Retail operations software development that keeps one stock number honest

Storefront and checkout, order routing and available to promise, store and dark store picking apps, and the ERP, POS and e-invoicing integration underneath. Built for retailers in Oman and the wider Gulf, and for brands selling into India, where ZATCA, Fawtara, PINT AE, DPDP and the RBI authentication rules change the order flow rather than just the paperwork.

  • Al Amri Express, Oman
  • Stylebank, B2B apparel
  • ZATCA and Fawtara aware
  • $40 to $100 per hour
See the short version

Get Your Free Consultation & We'll Reach Out Promptly!

By submitting this form, I authorize Zyneto to collect and process my personal data in accordance with theZyneto Privacy Policy.

We respond to all inquiries within 1 hour.

Trusted by
Global Industry Leaders

Al Amri Express
Cheer Sagar
MRO Supply
BankSathi
DoraDori
Kroolo
StyleBank
Hire Right
Cintas
Up in the Air
Famepilot
Swedishness
Corrib Coil
iCare Heal
TWAM
NDC: National Distribution Company Oman
Moneteo
Algora
Numerology
G4Girl

The short version

The six numbers a buyer wants before booking a call, answered before you scroll. Most retail software development here begins as omnichannel inventory software, because the stock number is the thing every channel argues about. They are: Typical integration set, Phase one timeline, Rate band, Phase one range, with the arithmetic, Stack we actually use and Our commitment.

Typical integration set

01

Four to nine systems on a normal build: ERP or accounting, POS, WMS or 3PL, PIM, payment gateway, an accredited e-invoicing service provider, a carrier or aggregator, and a marketplace channel manager.

Phase one timeline

02

10 to 16 weeks to a launchable slice, with a mid October to mid January freeze written into the contract. Retail's calendar does not move because a sprint slipped.

Rate band

03

$40 to $100 per hour by role. $40 to $55 for front end, CMS and content operations. $75 to $100 for integration architecture, payments and compliance engineering. Mixed teams blend to $60 to $70.

Phase one range, with the arithmetic

04

Lean slice: 850 build hours plus 170 QA at 20 percent plus 60 DevOps equals 1,080 hours. At $60 that is about $65,000. Full slice: 1,300 build plus 325 QA at 25 percent plus 120 DevOps equals 1,745 hours. At $70 that is about $122,000.

Stack we actually use

05

React and Next.js, React Native, Laravel, Python with Django, MySQL, Elasticsearch, Redis, Celery, AWS, websockets for live tracking, Sentry for error tracking, and WordPress or WooCommerce where that is genuinely the right answer.

Our commitment

06

No fixed price before discovery. Any figure quoted before the integration inventory exists is fiction. Two things we are not: an accredited e-invoicing Service Provider in the UAE, Oman or Saudi Arabia, and a payment institution. We integrate to accredited providers.

Audience

Who this is for

Six company shapes, and the one system each is usually missing. Not a fit: if you want a template storefront with no back office integration, a platform partner will be faster and cheaper, and we will say so on the first call.

01

Gulf retail group, ERP anchored

SAP, Oracle Retail or LS Central on Business Central already owns price, stock and customer master, and you want the storefront and order routing changed without anyone touching the nightly batch.

02

Saudi merchant on Salla or Zid

You have outgrown the template and need custom partner apps written against the platform APIs, with mada routing and ZATCA clearance already handled underneath you.

03

India D2C on Shopify or Woo

You have hit the three option variant ceiling, you are paying for return to origin on cash on delivery orders, and the April 2026 RBI authentication rules land on your card not present flow.

04

Apparel brand or garment manufacturer

Your product is style, then style and colour, then style, colour and size, with a PLM behind it and a cost structure that changes every season. No generic platform models that shape.

05

Grocery and quick commerce operator

Dark stores or store picked delivery, where out of stock handling and substitution logic decide your app rating more than any screen does.

06

B2B wholesaler or brand owner

Reps, contract price lists, quantity breaks, EDI and punchout sessions, and a stock figure that is really two numbers and a date.

