowment procuring through Etimad with an in-Kingdom registration requirement, that decides the vendor before quality does. Ask us early.

What we build


Custom software we build for Medina companies

Systems that talk to each other, so a reservation, a vehicle and an invoice do not have to be re-entered three times by three different people.

  • Booking

    Reservation and booking platforms

    Seat, room and slot allocation, group bookings and cancellation rules for licensed tour, transport and accommodation operators, replacing a phone-and-spreadsheet booking desk.

  • Fleet

    Transport and fleet management systems

    Vehicle rosters, driver assignment, trip logging and permit status for operators moving visitors between sites, built to hold up when the schedule changes an hour before departure.

  • Occupancy

    Hotel and accommodation occupancy systems

    Room inventory, rate and channel management and occupancy forecasting for properties that run near empty for months and near capacity for weeks.

  • Permits

    Vendor and permit management

    Licence records, renewal reminders and compliance status for the tour, transport and accommodation operators a season depends on.

  • Trade

    Date and agriculture trade platforms

    Harvest intake, grading, batch tracking and export documentation for Medina’s date farms and processors, replacing a paper ledger only one person can read.

  • Backend

    Custom backends and APIs

    Laravel, Node.js and NestJS services, integrations, queues and scheduled jobs: the layer that makes the rest possible.

Cost


How much does custom software development cost in Medina?

Custom software development cost in Medina is driven by scope, integration count, seasonal-scaling requirements and compliance depth rather than by headcount or an hourly rate. A ZATCA-integrated booking or invoicing layer, a fleet or property-management integration, and a peak-ready architecture are each a separate cost driver. We scope before quoting and estimate phase one on a fixed basis.

We do not publish a price range, and would treat any firm that does with some caution.

Search this and the ranges run from $10,000 to $500,000. That spread tells you nothing useful: a single-property booking system and a multi-site occupancy platform with a fleet module and Fatoora clearance are not remotely the same project.

What we do instead is a scoping call, a process map, and a fixed-scope estimate for phase one before you commit beyond discovery. Below is what actually moves that number, so you can check any quote against it, ours included.

Try the software development cost calculator

What moves the number

  • Scope of phase one

    The largest single driver. One system built properly beats three built thinly. Most first phases cover two connected modules, for example booking plus fleet, or occupancy plus reporting.

  • Integration count and quality

    A modern REST API with OAuth is straightforward. A property-management system or a payment gateway with no event support needs a middleware and reconciliation layer.

  • ZATCA integration depth

    Reporting simplified invoices is not the same job as clearing standard invoices. Clearance means CSID onboarding, XAdES signing, hash chaining and a failure-handling path.

  • Seasonal load and scaling design

    A system that only has to hold steady traffic is a different build from one that has to absorb a demand spike several times its normal size and then scale back down without breaking.

  • Data protection architecture

    Where guest, passenger and driver data lives, what crosses the border, and what gets tokenised at the boundary. Near-free to design at the start, expensive to retrofit.

  • Arabic in the product

    Bilingual interface, right-to-left layout, Arabic-correct booking confirmations and invoice output. Real engineering, frequently underestimated.

How we work with Medina teams


A delivery process built around a 2.5-hour offset

The offset is small. What is not small is the gap between a quiet month and a peak week, and we plan the whole schedule around that gap rather than around the clock difference alone.

  1. Discovery and process mapping

    Walk through how a booking, a vehicle assignment or a room block moves through your business today, who touches it, and where it breaks under load. Identify the highest-pain system for phase one and the data-protection profile for guest, passenger and driver records.

    Process map, system roadmap, realistic phase-one estimate, written data-transfer position.

    1–2 weeks

  2. Architecture and data design

    Design the data model, screens and integration contracts, including any property-management, fleet or payment interfaces. Decide what is hosted in-Kingdom and what never leaves, and size the architecture for peak load rather than an average day.

    Approved data model, screen designs, integration plan, hosting and residency decision.

    2–3 weeks

  3. Build phase one

    Develop in weekly increments, demoing against your real bookings, vehicles or rooms rather than dummy data. Demos land in your Sunday–Thursday week.

    Working modules validated against real operational scenarios.

    6–14 weeks, scope-dependent

  4. Migration, training and parallel run

    Migrate masters and open bookings, train front-desk and dispatch staff, and run the new system alongside the old one until the numbers reconcile, timed to land before the next peak window rather than during it.

