Platform & realtime

Multi-tenant by design, realtime by default, and built to scale across dynos — with white-label on Enterprise.

Club ownersStaff

Overview

Platform & realtime is the foundation everything else runs on. Strict multi-tenant isolation keeps every club's data separate — no leakage, no cross-venue queries, no shared state. A Socket.IO realtime layer pushes orders, inventory changes, check-ins, KPI updates, and Mo insights to your dashboard the moment they happen. Background jobs handle the work that should not wait for someone to log in — expiry checks, briefings, digests, and alert monitoring.

Under the hood, Helmet, CORS, rate limits, and Redis scaling keep the platform secure and performant across dynos. OpenAPI 3.1 with typed codegen opens the door to integrations. And on Enterprise, white-label branding — logo, colours, domain, receipts, and a branded app — makes the platform yours in members' eyes.

How it works

Strict multi-tenant isolation

  1. Every request is tenant-scoped

    API calls, database queries, and realtime subscriptions all carry a club identifier. The platform enforces isolation at the data layer — not just in the UI — so one club cannot read another's records.

  2. Multi-club owners see separate contexts

    Owners who manage multiple venues switch club context explicitly. Each switch loads that tenant's data only. There is no blended dashboard that accidentally mixes lounge revenue with retail inventory.

  3. Staff permissions reinforce isolation

    Role matrices are per club, and staff access is evaluated against the active tenant. A cashier at Club A has zero visibility into Club B, even if the same person holds a role at both.

Realtime dashboard (Socket.IO)

  1. Orders appear as they are placed

    New orders, status changes, and payment confirmations push to the owner dashboard instantly. Kitchen and counter staff see the same live queue without polling or manual refresh.

  2. Inventory and check-ins update live

    Stock level changes from sales or adjustments, and member check-ins from door scans, appear on the dashboard in realtime. Low-stock thresholds trigger alerts the moment levels cross the line.

  3. KPIs and Mo insights stream in

    Recognised-revenue shifts, proactive Mo insights, and delivery status transitions push over the same Socket.IO connection. Your dashboard is a live operations board, not a snapshot from five minutes ago.

Background jobs

  1. Membership expiry runs on schedule

    A background job checks upcoming and past-due memberships daily, triggers reminders, and surfaces lapsing members on the owner dashboard — even if no one logged in that morning.

  2. Mo briefings and digests dispatch automatically

    Daily and weekly briefings compile and send via Resend and Twilio on the schedule each club configures. Staff digest preferences determine who receives what and when.

  3. Alert monitors run continuously

    Low-stock, stuck-delivery, and revenue anomaly monitors execute on intervals. When a threshold is breached, the alert fires and pushes to the realtime dashboard with a deep link to the source.

Security & scaling

  1. Helmet, CORS, and rate limits by default

    HTTP security headers, cross-origin policies, and per-endpoint rate limiting ship enabled in production. The platform rejects abusive traffic before it reaches your club's data.

  2. Redis scales realtime across dynos

    Socket.IO uses Redis pub/sub so events broadcast consistently whether the platform runs on one server or scales horizontally. Add dynos without breaking live dashboards or session state.

  3. Datadog watches platform health

    API latency, job success rates, error spikes, and infrastructure metrics feed into Datadog observability. Issues are detected and escalated before they become outages your club feels.

OpenAPI & white-label

  1. OpenAPI 3.1 documents every endpoint

    A versioned API spec describes request and response shapes for orders, members, inventory, analytics, and more. Typed codegen generates client libraries so integrations stay in sync with platform changes.

  2. Build custom integrations confidently

    Connect internal tools, reporting pipelines, or third-party services against a documented API. Authentication is tenant-scoped — integrations access only the clubs you authorise.

  3. White-label on Enterprise

    Custom logo, brand colours, domain, receipt templates, and a branded mobile app replace default Join The Club branding. Members interact with your club's identity end to end.

Capabilities

  • Strict multi-tenant isolation — Every query, event, and API call is scoped to a single club. Data never crosses tenants, even for multi-club owners.
  • Realtime dashboard (Socket.IO): orders, inventory, check-ins, KPIs, Mo insights — Live updates push to your dashboard without refresh. Orders, stock changes, member scans, revenue shifts, and Mo insights stream in realtime.
  • Background jobs — expiry, briefings, digests — Scheduled processing for membership expiry, Mo briefings, email and WhatsApp digests, and continuous alert monitoring — reliable even when no one is logged in.
  • Helmet, CORS, rate limits, Redis scaling — Production-grade security headers, cross-origin policies, API rate limiting, and Redis-backed horizontal scaling across dynos.
  • OpenAPI 3.1 + typed codegen — Versioned API documentation with generated client types for building integrations and internal tools against a stable contract.
  • White-label logo, colours, domain, receipts, branded app — Enterprise branding replaces platform defaults so members see your club's identity on every surface.

Operator tips

Frequently asked questions

Common questions about platform & realtime.

Ready to launch your club?

Start a free trial or talk to us about onboarding your members, staff, and inventory.