Skip to content
← Work

Regulated consumer products · D2C

A regulated direct-to-consumer storefront, live and transacting in 45 days

We won the engagement on a commitment competitors would not make — a custom storefront taking live card payments within 45 days, under a 100% uptime guarantee. Both were met.

Period
2019 – 2021 · 18 months
What we delivered
Full platform build, payment and CRM integration, infrastructure and operations
Setting
Full technical ownership after launch

Client and project names are withheld under confidentiality. Sector, scale and outcomes are reported as delivered.

45 days

From zero to live card payments

100%

Uptime across an 18-month contract

~16 months

Owned end to end as the client's only technical supplier

10 plugins

Decoupled, single-responsibility modules

Context

A multinational consumer-goods company needed a direct-to-consumer channel for a regulated product category in a single European market. The category carries statutory age verification requirements and market-restricted distribution rights, so the platform had to enforce hard geographic and age controls — not as a nice-to-have, but as a condition of operating legally.

In vendor selection the client weighed off-the-shelf platforms and hosted services against fully custom development. We won on a specific, aggressive commitment: a live storefront transacting through a payment gateway within 45 days, backed by a 100% uptime guarantee — conditional on our also owning the server infrastructure.

The catalogue covered the device range (5–6 products, 40–50 SKUs with colour variants) and roughly 50 accessories at around 100 SKUs.

Problem

Two pressures pulled against each other. The deadline was fixed and short. And the compliance surface — age verification, market-level access enforcement, regulated-category constraints, later GDPR obligations that surfaced mid-engagement — was the kind of thing that normally takes longer than the whole build.

Approach

Phase 1 — build and launch in 45 days

  • Delivered a pixel-perfect custom theme against the client’s supplied designs, building the entire front end of every commerce-critical page — cart, checkout, profile, order history.
  • Implemented passwordless OTP authentication as a custom plugin: customers signed in by phone number, with no password to manage or leak.
  • Built the payment gateway integration as a dedicated plugin and owned all commerce development end to end.
  • Engineered market-level access enforcement as its own plugin. The client supplied IP ranges that administrators maintained as a whitelist through the admin panel; any request outside those ranges resolved through an IP-to-country geolocation service, and all traffic from outside the licensed market was blocked. Phone-number validation gave a second, independent check at sign-in.
  • Designed the age-verification flow, structured to avoid re-asking customers the platform could already trust: phone sign-in as the first gate, customers already present in the client’s CRM treated as verified upstream, and only previously unknown customers shown a date-of-birth step.
  • Selected the dedicated server platform and installed, configured and tuned the full stack — Nginx, MySQL, Redis and PHP.
  • Directed the client-side mid-level and junior developers across catalogue and blog pages, permissions, SEO and security.

Phase 2 — full technical ownership for ~16 months

After launch the client extended the contract and the team was reduced: a project manager on the client side, and us for everything technical — front end, back end and infrastructure.

  • CRM integration. A custom plugin looked the customer up in Salesforce on phone-number entry, retrieving their record or creating it. Profile data, addresses, loyalty tier, points balance and purchase history flowed from the CRM into the storefront; newly captured addresses and completed orders were pushed back, keeping the CRM as the system of record. Because completed orders flowed into Salesforce, downstream invoicing and fulfilment stayed in the client’s own systems — keeping the storefront deliberately narrow in scope.
  • CRM-driven dynamic pricing. Extended a rule-based pricing engine so CRM-sourced attributes — tier, points balance and related fields — became first-class conditions, exposed in the plugin’s admin panel. Marketing could then define loyalty-based discounts without developer involvement.
  • Campaign management. Marketing uploaded creatives and details; the system placed them into the storefront, activated and deactivated them on a schedule, and targeted them to defined customer segments.
  • Alternative fulfilment. For CRM-known customers, ordering without online payment — delivered to their own address or collected from an authorised dealer. Dealer locations synchronised from the CRM, with only administrator-activated locations selectable.
  • Variation-aware catalogue filtering. Existing filter plugins ignored product variations, so we wrote a filtering engine treating each variation as a first-class filterable entity.
  • Bulk messaging for mass email and SMS campaigns over SendGrid and Twilio.
  • GDPR compliance plugin covering consent, data-handling and data-subject obligations — a requirement that surfaced mid-engagement and had to be met for an EU-market enterprise client.
  • Architected the platform as ten decoupled custom plugins, each owning a single responsibility, deliberately keeping business logic out of the theme so core commerce stayed stable and independently maintainable across theme and platform updates.

Infrastructure and operations

  • A staging environment plus a CI/CD pipeline where every change deployed to staging automatically and emailed both the project manager and client stakeholders a summary of what had changed; on approval, the same pipeline promoted it to production. A global enterprise client got a documented review-and-approval trail without a release manager in the loop.
  • Tag-driven deployments: a commit marker on the test branch released to staging, the same marker on master released to production — an explicit, auditable trigger rather than deploying on every push.
  • Full-stack monitoring — CPU, memory, disk and application logs — as the operational backbone of the uptime guarantee.
  • Automated backups: full server snapshots to S3 on a schedule and automatically both before and after every deployment.
  • All server administration for the duration: OS and service patching, plus ongoing tuning of Nginx, MySQL, Redis and PHP.
  • A single Docker image so developers could run the full stack locally without installing anything.

Outcome

  • Live, transacting custom platform in 45 days, winning the engagement against off-the-shelf alternatives.
  • 100% uptime sustained across the full 18-month engagement, meeting the contractual guarantee the project was won on.
  • Combined mandatory two-sided staging approval with snapshots around every release; production rollbacks were effectively never needed.
  • Ran the platform end to end as the client’s only technical supplier for ~16 months — application, front end, infrastructure, monitoring and release management.
  • Marketing ran CRM-driven loyalty pricing and scheduled, audience-targeted campaigns self-service, removing the developer dependency from day-to-day commercial operations.
  • Served roughly 1,000 transacting customers at about 100 orders a month in a deliberately small, tightly regulated single-country market — where correctness, regulatory compliance and uninterrupted availability, not throughput, were the defining requirements.