Find your operation

Six operations wearing the same word. What breaks is different, so what we build is different. Each operation below breaks differently, and they are: Multi store omnichannel, D2C brand, Marketplace seller, B2B wholesale and distribution, Grocery, perishables and quick commerce and Multi vendor marketplace operator.

01 · Your operation

Multi store omnichannel

What breaks

Phantom inventory ruins click and collect pick success. Orders route to a store that is short staffed or already closing. Price changes reach the web before the POS, so the shelf label and the till disagree. Associates get blamed for cancellations the routing engine caused.

What we build

Distributed order routing with sourcing rules you can read, ATP with per node safety buffers, a store fulfilment app for pick, pack and handoff on a handheld, cycle count and RFID tooling, and endless aisle.

Where commerce systems earn their keep

The stages an order moves through, and what we build at each one The arc is: Catalogue and enrichment, Inventory position, Order capture, Allocation and sourcing, Fulfilment and returns and Settlement and margin. Each one is a place a system either holds the fact or loses it.

01Catalogue and enrichment02Inventory position03Order capture04Allocation and sourcing05Fulfilment and returns06Settlement and margin
Two band commerce map covering catalogue, inventory and order capture, then allocation, fulfilment and settlement.

Systems we connect to, and the arithmetic underneath

A retail build is mostly an integration project wearing a product costume. Here is the estate we expect to meet, and the inventory mathematics that decides whether any of it holds at peak. The groups are: Commerce platforms, Order, inventory and warehouse, POS and store systems, Product data, search and content, Payments and schemes and Channels, carriers and after sales.

Commerce platforms

Salesforce Commerce Cloud, Adobe Commerce 2.4.7 to 2.4.9, SAP Commerce Cloud, commercetools, Shopify Plus, VTEX, Medusa, Saleor, Odoo, WooCommerce, and in Saudi Arabia, Salla and Zid.

Order, inventory and warehouse

Manhattan Active Omni, Fluent Commerce, IBM Sterling OMS, Blue Yonder, Kibo, Deposco, Cin7, Linnworks. Across India: Unicommerce, Increff, Vinculum, Ginesys, EasyEcom, ClickPost and Shiprocket.

POS and store systems

LS Central on Dynamics 365 Business Central, Cegid Retail, Oracle Xstore, Oracle MICROS, Aptos, Shopify POS, Lightspeed, Foodics, Rewaa, Ginesys POS, GoFrugal, TallyPrime.

Product data, search and content

Akeneo, Pimcore, Salsify, inriver, Plytix, Stibo STEP. Bynder and Cloudinary for assets. Algolia, Constructor, Bloomreach, Elasticsearch and OpenSearch, Typesense for search. Contentful, Sanity, Storyblok, Strapi and Contentstack for content.

Payments and schemes

Network International, Amazon Payment Services, Checkout.com, Tap Payments, PayTabs, HyperPay, Moyasar, Geidea, MyFatoorah, Thawani, Amwal, Razorpay, PayU, Cashfree, Juspay. Schemes that decide your checkout shape: mada, KNET, BENEFIT, Jaywan, UPI and UPI AutoPay, Apple Pay. Buy now pay later through Tabby and Tamara.

Channels, carriers and after sales

noon, Namshi, Amazon.ae and Amazon.sa, Ounass, Talabat, Amazon.in, Flipkart, Myntra, Ajio and Meesho. Aramex, SMSA, Naqel, Barq, iMile, Shipa and Asyad Express. Talon.One, Capillary, Loop Returns, Narvar and AfterShip.

The ATP formula, written down

Availability to promise is computed per node and per channel: on hand minus reserved minus safety buffer minus allocated out. Inbound purchase order quantity is added only inside a stated promise window, and only where backorder is permitted. The safety buffer is per channel and per node, never global, because a marketplace cancellation does not carry the same penalty as one on your own site. If nobody has written that line down and agreed who owns each term, you do not have an inventory design. You have a number on a page.

The reservation lifecycle

Add to cart takes a soft reserve with a time to live. Payment authorisation promotes it to a hard reserve, and an authorisation that succeeds after the TTL expired needs an explicit compensating action rather than an exception in a log. Abandonment releases the reserve, and that release must be idempotent because the sweeper and the user can both fire it. Fulfilment converts the hard reserve to allocated out and then to a decrement, where double decrement on webhook redelivery is the single most common oversell cause. Cancellation restocks to sellable or to quarantine, and restocking a damaged return to sellable is a finance problem before it is an inventory one.

