Case study · NDA — details on request
Telegram commerce platform with installment checkout
An online store that lives inside Telegram — catalogue, installment checkout, SMS sign-in, payments, an operator bot and a full back office — in production for a consumer-electronics retailer.
- Client
- Consumer-electronics retailer (Uzbekistan)
- Role
- Architect & lead engineer — backend, frontend, bot, infrastructure
- Timeline
- Since April 2026 · in production
- Stack
- PythonFastAPIPostgreSQLSQLAlchemyaiogramReactTypeScriptReact NativeDockernginx
Problem
The retailer sold phones and electronics on installment plans through a chat bot and phone calls. Orders, customer data and installment applications lived in messages and spreadsheets; managers had no queue, no history and no view of where customers dropped off.
They needed a real store inside Telegram, where their customers already are — sign-in, catalogue, installment checkout and a back office — without putting at risk the personal data an installment application requires.
Approach & architecture
- Started from a written specification and an architecture document with rejected alternatives and milestones M-1…M-7; each milestone was closed against an acceptance matrix of end-to-end scenarios.
- One Python codebase, three processes: a FastAPI API, an aiogram bot for customers and operators, and PostgreSQL. The Mini App and the admin panel are static React apps behind nginx; a React Native app reuses the same API.
- Security designed in rather than bolted on: SMS one-time codes with lockouts and daily caps, Telegram initData HMAC verification, national ID numbers encrypted at rest, and a written security review for the client's IT department.
- A back office covering products, orders with assignment and event history, CRM, an SMS dashboard, referrals and UTM attribution, delivery zones on real geo-boundaries, and an AI shopping assistant with abuse controls.
Result
- In production and actively developed: 580+ commits since April 2026, MVP milestones closed, post-MVP features shipping continuously.
- 106 documented API endpoints over 43 tables and 64 versioned migrations.
- Funnel, search, web-vitals and CSP telemetry is stored alongside the data, so product decisions are made on evidence.
What made it robust
- About 1,000 backend tests plus 60 frontend test files; CI runs linting, pytest against a real PostgreSQL and vitest on every push.
- A gatekeeping workflow for fixes with contract tests, and a ledger of every fix and feature.
- Runbooks for deploys, backups and migrations; nightly backups and a production health check.
Have a similar problem?
Tell me about it — I'll reply with an honest view of scope, approach and what a first milestone could look like.