Overview
CM Pro is designed for apartments and resident associations, clubs, schools, cooperatives, charities, religious organizations, professional associations, gyms and other groups that collect recurring dues or pledges.
Owners and authorized staff can organize contributors, define collection goals, record offline and online payments, monitor pending amounts, manage expenses and generate receipts and reports. The product supports monthly, yearly, installment, event and pledge-based collection models.
Core capabilities
Typical collection workflow
- Create the organization account and complete email verification.
- Add or import contributors and create a monthly, yearly, installment, event or pledge goal.
- Subscribe contributors and set expected amounts.
- Record an offline collection or issue an online payment link.
- Let CM Pro update paid and pending totals and create the receipt.
- Review expenses, ledgers, dashboard summaries and exports.
Architecture
| Layer | Technology | Responsibility |
|---|---|---|
| Web frontend | React, TypeScript, Vite and Tailwind CSS | Owner and staff dashboard, public payment pages and administration interfaces |
| Mobile frontend | Capacitor-based web application | Android demonstration application and mobile collection workflows |
| Backend | Node.js and Express | Authentication, business rules, integrations, payment callbacks and scheduled maintenance |
| Database | Supabase PostgreSQL | Accounts, collections, goals, expenses, payment links, integrations and operational records |
| Resend HTTP API | Transactional messages and email OTP delivery |
Integrations
CM Pro contains payment integrations for Razorpay, Stripe and PayPal. All three payment flows have been seller-tested in sandbox environments. The buyer must reconnect and retest them in buyer-owned accounts before production launch.
| Provider | Webhook path | Current status |
|---|---|---|
| Razorpay | /api/auth/webhook/razorpay | Sandbox tested |
| Stripe | /api/auth/webhook/stripe | Sandbox tested |
| PayPal | /api/auth/webhook/paypal | Sandbox tested |
Email OTP communication is performed server-side through Resend. Provider keys, signing secrets and webhook identifiers are never required in the browser application.
Deployment and buyer setup
The current demonstration uses free-tier Render, Supabase and Resend services. The buyer will create new provider accounts, purchase a new domain and decide whether paid plans are required for its expected traffic and reliability needs.
Deployment sequence
- Create a buyer-owned Supabase project and apply the supplied ordered schema migrations.
- Deploy the Express backend with buyer-owned Supabase, authentication, encryption and provider secrets.
- Deploy the frontend and set its API base URL to the buyer's backend.
- Configure payment webhook URLs using the buyer's backend hostname and the documented webhook paths.
- Verify a buyer-owned email sending domain and update the transactional sender address.
- Load synthetic test data and complete acceptance testing before production use.
The supplied migration and synthetic seed were successfully exercised in a new Supabase project. The backend connected through Render and the populated demonstration account authenticated successfully.
Security and privacy
- The browser and mobile clients use the authenticated Express API rather than unrestricted direct table access.
- The buyer migration enables row-level security and retains database access for the server-side service role.
- Gateway credentials are encrypted before database storage.
- Payment webhook signatures are verified before payment events are processed.
- Authentication routes include rate limiting, OTP controls and password hashing.
- Account export and deletion routes provide a foundation for privacy operations.
Terms of Service and Privacy Policy are available on the product website. The buyer is responsible for legal review and for adapting these policies to its identity, deployment and operating jurisdictions.
Verification summary
- Frontend type-check completed successfully.
- 17 frontend automated tests passed.
- 53 backend automated tests passed.
- Web and mobile production builds completed successfully.
- All three project dependency audits reported zero known vulnerabilities at the time of review.
- Fresh Supabase restoration, synthetic seed, Render connection and authenticated dashboard login succeeded.
- Razorpay, Stripe and PayPal sandbox payment flows were seller-tested.
- The included Android APK was tested on a physical phone and is supplied as a demonstration build, not a store-ready release.
Acquisition scope
The acquisition is structured as a code and product-asset sale. It includes the web frontend, backend, mobile frontend source, Android demonstration APK, ordered database materials, synthetic seed, product documentation, original product-specific design materials and the seller's transferable rights in the CM Pro product identity.
It excludes seller domains, production provider accounts, real customer data, customer contracts, app-store accounts, release-signing credentials, unrelated seller trade names and any unverified registered-trademark claim. The product is recently developed and pre-revenue, with zero verified MRR, ARR and paying customers.
Transition support
The sale includes 90 calendar days of remote technical assistance after closing, capped at 30 hours in each 30-day period. The target initial response time is one to two business days.
Product and acquisition enquiries: hameed0473@gmail.com