The event rules

Webhooks arrive out of order and more than once. That is normal, not a vendor defect. Every inventory mutation carries an idempotency key and a monotonic version, and the write is a compare and set against that version rather than a blind overwrite. Last write wins is correct for absolute snapshots and wrong for deltas, and mixing the two in one handler is how a stock figure drifts for six weeks before anyone notices. Verify signatures with HMAC-SHA256 and a replay window, and put failures in a dead letter queue with a replay procedure an on call engineer can follow at two in the morning.

The variant grid

Style carries marketing copy, imagery and season code. Style and colour carries colourway assets and the per channel listing. Style, colour and size carries GTIN, on hand, country of origin, fibre composition and care instructions. Most platforms model two of those three levels well. Size plus colour plus fit plus length is four options and it does not fit a three option ceiling. Wholesale also ships ratio packs, a prepack such as 2-2-2-1 across S, M, L and XL, which is a different unit of measure to retail eaches and an expensive bug when mapped as though it were one.

Units, money and identity

OMR has three decimal places, and any integer minor unit assumption built around two decimals corrupts totals, refunds and reconciliation quietly. VAT inclusive display pricing is mandatory in Saudi Arabia and the UAE while storage is usually exclusive, so rounding has to be defined at exactly one layer and enforced there. Gulf addresses often have no postcode, phone number is identity in this region rather than email, and Arabic bidirectional text breaks PDF rendering and thermal label output at print time rather than in your test suite.

OMS against ERP

The ERP owns cost, price master and financial stock. The OMS owns the promise: ATP by node and channel, routing, splits and allocation. Confusing the two produces an ERP customisation project nobody scoped or budgeted.

PIM against ERP

PIM holds style level marketing content, Arabic attributes, imagery and per channel mapping. ERP holds the size and colour grid and the cost versions per season. Apparel programmes break when one of them is asked to be both.

Gateway against orchestration

Tap, PayTabs, HyperPay and Razorpay are gateways. Orchestration sits above several gateways for routing, retries and tokenised one click. You need orchestration once mada, KNET, BENEFIT and Jaywan routing plus buy now pay later all have to coexist in one checkout.

Not sure whether your stock number is a promise or a guess?

Send us the list of systems that own price, stock, customer and invoice. We will tell you where the oversell is coming from before you commit to anything.

Standards and compliance

Five standards carry almost every buyer and partner questionnaire, so they get a row each. Everything after them is jurisdiction, which decides the build but only in the markets you actually sell into, so it sits in one row and the FAQ goes deeper on the ones that change your order flow. We hold none of these ourselves. We build to the controls and hand you the evidence.

ISO/IEC 27001:2022

The information security standard, 93 Annex A controls in 4 themes, and the one Gulf and Indian buyers weight most heavily. The transition from the 2013 version closed 31 October 2025, so a 2013 certificate is now void, which is worth checking on your platform and 3PL vendors as well as on yourself.

SOC 1 and SOC 2

SOC 2 covers security and availability and is the default ask from US partners and marketplaces. SOC 1 covers controls feeding your customers' financial reporting, which is the one that appears once you are handling settlement, marketplace payouts or consignment stock on someone else's books.

GDPR and UK GDPR

Applies on the basis of your EU and UK shoppers, not where you are incorporated. Article 30 records, Article 33 breach notice inside 72 hours, data subject requests inside a month, standard contractual clauses for transfers out, and consent handling that survives contact with a marketing stack running server-side events.

PCI DSS v4.0.1

Future dated requirements have been mandatory since 31 March 2025. Requirement 6.4.3 script inventory, authorisation and integrity checks and requirement 11.6.1 tamper detection both reach the payment page even where you use provider hosted fields, so SAQ A reduces your scope rather than removing it.

European Accessibility Act

Applying since 28 June 2025 to e-commerce serving EU consumers regardless of where you are based. Conformity is presumed through EN 301 549, which incorporates WCAG 2.1 AA, and it reaches checkout and account pages rather than stopping at the marketing site.

