
Jabal Al Noor Pharmacy Digital Commerce Platform
A four-app commerce and operations platform for a UAE multi-branch pharmacy group, on one modular NestJS API.
- Client
- Jabal Al Noor Pharmacy
- Industry
- Pharmacy retail
- Outcome
- ~19,800 SKUs live across 6 branches
What it is
Jabal Al Noor Pharmacy sells prescription and over-the-counter medicines alongside cosmetics, body care, supplements, medical devices and wellness products, across six locations: four pharmacy branches and two Marhaba Opticals outlets.
We built four frontends and one API:
- Customer storefront — browse, search, prescription upload, checkout
- Staff admin portal — catalogue, orders, prescriptions, content
- Delivery agent app — an offline-capable PWA for the last mile
- Optical micro-site — a marketing site for the Marhaba Opticals brand
The apps are separate for bundle isolation and independent deploys, all served by a single modular NestJS backend.
Scale of the build
| Metric | Value |
|---|---|
| Production code | ~57,000 lines TypeScript |
| Test code | ~24,800 lines across 162 files |
| Commits | 627 |
| Apps | 5 (four Next.js, one NestJS) |
| API modules | 24 |
| Database tables | 31 |
| Permissions | 43 across 15 modules |
| Background queues | 7 BullMQ queues |
| Catalogue size | ~19,800 SKUs |
The stack
Frontends
Next.js 16 App Router, React 19, TypeScript strict, Tailwind CSS 4, TanStack Query, Zustand, and nuqs for URL state.
Backend
NestJS 11 on Express 5, Drizzle ORM, Zod for validation shared across the wire, BullMQ for all async and scheduled work, Argon2 for password hashing, and Meilisearch for bilingual typo-tolerant product search.
Data and storage
PostgreSQL, Redis split into two instances with opposite eviction policies, Cloudflare R2 for product images and delivery proof, and Azure Blob Storage in UAE North for prescriptions.
Why the write-ups
The interesting parts of this project were not the CRUD. They were the decisions where the obvious approach was wrong: classifying a catalogue that arrives as seven fields of free text, refusing to let a model decide which medicines need a prescription, keeping health data inside the UAE when the incumbent vendor could not, and building a delivery app for basements with no signal.
Deep dives
9 engineering write-ups from this project.
- Teaching a machine what a medicine isClassifying ~19,800 pharmacy SKUs that arrive as seven fields of free text, after embeddings alone failed for a structural reason.
- An AI that is not allowed to decideWhy the prescription-required flag is a three-state classifier that can abstain, and why a model never writes the operational truth.
- Surviving the quotaA degradation path where the failure mode is worse than an outage, because a fallback hides the evidence of itself.
- Health data that cannot leave the countryUAE health-data residency, after the incumbent storage vendor turned out to be unable to provide it and the backup plan went offline.
- A delivery app for a basement with no signalAn offline-first PWA with two persistence layers, and error handling that refuses to treat a lost connection like a server rejection.
- Six branches, one order pool, no privilege escalationGroup-based permissions for branch staff, and the 14-minute cache window that made a revocation dangerous.
- Local SEO for near-identically-named branchesSix locations on two URLs, hardcoded ratings, contradictory opening hours, and a QR redirect that survives a reprint.
- A CMS the marketing team cannot breakDraft and published content in one row, optimistic concurrency, and a preview token that works exactly once.
- Two Redis instances, opposite eviction policiesWhy the cache and the queue run the same technology with contradictory configuration, and the class of bug that forces it.