    Confident go-live with reconciled data and trained users, ahead of the season that would have made it risky.

    2–4 weeks

  5. Stabilise, extend, roll out next

    Tune performance for peak load, add reports and automations, then build the next system on the roadmap once adoption settles.

    A system that grows with your operation rather than a one-time delivery.

    Ongoing, month-to-month

The Saudi working week runs Sunday to Thursday. Medina is UTC+3 and our team is UTC+5:30: a two-and-a-half hour offset, with four of your five working days fully overlapping ours. Thursday afternoon and Friday–Saturday run on written updates, and any go-live is planned around your calendar of peak weeks rather than a standard one.

Book a scoping call

Where we fit best


Medina projects we take on

These are the engagements that work well remotely. The ones that don’t are listed higher up the page.

  • First build

    Replacing a phone-and-spreadsheet booking desk

    Transport, accommodation and tour operators running reservations, vehicle rosters or room blocks on spreadsheets and phone calls who need a real system built properly the first time. For transport, accommodation and visitor-services operators.

  • Modernisation

    Rebuilding software you have outgrown

    Old desktop or early web systems rebuilt as modern web applications, without losing years of booking or account history or retraining everyone overnight. For companies stuck on unsupported systems.

  • Compliance

    ZATCA and PDPL retrofit

    Bringing an existing system to Fatoora clearance and restructuring where guest, passenger and driver data sits. Often the deadline is what starts the project. For companies with a Wave 25 notification.

  • Seasonal scale

    Systems built to peak hard and stand down after

    Reservation, occupancy and fleet platforms engineered for a handful of high-volume weeks each year, sized to absorb the spike without a rebuild every cycle. For operators with sharply seasonal demand.

Industries


Sectors we build for in Medina

Operational software is industry-shaped. These are the sectors where the process knowledge transfers.

  • Visitor transport and logistics

    Vehicle rosters, driver assignment, permit compliance and trip records across a demand curve that can multiply several times over in a matter of weeks.

  • Hospitality and accommodation

    Occupancy, rate and channel management for properties running from a quiet month to a fully booked one without warning, and back again.

  • Date and agriculture processing

    Harvest intake, batch grading, packing and export documentation for a farming and processing trade that predates the visitor economy and runs alongside it.

  • Retail and small manufacturing

    Multi-branch operations, simplified-invoice reporting to ZATCA, and production tracking for the workshops and small manufacturers supplying the wider region.

Next step


Your process is the reason the off-the-shelf tool doesn’t fit.

That is usually the actual case for a custom build. Describe the process, whether it runs through a booking desk, a transport yard or a packing line, and we will tell you honestly whether it justifies the project.

Saudi compliance


Building software for Medina: ZATCA, PDPL and data residency

The same two regulations decide this everywhere in the Kingdom. What differs in Medina is which system usually raises the question first: a reservation platform holding names and passport numbers, or a fleet system carrying driver and vehicle records.

  1. ZATCA e-invoicing (Fatoora)

    Phase 2 requires direct integration with ZATCA’s Fatoora platform. Standard B2B and B2G invoices clear before you send them; simplified B2C invoices report afterwards. Invoices carry UBL 2.1 XML, a UUID, a cryptographic stamp and a QR code. Wave 25, announced 24 July 2026, covers taxpayers whose VAT-subject revenue exceeded SAR 187,500 in any of 2022 to 2025, with integration required by 1 February 2027, half of Wave 24’s SAR 375,000 threshold and effectively the bottom rung. For an operator in Medina this usually pulls in both the invoicing system and any booking or reservation platform that issues a tax invoice on confirmation, not just one of them. Where integrations fail: CSID onboarding, XAdES signature validity, and the previous-invoice-hash chain breaking after a rejected clearance, which silently invalidates everything downstream. Sources: ZATCA Wave 25 e-invoicing announcement, zatca.gov.sa · Zakat, Tax and Customs Authority.

    Phase 2 · Wave 25

  2. PDPL and cross-border data

    The Personal Data Protection Law, enacted by Royal Decree M/19 and amended by M/148, became fully enforceable on 14 September 2024, and applies extraterritorially: an organisation outside the Kingdom processing personal data of people inside it is in scope, including us. For a Medina operator this most often means guest, passenger and driver records held inside a booking, fleet or property-management system. Article 29 permits transferring that data outside the Kingdom under SDAIA’s approved safeguards, including Saudi Standard Contractual Clauses, with a risk assessment where those apply. In practice you are the controller and we are the processor. The transfer has to be justified, documented and contracted, not assumed. Sources: Regulation on Personal Data Transfer Outside the Kingdom, v2.0, August 2024, dgp.sdaia.gov.sa · Saudi Data & AI Authority.