Regional rules, by where you sell

Oman: PDPL with the transition closed 5 February 2026, Fawtara e-invoicing on Peppol PINT OM where B2C invoices carry a QR and must reach the provider within 24 hours, and a MoCIIP licence with Maroof verification rendered in your footer. Saudi Arabia: PDPL under SDAIA with no adequacy list, and ZATCA Fatoora Phase 2, where Wave 25 drops the threshold to SAR 187,500 with integration by 1 February 2027. UAE: PINT AE through an accredited service provider, appointed by 30 October 2026 above AED 50m. GCC-wide: Arabic labelling and G-Mark, which makes Arabic a first class PIM field. India: DPDP, RBI authentication from 1 April 2026, GST e-invoicing, the Legal Metrology country of origin filter from 1 July 2026, and the CCPA dark patterns list. The FAQ takes the ones that change the order flow.

Our work in this sector

Five builds and one client statement. We would rather describe real things than show a wall of logos.

Oman

Al Amri Express

Grocery and daily essentials delivery across iOS and Android. Product search and filtering, one tap reordering, and live order tracking over websockets.

  • React Native
  • Laravel
  • Elasticsearch
  • MySQL
  • AWS

Oman

Al Amri Express Partner

The operations app behind the storefront. Role separated access across admin, packer and delivery, with picking, packing and ready for dispatch states, so the floor sees a work queue rather than an admin panel.

  • React Native
  • Laravel
  • MySQL
  • AWS
  • Push Notifications

India

G4Girl

Women's fashion e-commerce. The founder's published review on Clutch reports a fivefold sales increase, less manual work in daily operations, and delivery inside four months. That is the client's account of their own business, taken from their published review, not a Zyneto performance figure.

  • WordPress
  • PHP
  • MySQL
  • AWS
  • Sentry

India

Stylebank

A B2B apparel catalogue and replenishment platform, integrating EasyEcom so that a single catalogue and stock position reaches Myntra, Nykaa, Flipkart, Amazon Vendor Central Dropship and Ajio.

  • Django
  • MySQL
  • Redis
  • Celery
  • BigQuery
  • OpenRouter

India

DoraDori

A garment ERP built on FastAPI and PostgreSQL, integrated with Zoho and the client's internal CRM, publishing the item summary and fabric valuation reads that the apparel catalogue consumes.

  • FastAPI
  • Python
  • PostgreSQL
  • Zoho
  • Internal CRM

India

Cheersagar

Garment accounting and reporting, with Zoho on one side and the client's internal CRM on the other, covering job work movement, GST and stock valuation.

  • FastAPI
  • Python
  • PostgreSQL
  • Zoho
  • Internal CRM

What goes wrong

Ten failure modes we have hit or inherited. Naming them is more useful than a list of reasons to choose us. The opening three are: Inventory is never defined, Go live scheduled into peak and Promotions treated as configuration. Each is written plainly enough that you can check whether yours is already happening.

01

Inventory is never defined

One availability number ships and ATP was never specified. Write the formula into the spec, set per channel and per node buffers, give reservations a TTL and a compensating action, and publish oversell rate as a measured service level objective.

02

Go live scheduled into peak

A three week slip lands on Black Friday or the festive season, and there is no way to move either. Launch in the trough and put a mid October to mid January freeze in the contract.

03

Promotions treated as configuration

Stacking, exclusions, buy one get one, tiered thresholds, gift cards and loyalty burn interact combinatorially, and finance finds the margin leak in month three. Run a promotions matrix workshop, then put 80 to 120 golden basket scenarios in CI.

04

Product data not ready

Orphaned variants, missing attributes and no image standard, all discovered during user acceptance testing. Gate the build on a data readiness report, run enrichment in parallel, and name a taxonomy owner on the client side.

05

SEO equity destroyed at replatform

URL patterns change, redirects are partial, structured data quietly disappears. Build the redirect map from live server logs, check canonical, schema and pagination parity, and make Search Console monitoring a named workstream with an owner.

