Case study

Gym management system

2026

Gold Gym

Gold Gym's management system is a web app for running a gym's front desk: members, fees, attendance, expenses and reports, used by several staff at once. Staff permissions are enforced by the database itself, members check in by thumb impression or member code, and fee reminders go out over WhatsApp.

Demo video

At a glance

Role

Full-stack design and development

Year

2026

Stack

  • — Next.js
  • — React
  • — Supabase (Postgres, Auth, row level security)
  • — Cloudinary
  • — Tailwind CSS
  • — Node.js fingerprint bridge

Highlights

  • — Database-enforced staff permissions
  • — Thumb impression and kiosk check-in
  • — WhatsApp fee reminders

The problem

The system began as an offline desktop program on a single reception computer. That holds up until a gym needs more than one person at the desk: separate men's and women's desks, staff who should take payments but not see the expenses, member photos, and attendance by thumb impression.

A program that lives on one PC cannot be shared, and hiding menu items from a staff account is not the same as stopping them.

The approach

The desktop app was rebuilt as a website with the same screens and the same way of working, on Postgres. The superadmin ticks what each staff account may view and edit, module by module, and those permissions are enforced by row level security in the database rather than by the interface. A staff member who types a URL they were not granted gets nothing back from the database, not just a redirect.

The men's and women's desks are scoped the same way, at the database. Verification scripts sign in as a throwaway staff account and prove the database refuses what that account was not given — reading, adding, editing, deleting, taking payments and marking attendance.

Attendance and reminders

Browsers cannot talk to fingerprint readers, so a small companion service on the front-desk computer owns the reader and answers the app over localhost. Swapping one reader for another, or for a fingerprint terminal by the door, is a single setting. Fingerprint images are never stored, and a public kiosk screen lets members check themselves in by code until the reader is in place.

Fee reminders go out over WhatsApp, either tapped from the Reminders screen or sent by a nightly run through Meta's Cloud API, with SMS as the fallback for numbers that cannot receive WhatsApp. Members who stop coming are marked as left rather than deleted, so their history is still there if they come back.