    Royal Decree M/19

  3. Vision 2030 context

    Saudi Arabia’s digital economy has reached roughly SAR 495 billion, about 15% of national GDP, with the ICT market passing SAR 180 billion by 2024. The Kingdom took first place globally in the ITU’s 2025 ICT Development Index. Sources: Ministry of Communications and Information Technology · Communications, Space and Technology Commission.

We build systems that emit compliant output natively rather than bolting a compliance module onto software that resists it. If a Wave 25 notification is driving your timeline, that date is where we start planning backwards from.

Working with us


Hiring a vendor outside the Kingdom: the honest version

Every foreign vendor selling into Saudi Arabia carries the same four exposures. Here they are, named.

  1. Data transfer

    You are the controller. Every transfer of guest, passenger or driver data to us needs a lawful basis under Article 29 and documented safeguards, agreed once, in the contract, before the build starts.

  2. Sensitive data

    Health, biometric, genetic and criminal-record data carries tighter restrictions. If a booking or medical-transport system you run touches any of it, plan for in-Kingdom processing regardless of who writes the code.

  3. Government and endowment procurement

    Etimad tenders and some municipal or endowment contracts require a Saudi commercial registration from the contracting party. We do not have one.

  4. Physical presence

    Nobody from our team will be on a hotel floor, in a transport yard or at a permit counter during a peak week. Rollouts and floor training around a seasonal cutover need local hands, and we say so before you sign.

  5. Everything else

    Payment gateways, e-invoicing service providers, hotel and property-management systems, fleet and dispatch platforms, banking APIs, BI tools.

    Integrations

None of that is a reason to avoid a remote partner. It is a reason to handle the contract properly before the season starts rather than during it.

Tech stack


Technology we use for Medina builds

Booking, fleet and occupancy systems have to survive a demand spike measured in multiples, not percentages. We choose proven technology that holds under that load and that your future team, internal or external, can still maintain afterwards.

  • Backend and business logic

    • Laravel (PHP 8.x) for modular business systems with strong audit trails.
    • NestJS (TypeScript) for booking, fleet and dispatch flows with heavy real-time updates.
    • Queues and schedulers for reminders, occupancy alerts and report generation.
  • Frontend and usability

    • Next.js and React for fast, keyboard-first data entry at a booking or front desk.
    • Bilingual Arabic and English interfaces with correct right-to-left layout.
    • Role-based dashboards for owners, dispatchers and front-desk teams.
  • Data and integrations

    • PostgreSQL and MySQL with strict constraints for booking and financial integrity.
    • ZATCA Fatoora clearance and reporting APIs.
    • Integrations with property-management systems, fleet platforms and payment gateways.
  • Security and residency

    • Role- and location-based permissions with full audit logging.
    • In-Kingdom hosting options where residency is required.
    • Automated backups, staged deployments, monitoring and alerting, tuned for peak-week load.

Already running a property-management system, a fleet spreadsheet or a paper permit register? We extend and integrate before we replace: the migration path is part of the plan, not an afterthought.

Outcomes


What the project should actually change

Not projections. These are the operational changes the build is meant to produce, and how you would know whether yours did.

What the project should actually change: what changes and how you would measure it
What changesHow you’d measure it
One booking and occupancy record across every channelVariance between system count and physical or ledger count
Compliance output is generated, not assembledHours per filing period
Invoices clear ZATCA first timeRejected-clearance rate and hash-chain breaks
Vehicle and permit records stay current through a peakShare of trips and permits with a complete audit trail
Arabic output is correct without manual fixingDocuments requiring rework before sending
Owners see position without asking anyoneTime from question to answer
  • A note on sourcing

    A note on sourcing

    We don’t quote a headline failure rate for software projects. The widely circulated figures attributing 55–75% failure to Gartner have no traceable primary source, and we won’t repeat them to make a point. Where we cite a number on this page, the source and date are next to it.