06

Big bang cutover with no rollback

The whole estate moves on one night and there is no way back if the opening stock is wrong. Use the strangler pattern, run two weeks of read only dual run on inventory and orders, cut over in cohorts by region or store, and write the reverse cutover with named trigger conditions.

07

The ERP is the real project and it is out of scope

The storefront is the visible half; the ERP work underneath it is the half nobody budgeted. Write contract first integration specs, put idempotency keys and retry queues on every mutation, and name the ERP owner in the RACI before kick off rather than after the first failure.

08

Store and picker experience designed at a desk

Then used one handed on a rugged scanner, with gloves, in a chiller, on bad Wi-Fi. Shadow a shift before wireframing, test on the actual device, and build offline first with queued sync.

09

Returns scoped as phase two

Refund timing, disposition and return fraud are financial controls, not a nice to have screen. Model RMA, disposition, restock to sellable and refund triggers in phase one.

10

Payments, tax and compliance underestimated

3DS, local wallets, partial capture, capture on ship, marketplace VAT and PCI scope. Get a payment and tax matrix per market signed by finance, use provider hosted fields so you stay in SAQ A, and run a tax engine instead of hand coded rate tables.

Build, buy, or buy the core and build the edge

The honest answer is usually the third one, and sometimes the answer is that you should not hire us for this part. The calls are: Payment acceptance and card data, E-invoicing transmission, UAE and Oman, Tax calculation across markets, Commerce engine and checkout, Search and merchandising, ATP, order routing and allocation and Store and dark store picking apps.

ComponentOur recommendationOur honest verdict
Payment acceptance and card dataBuyProvider hosted fields keep you in SAQ A and keep the card number out of your database entirely.
E-invoicing transmission, UAE and OmanBuyOnly an accredited Service Provider may transmit. We integrate to one. We do not transmit.
Tax calculation across marketsBuyRate tables age badly and hand coded rates fail audits in a way that is expensive to unwind.
Commerce engine and checkoutBuy the coreChosen by market and catalogue shape, whether that is a hosted platform, a composable engine or a regional Arabic first option.
Search and merchandisingBuy the core, build the edgeA search engine underneath with your ranking and filter logic on top. Deep catalogue filtering is exactly the shape of the edge.
ATP, order routing and allocationBuildThis is where your margin and your cancel rate live, and no vendor default matches your node economics.
Store and dark store picking appsBuildThe device, the glove, the chiller and the network are yours specifically.
Product information managementBuy the core, build the edgeBuy the PIM and build only the syndication mapping to your channels.
Loyalty and promotionsBuy the core, build the edgeA rules engine with a custom layer and the golden basket regression suite.
Marketplace split payoutsBuyA licensed platform provider handles settlement. You keep the ledger and the reconciliation.

Transparency

What retail operations software development costs, with the arithmetic shown

Every competitor publishes a total with no hours behind it. Here is the rate, the hours and the multiplication, so you can argue with any line of it. Priced against: Number and quality of integrations and SKU and variant cardinality plus data readiness.

Phase one range

$65,000 to $122,000

Lean slice at a $60 blend, full slice at $70.

Typical timeline

10 to 16 weeks

To a launchable slice, scheduled outside the freeze.

Useful hours

1,080 to 1,745

Build, plus QA at 20 to 25 percent, plus DevOps.

What moves the number, ranked
DriverHours
Number and quality of integrationsIntegration count multiplies QA cost, not just build cost, because every new system adds contract tests, failure paths and a reconciliation report.Highest impact
Pricing and promotion complexityHigh
Fulfilment nodes and channelsHigh
SKU and variant cardinality plus data readinessHigh
Markets, languages and tax regimesMedium
Peak concurrencyMedium
Real time against batch inventory truthMedium
Legacy data migrationVariable
Hours by module
ModuleHours
Discovery and integration contracts80 to 180
Catalogue, PIM, search and merchandising220 to 520
Storefront, checkout, payments and tax160 to 360
Subscriptions and dunning120 to 300
Order management: ATP, routing and allocation250 to 600
ERP, POS and inventory integration330 to 870
Picking, dark store app and returns290 to 680
B2B, marketplace and the customer mobile app800 to 1,880

