A checkoutwith a humanin it.
LooksLab takes payment off the site. Rather than treat that as a gap to paper over, the platform was built around it — a staff member verifies the money, and everything of value in the system waits for them to do it.

- Client
- LooksLab
- Scope
- Storefront, accounts, staff console
- Built
- June – August 2026
- Status
- Live in production
- 22
- Console tabs
- 30
- Database tables
- 13
- API modules
- 22
- Build days
01
The spine
Eight steps, and nothing in the codebase is allowed to break them. Every feature added afterwards had to respect the order rather than route around it.
- 01
Customer orders; an invoice is generated and emailed
- 02
They pay externally, by whichever method the store has enabled
- 03
A staff member verifies the payment — the human gate
- 04
Status moves, and the customer is emailed at each move
- 05
Shipments are created and tracking is emailed per parcel
- 06
A carrier API confirms delivery, or a person does
- 07
The order completes itself, and the whole thing is audit-logged
03
What got built
A storefront the staff can rewrite without a deploy, an identity system of its own, and a console with enough in it to run the company from a phone.
- Two catalog lines with per-variant pricing, bulk discount thresholds and stock-aware variant chips
- Pre-orders that ship together or separately, with a configurable split fee
- Accounts with magic-link sign-in, saved addresses, and a wishlist that emails on restock and price drops
- A points programme and a referral scheme, both with admin-set rules and a review queue
- A 22-tab staff console across orders, inventory, growth, content and settings
- Carrier tracking polled every thirty minutes, with orders closing themselves once every parcel lands
- Every customer-facing word — copy, banners, FAQ, email templates, SEO — edited from the admin, not the repo
04
The unglamorous half
Four things were quietly broken in production before I found them, and none of them had raised a complaint. This is the part of shipping that never makes a highlight reel.
- 01Bot protection was inert — the site key had never been set, so checkout had been open the whole time
- 02Customer login never stored its session, so signing in appeared to work and then did not
- 03A first-time save in the admin could overwrite live site copy with the panel’s own defaults
- 04A cart race could write an empty cart to storage over a full one
05
Security, on the record
An audit early in the build found a hidden route that minted owner accounts and kept them out of the accounts list. It was deleted, along with every mechanism that had concealed it.
- Order pricing moved server-side, so totals cannot be edited from a browser
- Database backups taken out of version control — they can hold customer data
- Permissions enforced in the Worker, never by hiding a button
- Every admin change logged with who did it, when, and what changed
Behind the counter
The deskit runs on.


Under the hood
What it ismade of.
- Frontend
- React 19 · Vite 6 · React Router 7
- API
- Cloudflare Workers
- Database
- Cloudflare D1 — 30 tables
- Resend — transactional, campaigns, inbound
- Bot protection
- Cloudflare Turnstile
- Scheduled work
- Worker cron — carriers, rewards, wishlists
Next step
Yours to run.Not to rent.
This one was built around how the business already took money, rather than around what a platform would allow. If yours has a step like that, it is a reason to build rather than a problem to work around. Thirty minutes and we will tell you which you need.
Fig. 01The gate is a personMoney moves when someone confirms it did. Everything else in the system waits for that.
We do the marketing. You stay lazy.
