Business & Operations

Washly

Source code included

Full-stack laundry & dry-cleaning platform: admin panel, REST API, customer & driver apps for door-to-door service

Built by Max code Updated 6 Oct 2026 290,971 lines of code

Open live demo Built withClaude Code

Why Washly

What makes it better
than the alternatives

  1. 01

    Single-tenant architecture

    One installation serves one laundry business with full data isolation and no multi-tenancy overhead

  2. 02

    Ownership guards on every API endpoint

    Customers and drivers can only read and change their own records, enforced by ApiOwnershipFilter

  3. 03

    Role/page permission matrix

    39 Admin pages with granular read/save/update/delete rights per staff role, checked by AdminPageAccessFilter

  4. 04

    Hosted payment pages with Apple Pay

    Mastercard Payment Gateway Services integration, signed payment tickets (JWT, 30 min), saved cards and wallet top-up

  5. 05

    Comprehensive audit trail

    Every foreign key has an index, cascade deletes only for owned rows, soft deletes for business data, no dynamic SQL

Customer App (Flutter)

  • Sign in with OTP by SMS or email (no password)
  • Service catalogue: wash & fold
  • clean & press
  • dry cleaning
  • home care
  • shoes & bags with per-item prices
  • Order with collection/delivery time slots
  • address book with map pin
  • driver instructions
  • Promo codes
  • coupons with wallet cashback
  • wallet balance and top-up
  • Card payment and Apple Pay through hosted payment page
  • Live order status
  • proof-of-collection and proof-of-delivery photos
  • invoices (PDF)
  • Push notifications (Firebase)
  • support tickets
  • FAQ

Driver App (Flutter)

  • Jobs for today: collections and deliveries assigned to the driver
  • Status updates (collected
  • delivered
  • attempt failed with reason)
  • Proof photos with bag
  • hanger and package counts
  • Navigation to customer's address (Google Maps)
  • Push notifications for new assignments

Admin Panel (ASP.NET Core MVC)

  • Dashboard with order and customer statistics (stored procedure DashBoardStatistics)
  • Orders: list
  • search
  • edit
  • invoice (PDF)
  • receipt
  • assign drivers
  • bulk item upload from Excel
  • Service catalogue: categories
  • groups
  • items
  • bags
  • promo codes
  • coupons
  • Drivers: list
  • create
  • schedule
  • performance reports
  • Customers: list
  • details
  • transaction history
  • wallet top-up
  • Corporate accounts (Businesses): employees
  • orders
  • invoices
  • Areas
  • delivery charges
  • time slots
  • unavailable days
  • Staff users with role-based page access (39 pages
  • read/save/update/delete per role)
  • Reports: revenue
  • sales
  • customer
  • driver
  • payment (Excel export with ClosedXML)
  • Push notifications to customers and drivers
  • Settings: onboarding screens
  • terms & conditions
  • FAQ
  • landing page HTML

REST API (62 endpoints)

  • Public: catalogue (areas
  • bags
  • items
  • service categories
  • time slots)
  • onboarding screens
  • FAQ
  • Sign-in: OTP request and verify (SMS/email)
  • JWT token issue (30 days)
  • Orders: place
  • list
  • details
  • cancel
  • rate
  • proof photos
  • Payments: saved cards
  • Apple Pay
  • wallet top-up
  • hosted payment page ticket issue
  • User: profile
  • address book
  • wallet balance
  • transactions
  • Driver: assigned jobs
  • status update
  • proof upload
  • schedule
  • Business employee: login
  • items
  • place order
  • Ownership guards: every userId
  • customerId
  • driverId
  • orderId checked against caller's identity

Payment Integration

  • Mastercard Payment Gateway Services (API v71
  • Apple Pay v100)
  • Hosted payment pages with signed tickets (JWT
  • 30 min
  • one user)
  • Saved cards (tokenization
  • last 4 digits
  • brand
  • expiry)
  • Apple Pay (merchant id in 3 files: Info.plist
  • Runner.entitlements
  • apple_pay_config.json)
  • Wallet top-up and cashback from coupons
  • Refunds (PaymentGateWayService.RefundsAndCards.cs)
  • Payment reports with Excel export

Database (SQL Server)