Three worked examples

  • On top of whichever rows apply, every build carries the same cross-cutting lines: admin, CMS, reporting, consent and analytics 90 to 200, accounts, loyalty and wallet 80 to 200, data migration 60 to 260, peak load hardening 60 to 160, DevOps and CI/CD 60 to 160, and QA, UAT and hypercare at 20 to 25 percent of build.
  • D2C launch or single channel B2B portal: 700 to 1,400 hours. At a $60 to $70 blend that is roughly $42,000 to $98,000.
  • Mid market omnichannel covering web, POS, one ERP, click and collect and returns: 1,800 to 3,500 hours. At the same blend that is roughly $108,000 to $245,000.
  • Quick commerce add on: the picking and dark store app at 200 to 460 hours plus slot capacity and dispatch, added to a storefront you already own rather than replacing it. This is the cheapest useful project in this sector and the one most often skipped.
  • These are ranges derived from module hours, not a quote. Discovery converts one of them into a fixed price.

Engagement

Engagement models

Four models for retail operations software development, each with the downside stated in the same breath. In order of how settled the scope is, they are: Fixed scope phase one, Dedicated squad, monthly, Integration only engagement and Support, hypercare and peak standby.

Fixed scope phase one

Upside

You get a fixed price and a fixed date, both derived from the discovery artifacts rather than from a guess.

Downside

Everything outside the signed spec becomes a change request, so the spec has to be frozen and somebody on your side has to own that freeze and defend it.

Dedicated squad, monthly

Upside

A standing team, re-prioritised each sprint. Best where the roadmap is genuinely unknown and will be discovered by shipping.

Downside

You carry the utilisation risk, and it only works if your product owner gives it real hours every week rather than a status call.

Integration only engagement

Upside

We build and own the middleware between ERP, OMS, POS and channels while your existing team keeps the storefront.

Downside

We do not control the storefront roadmap, so the blame boundary has to be written down before anything breaks rather than negotiated after.

Support, hypercare and peak standby

Upside

Named response targets through the freeze window and the peak season, with a rota you can see.

Downside

This is not a discovery vehicle, and during the freeze the honest answer to most feature requests is January.

Delivery

How we deliver retail operations software development

Five phases, each named by the artifact it produces. A generic waterfall diagram would tell you nothing. In order, they are: Integration contract pack, Data readiness report, Vertical slice in production, Cutover runbook and Peak readiness pack. Each is named by the artifact it hands you, so you can ask to see one.

  1. Phase 01

    Integration contract pack

    Request and response contracts per system, the ATP formula agreed in writing by the people who own each term, idempotency and retry rules, and a RACI that names the ERP owner. 80 to 180 hours.

  2. Phase 02

    Data readiness report

    A variant grid audit, attribute completeness by channel, image standards, country of origin and Arabic attribute coverage, and a named taxonomy owner. Build does not start until this passes, which is occasionally an unpopular sentence and always the right one.

  3. Phase 03

    Vertical slice in production

    One complete order path live end to end, running read only dual run against the existing system for two weeks, on one cohort or one store.

  4. Phase 04

    Cutover runbook

    A redirect map built from live server logs rather than from a sitemap, a canonical and schema parity checklist, the cohort schedule, and a documented reverse cutover with the decision owner and trigger conditions named.

  5. Phase 05

    Peak readiness pack

    Load test report at a stated multiple of business as usual peak, the oversell SLO dashboard, the promotions regression suite result, the freeze calendar and the hypercare rota.

Non-functional

The technical buyer's checklist

Grade any vendor quoting for retail operations software development with this, including us. They are grouped as: Correctness, Performance, Integration hygiene, Auth, secrets and the payment page, Privacy and residency, Accessibility, Operability, Exit and Certifications, stated plainly. Copy any line straight into your own requirements document.

Correctness

An oversell rate service level objective with a numeric target. Stated ATP recompute latency. A daily reconciliation job comparing orders across commerce, ERP and payment provider, with an exception report somebody actually reads.

Performance

A p95 checkout latency budget. A largest contentful paint budget on the product page. Load tested at a stated multiple of peak. Defined cache and queue behaviour under a flash sale.

