Client Collaboration Portal for a Custom Travel Agency
Worldwide
We're a custom travel agency looking for someone to build a client collaboration portal (web applicaiton). Today we plan trips in Travel Joy and collaborate with clients over email, phone, and copy-pasted Google Sheets, which leaves no record of what was agreed and no way for clients to respond to what we propose. We need a portal where each itinerary item — hotel, flight, activity, transfer — carries an approval status: the client either approves it or requests a change with a required comment, we're notified, we make the edit, and a client-visible revision log shows what changed. Behind that we need a CRM for clients and trips, an itinerary builder with typed items and a reusable template library, planner-to-client messaging, notifications, and branded PDF output. Two requirements rule out most platforms: 1. no per-user pricing for clients, we may be planning 100+ trips at a time and a group trip can have 50+ travelers who each need a login to submit their own passport and preference details (i.e., we may have 5,000+ people on the portal at once or), and 2. two-axis record permissions enforced server-side, where everyone on a trip sees the shared itinerary but each traveler sees only their own room and flights, never another traveler's. We haven't picked a platform, but Stacker.ai, Noloco, and Softr have major limitations so more than likely a vibe code/no code platform will not work, and CMS’s like Wordpress also cannot render the capabilities we need. We do have a dedicated enterprise architecture resource on our team that tested this but also does not have the bandwidth to fully architect a platform and implement, so we have a full spec ready below covering the data model, permission matrix, and build phases. ⭐Please read full spec attachment to learn more about this project Problem: Our current itinerary tool has no way for clients to give us structured feedback. So when we propose a hotel or a day plan, the response comes back by phone, email, or a copy-pasted spreadsheet. There's no approval status, no record of what changed or why, and no single place either side can look to see where things stand. On a trip with dozens of moving parts, that costs us hours per client and creates real risk of something being missed. What we need: A client-facing portal with: - A CRM: holding client records, trips, travel preferences, and trip history - An itinerary builder: with typed items including lodging, flights, activities, transfers, restaurants, cruises, rail, car rental — each with its own fields, plus a library of reusable blocks our planners can drop into any trip - An approval workflow: where each itinerary item moves through In Progress → Pending Approval → Approved, or gets sent back as Change Requested with a mandatory comment explaining why - A revision log: clients can see, so after we make a change they know exactly what changed - Comments and messaging: between planners and clients, on individual items and generally - Notifications: in-app and by email, with the ability to turn email off per event type - Branded PDF output: of the final itinerary, generated from the portal data These are non-negotiable and they rule out several popular platforms: 1. **No per-user pricing for clients.** A single group trip can have 50+ travelers, each needing their own login to submit passport details and travel preferences. Per-seat pricing for external users doesn't work for us at any tier. 2. **Two-axis record permissions, enforced server-side.** Everyone on a trip sees the shared day-by-day itinerary. But each traveler sees only *their own* room assignment, flights, and personal data — not the other 49 travelers'. This has to be enforced at the data layer, not by hiding elements in the interface. Required experience ● 6+ years building and shipping production web applications end to end ● 3+ years specifically on multi-tenant applications where different users see different subsets of the same data — client portals, SaaS platforms, marketplaces, healthcare or legal software, or similar ● Demonstrated experience designing and implementing authorization models, not just authentication. You've built systems where "which records can this user see" was a hard problem, and you can talk about how you solved it ● Experience handling PII in production — passport data, dates of birth, payment references — including encryption at rest, access logging, and least-privilege design Core technical skills ● Strong backend proficiency in one of: Laravel/PHP, Ruby on Rails, Django/Python, or Node/TypeScript. We're stack-agnostic and will defer to your recommendation, but you should be deeply fluent in whichever you propose rather than learning it on our project ● Relational database design — normalized schema, indexing, migrations. PostgreSQL preferred ● Row-level authorization implemented at the data layer. Postgres RLS, policy objects (Pundit/CanCanCan), Laravel Policies and Gates, Django Guardian, or an equivalent approach you can defend ● Modern frontend: React, Vue, or a server-rendered equivalent (Inertia, Hotwire, Livewire). The interface needs to be genuinely good — planners use it daily and clients judge us by it ● Role-based access control with field-level granularity, not just page-level gating ● Audit logging and change tracking — PaperTrail, django-simple-history, Laravel Auditing, or a custom implementation. We need a client-visible record of what changed on each itinerary item ● REST/webhook integrations: Stripe, JotForm, Kit (ConvertKit) ● Transactional email at production quality — Postmark, SES, or SendGrid, with deliverability configured properly ● Server-side PDF generation from application data with real design fidelity (Puppeteer, Playwright, WeasyPrint, or a rendering service) ● File upload and storage with access control — S3 or equivalent, with signed URLs ● Deployment, environments, and CI/CD. You own staging and production, not just the codebase Nice to have ● Supabase or similar experience, particularly with Postgres Row-Level Security ● Prior work in travel, hospitality, events, or another domain with group bookings and per-participant data ● Experience with document generation templates at scale ● Background in security review or penetration testing ● Comfort with SOC 2 vendor requirements and compliance documentation What we're not looking for ● No-code or low-code implementers. We evaluated Stacker, Noloco, and WordPress and decided against them for this build
- More than 30 hrs/weekHourly
- 3-6 monthsDuration
- ExpertExperience Level
$15.00
-
$50.00
Hourly- Remote Job
- Ongoing projectProject Type
Skills and Expertise
Activity on this job
- Proposals:50+
- Interviewing:0
- Invites sent:0
- Unanswered invites:0
About the client
- United StatesMissouri City3:21 AM
- $33K total spent42 hires, 2 active
- 139 hours
- Tech & ITMid-sized company (10-99 people)
Explore similar jobs on Upwork
How it works
Create your free profileHighlight your skills and experience, show your portfolio, and set your ideal pay rate.
Work the way you wantApply for jobs, create easy-to-by projects, or access exclusive opportunities that come to you.
Get paid securelyFrom contract to payment, we help you work safely and get paid securely.
About Upwork
- 4.9/5(Average rating of clients by professionals)
- G2 2021#1 freelance platform
- 49,000+Signed contract every week
- $2.3BFreelancers earned on Upwork in 2020
Find the best freelance jobs
Growing your career is as easy as creating a free profile and finding work like this that fits your skills.
Trusted by