Context
Charter software that only collects a date dumps work onto email. Operators need remaining capacity, “call to book” holds, pending confirmation, walk-up booking, and a week board that does not drift to UTC. Guests need a two-minute path. The desk needs the same product in a native shell, not a bookmark.
Architecture
Three principals, one schema. Guests are anonymous and only hit public read/write paths that create pending bookings. Operators authenticate and are constrained to their tenant — tours, departures, and bookings for that company only. Admin oversees platform earnings and operator provisioning (invite-only; no public signup).
Availability is computed, not cached as a guess. A departure’s remaining seats are capacity minus non-cancelled bookings. Some departures are flagged call-to-book and render as phone-only. Repeat generation can project weekday patterns out two years.
Money and messages are side effects of a confirmed booking, not a separate product. Stripe handles the charge. Confirmation email/SMS include waiver and what-to-bring once the operator accepts. The Capacitor apps (bundle com.hawaiitours.booking) load the live Vercel origin — one codebase, two native shells.
Implementation
Public booking with live remainder
Tour grid, date picker (availability horizon two years), seat count, price preview (per-seat × guests + platform fee), confirm. No guest account. Pending until operator confirm.
Tenant-scoped operator OS
Owner vs staff roles. Tour CRUD, single and repeating departures, HST week calendar with booked/capacity on each card. A walk-up guest can be booked from the operator side.
Payments and notifications in-band
Stripe for capture. Resend for email, Twilio for SMS. Failures are logged as skipped/failed rather than silently dropped. Operators do not see another tenant’s PII.
Native shell, same runtime
iOS and Android are Capacitor WebViews pointed at production. Splash and status bar are native; booking logic is not forked.
Non-negotiables
No public operator signup
Accounts are provisioned. The platform is not a marketplace with self-serve companies on day one.
Hawaiʻi time is the schedule
The week view is Sunday–Saturday in HST. UTC leakage would mis-board a morning departure. That is treated as a correctness bug, not a display preference.
