A bilingual tutoring platform built for Syria, with student, teacher, and admin flows. The public website is live; booking and payment availability are separate release gates.
Finding a suitable private tutor and coordinating lessons through scattered messages leaves students, families, and teachers without a clear shared record of requests and status.
A structured flow can make tutor discovery and requests clearer, provided identity checks, delivery, local operations, and legal readiness are established before public booking is enabled.
The platform includes bilingual interfaces, role-specific student and teacher flows, admin review, request and booking logic, and commission records. These implemented paths should not be read as a claim that public booking or payment is enabled today.
Next.js (Arabic RTL + English, next-intl)
-> Express/Node API
- phone + OTP auth (no passwords)
- teacher verification (PENDING -> VERIFIED/REJECTED/SUSPENDED)
- booking state machine (REQUESTED -> CONFIRMED -> COMPLETED,
or CANCELLED/NO_SHOW with actor tracking both sides)
- commission engine: versioned + snapshotted per booking,
append-only ledger, teacher risk-tier escalation
- review/rating system with a flag-and-moderate pipeline
-> PostgreSQL (Prisma) on Neon; Supabase Storage for media
-> Web deployed on Vercel; Capacitor mobile wrapper not distributed in app stores
Commission is versioned, never mutated. The rate is snapshotted per booking, so a later rate change never silently rewrites historical bookings — the ledger itself is append-only, not a mutable balance field.
Risk-tier escalation actually blocks bookings. A teacher's outstanding debt escalates them through NORMAL to WARNING to RESTRICTED to BLOCKED, and BLOCKED genuinely prevents new bookings — not just a dashboard label.
A real gap was found and fixed during development: originally only teachers could report a student no-show, leaving no way for a student to report that a teacher simply didn't show up. Fixed with a symmetric reporting path for both sides.
Phone/OTP authentication and role checks are implemented. Delivery of OTP messages to a handset requires separate confirmation; an HTTP success alone is insufficient. Admin enrollment is kept outside public registration. Legal and operational release requirements still need owner review.