APCDT supports families of children with disabilities in Toplița, Romania, and funds its work through charity concerts, donations and volunteers. Its old Wix site was a brochure: a few static pages and an IBAN for donations. Everything else happened by hand: seats tracked on paper, volunteer contracts printed and scanned, reminders typed one WhatsApp at a time.
I rebuilt it from scratch as a custom web platform that now does that work for the team. I owned the whole project end to end: product scope, UX and visual design, front-end, database, integrations, deployment and security.
Every concert meant a paper seating plan, phone reservations and hand-written lists at the door
Volunteer onboarding was a stack of printed contracts, including extra paperwork for minors
Confirmations and reminders were sent manually, one message at a time
Romanian only, with no accounts and no data to learn from
The goal: one platform that a small volunteer team can run on its own, that is cheap to host, and that is safe enough to handle payments and personal data.
How I built it: four phases, the right tool for each
1. Prototype (late January 2026) — Lovable
I used Lovable to get a clickable prototype in front of the board within days: the information architecture, the look and feel, sign-in, the admin shell and RO/EN/HU switching. People react far better to something real than to a mock-up, and it locked the scope early.
2. Engineer (February – March 2026) — Google Antigravity
I then took the code in-house and continued in Antigravity. I migrated the content and past events from the old Wix site, then built the parts that make the site useful: an events CMS, a seat map of the venue, ticket generation, Stripe donations, WhatsApp messaging, volunteer contracts and email marketing.
3. Launch and run live events (March 2026)
Free tickets for the 2026 Easter concert were handed out online from apcdt.ro. Running real events surfaced real bugs (timezones, seat numbering, how WhatsApp replies were read), and each was fixed before the next event.
4. Harden (July – August 2026) — security audit with Claude
Because the site takes payments and stores personal data, I ran a full audit: tightened the database access rules, enforced a strict Content-Security-Policy, upgraded the build toolchain, fixed 10 QA issues and added off-site log backups.
What I built
Fundraising
One-off and monthly card donations through Stripe, confirmed by webhook
Preset amounts tied to concrete impact, automatic thank-you email, donation history in the donor's profile
Online Form 230 for redirecting 3.5% of income tax to the association
Events and ticketing
Events CMS with posters, descriptions, video links and photo galleries
Interactive seat map built from a reusable venue template, with temporary holds that release automatically
PDF tickets with QR codes, delivered by email and WhatsApp
A door scanner page that validates tickets at check-in
CSV import for offline reservations, plus RSVP tracking
Volunteers
Online sign-up that generates the volunteer contract automatically
ID document upload and a parental-consent flow for minors
Signed contracts stored in private storage and emailed back automatically
Communication
Email campaigns and event automations (confirmations, reminders)
WhatsApp campaigns, automatic RSVP reading, and a two-way WhatsApp inbox inside the admin
Blog with a rich-text editor for the marketing team
Admin and accounts
Sign-in with email, Google or Facebook, with password recovery
Roles for admins, marketers and members
One dashboard for events, seats, registrations, donations, volunteers, content and messages
In-house page-view analytics alongside Vercel Analytics and GA4
Labelled forms, named links for screen readers, an accessibility toolbar, and a unique title and description on every public page for SEO
Architecture
A serverless setup that costs almost nothing to run and has no servers to maintain.
Vercel serves the React + Vite single-page app from its edge CDN, with strict security headers
Cloudflare handles DNS and stores media in R2
Supabase provides the Postgres database, authentication, private file storage, scheduled jobs, and Edge Functions for tickets, PDFs, payments, contracts, email and WhatsApp
Stripe for card payments, Twilio for WhatsApp, SMTP for email
GitHub Actions backs up logs every 6 hours
Security and quality
Database rules open to anonymous visitors cut from 33 to 4, and those 4 only read public data
High-severity dependency advisories cut from 12 to 0 (Vite 5 → 8 upgrade)
QA score raised from 77 to 99 after fixing 10 issues in accessibility, SEO and UX
Content-Security-Policy switched from report-only to enforced, after testing it live page by page
28 automated checks confirm that admins and members still see exactly what they should
Logs exported every 6 hours with 180-day retention, so incidents can be investigated
Results so far
510 event registrations managed in the platform
447 seats mapped for reserved seating
7,900+ page views tracked in-house
14 volunteer contracts processed online instead of on paper
230+ WhatsApp campaign messages sent from the admin
3 languages, 26 pages and views, 592 commits over 36 build days
Most importantly, a small volunteer team now runs donations, events and volunteers from one place, without spreadsheets or paper.
Want something like this?
I build websites that do real work for nonprofits, event organisers and small businesses: online donations or payments, bookings and ticketing, member and volunteer flows, automated email and WhatsApp, and an admin your team can actually use. I prototype fast so you see your product early, then I engineer it properly and secure it before it handles real money or real data.
Send me a message here on Contra with what you need, and I'll reply with a scope and a quote.
Rebuilt an NGO site into a custom platform: card donations, seated ticketing with QR check-in, volunteer e-contracts, WhatsApp + email, in 3 languages.