Integration hygiene

Idempotency keys on every mutation. HMAC-SHA256 verification with a replay window. A dead letter queue with a replay runbook. Contract tests running in CI, not in a document.

Auth, secrets and the payment page

OAuth 2.0 with PKCE for platform apps, client credentials for server to server, mTLS for bank and ZATCA integrations, JWKS rotation, and no secrets in the repository. On checkout specifically, PCI DSS v4.0.1 requirement 6.4.3 script inventory and integrity checks and requirement 11.6.1 tamper detection, plus content security policy and subresource integrity.

Privacy and residency

Consent log versioning, a DSAR workflow, a 72 hour breach notification path, India payment data localisation, and a documented cross border transfer position for Oman.

Accessibility

EN 301 549 and WCAG 2.1 AA if you sell into the EU, plus a published accessibility statement.

Operability

Sentry or equivalent, correlation IDs that survive across systems, structured logs, blue green or canary deploys, feature flags, and a rollback procedure someone has rehearsed.

Exit

Code in your repository, infrastructure as code, credentials in your accounts. Changing supplier should be a commercial decision, not a technical hostage situation.

Certifications, stated plainly

Zyneto holds no certifications. We are not ISO 27001 certified, not SOC 2 attested, not a PCI DSS assessed entity, and not an accredited e-invoicing Service Provider anywhere. We build to the controls, document them, and hand you the evidence for your own audit. Ask any vendor who implies otherwise to show you the certificate and its expiry date.

Frequently Asked Questions

We are a Saudi retailer. Are we already in ZATCA Phase 2 scope?

Wave 25, announced 24 July 2026, drops the threshold to SAR 187,500 of VAT subject revenue in any year from 2022 to 2025, with integration required by 1 February 2027. Phase 2 needs cryptographic stamping, a UUID, hash chaining and API clearance or reporting. A compliant looking PDF is not Phase 2.

What does Oman's Fawtara require from our commerce and POS stack?

Peppol five corner, UBL 2.1 XML plus a Tax Data Document, routed through an accredited Service Provider. Phase 1 went live August 2026, Phase 2 February 2027, Phase 3 August 2027, B2G August 2028. B2C invoices carry a QR code and must reach the Service Provider within 24 hours, which ends nightly batch invoicing as a practice.

Can a three option platform handle apparel with size, colour, fit and length?

Not in one product. A three option ceiling means four dimensions requires either splitting the product or modelling the grid outside the platform. Variant limits and API generation also matter: older REST admin integrations degrade well before the documented variant ceiling, so check the API version your apps are on, not just the platform tier.

We are on Adobe Commerce 2.4.6. Do we have to move?

Less urgently than the headline date suggests, and the answer differs by licence. 2.4.6 hit end of support on 11 August 2026, which is a hard stop for Magento Open Source. Paid Adobe Commerce carries a further year of quality and security patches on 2.4.6 at no extra cost, so you have room to plan rather than to scramble. 2.4.7 has regular support to 31 May 2027 and extended support to 31 May 2028. The upgrade that actually needs thought is Adobe Commerce as a Cloud Service, which removes filesystem access, so module based customisations do not port across as they are.

Do we need a local platform to sell in Saudi Arabia?

Not required. Salla and Zid are Arabic first and ZATCA ready, and both expose partner APIs using OAuth 2.0 with PKCE, which is why they are common choices there. Assume a local gateway is still required whichever platform you pick, because scheme routing rather than platform choice decides your checkout shape.

What changes for our Indian checkout in 2026?

The RBI Authentication Directions, issued 25 September 2025, take effect 1 April 2026: at least two factors with one dynamic for card not present, plus risk based authentication. Cross border card not present mechanisms follow by 1 October 2026. Card on file tokenisation has barred merchants from storing PAN, CVV and expiry since 1 October 2022.

Is a country of origin line in the product description enough in India?

No. Rule 6(10A) of the Legal Metrology (Packaged Commodities) Amendment Rules 2026, notified 13 February 2026 and in force from 1 July 2026, requires a searchable and sortable filter for imported products. That makes origin a structured, indexed attribute wired into your search facets, not a sentence in the copy.

Can we keep our countdown timer and the pre-ticked insurance add on?

