Hashlogics
Case study · Outdoor Hospitality

Functional Fox Smart Site

A live page for every campsite, one scan away.

Guests scan the marker at their campsite and get that site's page with no app or login. Each park keeps its own content current.

Client
Functional Fox
Industry
Outdoor Hospitality (RV parks and campgrounds)
Engagement
Web app · Mobile-first guest experience · Multi-tenant SaaS portals
Overview

Hashlogics built Smart Site for Functional Fox: the guest page, park manager portal and admin portal behind a QR code at every campsite. Functional Fox supplies the solar-lit Smart Site Markers to RV parks and campgrounds. Hashlogics built the software the code opens. A guest wants the Wi-Fi password, check-out time and park rules for their exact site. A printed handout can't change.

The challenge

Why a printed sign can't hold the answers

01

Guests keep asking the front desk the same questions: Wi-Fi, check-out time, rules.

02

Printed handouts and binders go out of date and cost money to reprint.

03

A URL printed on a metal sign can never change, a rule most web systems don't meet.

04

Maintenance issues are reported in person or by phone, with no tracking.

05

Thousands of signs had to run across many independent parks, and no park could see another park's data.

What success needed to look like

  • A guest scan opens the right site's published content, with no login and no app.
  • A park can't reach another park's data, even with a tampered URL or a direct API call.
  • Park users can't raise their own privileges.
  • Suspending an account or deactivating a marker stops that content right away.
Our approach

How Hashlogics built it, tenant rules first

  1. 01

    Map the chain from customer to scan

    We modeled the tenancy first: customer, property, area, site, marker, scan.

  2. 02

    Put the tenant rules in the database

    Row-level security went in with the data foundation, and anonymous visitors have zero direct table access.

  3. 03

    Keep the guest page light

    Guests download a small page of their own, kept apart from the portal and admin code.

  4. 04

    Build both portals on the same rules

    Next came the Park Manager Portal and the Functional Fox Admin Portal, with analytics, sign output and CSV import.

  5. 05

    Test the attacks and audit the build

    Six suites hold 43 automated end-to-end tests, including tenant isolation, privilege escalation and sign permanence. An internal security audit found three critical defects, and all three were fixed before handover.

The solution

What a scan does and what each portal controls

Each marker carries a permanent QR URL. When a guest scans it, the platform checks that the customer account, property, site and marker are all active. Only the published content for that site and its area comes back. Nobody installs an app or signs in.

Park managers edit in a draft-then-publish flow, so a change goes live on the next scan and no sign gets reprinted. Functional Fox provisions markers in batches of up to 1,000 and suspends or reactivates accounts. If you're buying a multi-tenant product, check this part first. Row-level security is forced on all 23 database tables, so the database decides who sees what. It runs on Vercel and Supabase Cloud.

One scan, from sign to pageLive
  1. ScanA guest points a phone camera at the marker.
  2. ResolveThe permanent URL maps to one site. Retired paths redirect.
  3. Status checkCustomer, property, site and marker must all be active.
  4. AssembleOnly published content for that site and area comes back.
  5. LogThe scan is saved with a time and a coarse device type.

If any check fails, the guest sees "Site unavailable".

Guests copy the Wi-Fi password with one tap.
Each site page lists hookups, electric amps, maximum RV length and parking notes.
Announcements and events can target one area of the park.
Guests report a maintenance issue from their site, and staff track it as new, in progress or done.
QR codes download as PNG or SVG, with print-ready 4×6 in sign PDFs generated in the browser.
Scan analytics show top sites, areas, hours and device types without storing IP addresses or guest identifiers.
Three roles: Functional Fox admin, park admin and park staff.
URL slugs are locked for parks and admin renames are logged, so printed signs keep working.
Guest page preview in a phone frame for site A2, with the park welcome, an announcement and site details.
The guest page preview for site A2 in a sample park, as a guest sees it after a scan.
QR codes table with sample data listing marker IDs, assigned sites, permanent URLs and status for 180 markers.
QR codes, shown with sample data: each marker ID maps to one site and one permanent URL.
Content tab for site A2 listing Wi-Fi and rules items, each marked published or draft.
A site's content list, with draft and published items side by side.
How it's built

Tech stack

  • React 19
  • TypeScript
  • Vite 7
  • React Router 7
  • TanStack Query 5
  • Recharts
  • PostgreSQL 17

Platform

  • Supabase
  • Vercel

Libraries

  • qrcode
  • pdf-lib
  • papaparse

Testing

  • Playwright
  • Vitest
More from the build
Properties screen with three published park cards, each showing its area and site counts.
Properties: a sample customer account with three parks.
Wi-Fi access screen with six network cards, each showing the park and number of sites it appears on.
Wi-Fi access: one edit updates every site page it reaches.
The takeaway

Metal doesn't update. Once a URL is printed on a campground sign, it has to work for the life of that sign. That rule shaped the build: locked slugs, logged renames, redirects for old paths and a test suite for sign permanence. Tenant isolation was the other hard part. A park with a valid login must still never read a neighbor's data, and the tests attack exactly that.

By , CEO, HashlogicsUpdated
Start

Let’s deploy working AI into your business.

We build AI agents and automation, ship them into the tools you already run, then stay on under an agreed service level. A senior engineer reads every brief, and your call gets scheduled within 24 hours.

What happens next

  1. 01

    You send a brief or book a call

    Two minutes, whichever you prefer.

  2. 02

    A senior engineer replies within 24 hours

    Not a sales rep.

  3. 03

    Honest scoping, in writing

    And if we’re not the right fit, we say so.

Abdul Basit, CEO of Hashlogics

“I started Hashlogics because too many teams ship a demo, get paid, and disappear. We build to a standard we’d run ourselves — and we stay to keep it running.”

Abdul Basit · CEO · a direct line

Not ready to talk? Take the checklist.

12 questions to ask any AI agency before you sign. They separate a demo shop from a team that ships to production.

Get the checklist

Free · no newsletter