Why QalbIT


Why work with us

  1. Eight years building operational software

    120+ engagements delivered across web, mobile and platform work, with 50+ clients. Clutch 5.0, Google 4.9, Upwork Top Rated. We deliver into the GCC today as a white-label engineering partner to a regional agency, and our Saudi-facing work is built on that same operational-software experience.

  2. We say what we are

    No Medina office, no local entity, no implied presence. The compliance section above exists because we would rather lose a deal at the scoping call than at the audit.

  3. You own the code

    Full source ownership, documented, in your repository. No licence, no per-seat fee, no restriction on hiring a different team later.

  4. Senior team, founder-led

    A small senior team with direct access to the people writing the code. You won’t be handed to an account manager who relays questions to engineers you never meet.

  5. We’ll tell you to hire locally

    When a Medina operator or systems house is genuinely the better answer, we say so on the first call. It costs us a project and saves you a year.

QalbIT did a great job turning my idea into a real product. What I really appreciate is how well they understand my requirements, even when I'm not fully sure how to explain or finalize things. They listen patiently, guide me when I'm stuck, and always try to find the right solution. I really enjoy working with their team and I'm definitely looking forward to continuing our work together in the future.
Kundan Raval, CEO of Hellory Reminder App

FAQs · Custom software development in Medina


Frequently asked questions from Medina teams

These are the questions transport, hospitality and operations leads actually ask when they compare a remote partner with a local operator.

Talk to the team
No. QalbIT has no office or legal entity anywhere in Saudi Arabia. Delivery runs remotely from Ahmedabad, India, on Medina working hours. We say this plainly because implying a local presence creates a problem for both of us the first time it is checked.
Yes, with the data-protection position handled properly. Under PDPL you are the controller and we are the processor. Transferring personal data outside the Kingdom is permitted under Article 29 with approved safeguards, including Saudi Standard Contractual Clauses. That is contract work done once, before the build starts.
Yes. Phase 2 requires direct integration with the Fatoora platform: UBL 2.1 XML, UUID, cryptographic stamp and QR code, with standard invoices cleared before sending and simplified invoices reported afterwards.
Wave 25 covers VAT-subject revenue above SAR 187,500 in any of 2022 to 2025, with integration required by 1 February 2027. Treat the notification you received from ZATCA as authoritative for your own date, and confirm your status directly rather than relying on any article, this one included.
Medina is UTC+3 and we are UTC+5:30: a two and a half hour offset. Your Sunday to Thursday week overlaps ours on four days out of five. Demos and decision calls are scheduled in your hours; Thursday afternoon through Saturday runs on written updates.
Your organisation, in full, in your own repository, once project payments are complete. No licence, no per-seat fee, no restriction on hiring another team afterwards.
Booking and reservation platforms, fleet and dispatch tools, occupancy tracking and permit systems: the operational software behind a visitor-services or transport business. Group bookings, cancellation rules and driver assignment are the kind of detail we design around, not an afterthought. We do not build or advise on religious content or ritual guidance, and we say so plainly if asked.
That is the case we design for, not the exception. Vehicle rosters, driver assignment and trip logging are built to absorb a late change without the whole day’s schedule breaking, because in transport and visitor-services operations that call comes in more often than a calm rollout plan assumes.
Yes. Medina’s economy is not only visitor-services and transport: we also build backend systems, workflow tools and CRM for its date-trade and manufacturing businesses. The starting questions are the same either way: what spreadsheet or phone call is the system replacing, and what does the first release need to do on day one.
We size the architecture for your highest week, not your average one. A booking or occupancy system that is over-built for its quiet months costs more to run and maintain all year for capacity you use a handful of times, so the peak numbers get established at the discovery stage, before anything is estimated.
Yes. Booking confirmations, permit documents and reporting can be fully bilingual with correct right-to-left layout and Arabic sorting. Project delivery itself, calls, documentation, written updates, runs in English. If your stakeholder group needs Arabic-language delivery throughout, a local systems house is the better fit and we will say so.
Our current GCC delivery is a white-label engagement, so we cannot name the end client in that sector. We can share detailed case studies from comparable booking and scheduling builds in Europe and India, and we would rather tell you that than manufacture a Medina reference.

Next step


Let’s scope the first system.

Tell us how a booking, a vehicle or a shipment of dates moves through your business today. We will map the process, name the system that earns its place first, and give you an honest, phased estimate. If a Medina operator is the better answer, we will say that instead. Typically a reply within 24–48 hours, with questions rather than a brochure.