The CCPA dark patterns guidelines of 2023 name thirteen patterns, including false urgency, basket sneaking, confirm shaming and drip pricing. The advisory of 5 June 2025 asked platforms to self audit within three months and publish a declaration. Read your checkout against that list before someone else does.

We use hosted payment fields, so is PCI our provider's problem?

Only partly. Under PCI DSS v4.0.1, all future dated requirements have been mandatory since 31 March 2025, and requirements 6.4.3 and 11.6.1 apply to the payment page even for SAQ A merchants. You still owe a script inventory and client side tamper detection.

Is Zyneto ISO 27001 or SOC 2 certified?

No, and we will not imply otherwise. What we do instead is build to the controls and hand you an evidence pack your own auditor can sample, which is the part that carries over whichever certification you eventually pursue. One thing worth knowing when you assess other vendors: the ISO/IEC 27001 transition from the 2013 standard to the 2022 standard ended on 31 October 2025, so a 2013 certificate is now void.

What does a phase one cost, how many hours is that, and how long does it take?

A lean slice is 850 build hours plus 170 of QA at 20 percent plus 60 of DevOps, so 1,080 hours, which at a $60 blend is about $65,000. A full slice is 1,300 build plus 325 QA at 25 percent plus 120 DevOps, so 1,745 hours, about $122,000 at $70. Calendar is 10 to 16 weeks to a launchable slice. We will give you a band on the first call and a fixed price only after discovery, because the integration inventory moves the number more than the feature list does.

Who owns the code, the data and the accounts?

You do, from day one rather than at handover. Code sits in your repository, infrastructure is defined as code, and cloud, gateway and provider credentials are in your accounts and your name. Two relationships stay directly yours because they cannot be ours: we are not an accredited e-invoicing Service Provider in the UAE, Oman or Saudi Arabia, and we are not a payment institution. Replacing us should cost you a notice period, never a rebuild.

What happens next

You get a reply within one business day, from someone who has read what you sent rather than a scheduling link.

  1. A 30 minute technical call

    You describe the estate. We tell you which of the ten failure modes above you are currently exposed to, and which of them we would fix first.

  2. The integration inventory

    A short questionnaire listing every system that owns price, stock, customer or invoice, and the name of the person who owns each one inside your business.

  3. Paid discovery

    Two to four weeks. Output is the integration contract pack, the data readiness report and a fixed phase one price. Credited against phase one if you proceed.

  4. Phase one starts

    Scheduled deliberately to avoid the mid October to mid January freeze.

Start with the integration inventory, not the wireframes

Paid discovery runs two to four weeks and produces the integration contract pack, the data readiness report and a fixed phase one price. It is credited against phase one if you proceed.

  • No fixed quote before discovery
  • Reply within one business day
  • $40 to $100 per hour, by role

Our Success Stories

Real feedback from the people we've proudly partnered with.

Brooklyn Foster profile

Brooklyn Foster

Sales Director |Cintas

United States

GoodFirms
"

Zyneto Global Technologies provided excellent project management and technical expertise throughout the engagement. The team was responsive, collaborative, and adaptive, ensuring the project met our expectations and set a strong foundation for future growth.

"
Verified Review
Rating: 5 out of 5
Krystian Chlebek profile

Krystian Chlebek

Founder & CEO |Moneteo

TechBehemoths
"

We engaged Zyneto to design and develop a custom web platform for Moneteo, aimed at improving project management, data tracking, and collaboration across internal teams and external partners. Their work included full-stack web development, custom modules for workflow automation, API integration, and comprehensive testing.

"
Verified Review
Rating: 5 out of 5
Kevin Scott profile

Kevin Scott

CEO |E-Commerce Platform

Clutch
"

Overall, their responsiveness and timely deliveries contributed positively to the project's success. The client achieved better data management and quality. The service provider delivered the project on time and ensured prompt responsiveness throughout the engagement. Their innovative approach was outstanding.

"
Verified Review
Rating: 5 out of 5

Explore further

Go deeper

Build and integrate

Data and decisions

Other sectors

Related Insights

Integration, analytics and app work that applies directly to retail and commerce operations.

WhatsApp
Email
Book a Meeting