  • 62 tables
  • 38 foreign keys
  • 151 indexes (62 primary + 89 others)
  • Every foreign key column has an index (verified by query in database/README.md)
  • Cascade deletes only for owned rows (order logs
  • payments
  • proof photos
  • time slots
  • role permissions)
  • Soft deletes for business data (Status = 2)
  • no hard deletes
  • 10 stored procedures for reports and lists (DashBoardStatistics
  • GetOrdersByFilter
  • GetRevenueReport
  • GetSalesReport
  • GetUsers
  • SearchCustomers
  • etc.)
  • No dynamic SQL: EF Core LINQ for single-entity work
  • Dapper with named parameters for lists
  • ORDER BY from fixed dictionary (SqlSort.cs)
  • PBKDF2 password hashes with check constraint (CK_Users_Password_IsHash)
  • One EF Core migration (InitialCreate)
  • schema.sql matches it

Security & Access Control

  • Admin panel: cookie sign-in (staff roles only)
  • 8-hour session with sliding expiration
  • Mobile API: JWT bearer tokens (30 days)
  • issued after OTP verification
  • OTP: 4 digits
  • 5 minutes expiry
  • 5 max attempts
  • demo codes for testing
  • Roles: Super Admin
  • Admin
  • Driver
  • Customer
  • Business Employee (AppRoles.cs)
  • AdminPageAccessFilter: 39 pages with read/save/update/delete rights per role
  • ApiOwnershipFilter: customers and drivers can only access their own records (userId
  • orderId checked)
  • OwnershipGuard: service methods verify caller's identity before data access
  • Rate limiting: 10 sign-in attempts per minute per client address
  • PBKDF2 password hashing (PasswordService.cs)
  • app users sign in by OTP and have NULL password

Notifications & Communication

  • Firebase Cloud Messaging for push notifications (customer and driver apps)
  • SMS gateway integration (configurable
  • disabled by default
  • Sms:Enabled in appsettings)
  • Email (SMTP
  • configurable
  • Smtp:Enabled
  • templates in Areas/Admin/Views/Email/)
  • Push notification screens in admin panel (CustomerPushNotification
  • DriverPushNotification)
  • Order status change notifications (OrderService.cs)
  • Support tickets (UserReportsAndHelp)

Reports & Analytics

  • Dashboard statistics: orders
  • customers
  • revenue (stored procedure DashBoardStatistics)
  • Revenue report: date range
  • area
  • service category
  • Excel export (GetRevenueReport)
  • Sales report: date range
  • customer
  • driver
  • Excel export (GetSalesReport)
  • Customer report: orders
  • spending
  • last order date (GetUsers)
  • Driver report: collections
  • deliveries
  • performance
  • Payment report: transactions
  • gateway
  • wallet
  • Excel export
  • Order report: combined report with filters (OrderReport/Index.cshtml)
  • Excel export with ClosedXML (ClosedXML 0.105.1)

Configuration & Deployment

  • Docker Compose: web (ASP.NET Core)
  • db (SQL Server 2019)
  • init-db.sh runs schema.sql and seed.sql
  • Environment variables: JWT key
  • MSSQL password
  • site URL
  • OTP log codes (.env.example)
  • appsettings.json: JWT
  • OTP
  • SMS
  • SMTP
  • payment gateway
  • PDF
  • branding
  • CORS
  • Flutter build-time config: API_BASE_URL
  • GOOGLE_MAPS_API_KEY
  • SUPPORT_WHATSAPP
  • SUPPORT_EMAIL (--dart-define)
  • Firebase setup: google-services.json (Android)
  • GoogleService-Info.plist (iOS) for both apps
  • Release signing: key.properties (Android)
  • Xcode team (iOS)
  • Launcher icons: flutter_launcher_icons.yaml
  • source images in assets/

Quality report

Manually reviewed

90/ 100

Automated audit score

The automated audit flagged a blocking check · 4 open warnings — listed after a manual review

◷ 4 open warnings

Listed after manual review.
Audit run: 4 Oct 2026
Reviewed by Vibe96 staff, Dubai.

Security92
Code structure72
Docs & completeness100
Dependency health95
Build & deploy92

What to know before you buy

4 non-blocking findings shown publicly: . The seller has been notified; fixes ship in the next version.

Versions & updates

1.0.0
First release6 Oct 2026✓ Reviewed & audited

No updates yet. New versions appear here with a changelog.
Buyers receive updates free for 1 year.

Quality report

What you get

  • </>Full source codeThe complete audited source, delivered as a download from your account. No obfuscation.
  • ▤DocumentationSetup guide, architecture notes, CLAUDE.md and AGENTS.md.
  • ↻One year of updatesEvery new version the builder publishes, free for 12 months.
  • ♧30 days of supportInstallation and defect support through Vibe96 tickets.
$400Single-site licence Details