Skip to content
Sean Marroquin
Esc
  • HomePage
  • WorkPage
  • AboutPage
  • Start a projectPage
  • How this site is builtPage
  • BlogPage
  • DownloadsPage
  • Client PortalClients
  • TerraLoopCase study
  • ListoCase study
  • The Listening RoomCase study
  • PasslineCase study
  • AccuBetsCase study
  • How this site is builtPost
  • Why every client gets a portalPost
  • Switch between light and darkAction
  • Copy my email addressAction
  • PWNTT ArcadePlay
  • Play The Deploy TrailPlay
  • Play Merge ConflictPlay

Use the arrow keys to move and Enter to open.

All work

Passline

Front-desk software for small venues: check guests in, sell passes and memberships, track waivers, and market to the people who walk through the door. One codebase, rebranded per business with a single config file.

  • A new business is one JSON file and about fifteen minutes of setup.
  • Pass status comes from payment history, so a member who paid weeks ago still reads as valid.
  • Membership cards and unsubscribe links are signed, so nobody can forge or guess them.
  • Runs on the smallest server you can rent, with nightly off-site backups.

The idea

Trampoline parks, climbing gyms, and studios all run the same front desk: who is here, did they sign the waiver, is their pass still good, and how do we get them back next month. The tools for that are either a clipboard and a spreadsheet, or a big platform priced for chains. Passline sits in between. It is built for one cashier at one counter, and it costs a few dollars a month to host.

It is white-label from the ground up. Branding, colors, copy, pricing, and the waiver all live in one config file per business, so the same code ships as a jump house today and a climbing gym tomorrow. A starter preset for passes, memberships, or retail gets a new venue most of the way there.

What I built

The front-desk console is the screen that stays open all day. The cashier looks a guest up by name, email, or phone and checks them in with one tap. It greets regulars, flags someone who has not been in for six weeks, and points out a child's birthday coming up. Walk-ups are registered in one flow: contact details, pass, marketing consent, children's birthdays, and the signed waiver, then straight into the building. An Expected today list shows everyone who bought online or signed up ahead, and On site now shows who is inside.

Every guest gets a digital membership card with a QR code. Scanning it at the desk opens a one-tap check-in. The card can be added to Apple Wallet or Google Wallet.

Around the desk sits the rest of a small business:

  • Payments: online passes and recurring memberships through Stripe, a point-of-sale register with cash, card, split, and comp tenders, tips, receipts, refunds, and cash-drawer counts.
  • Waivers: signed electronically and valid for a year, with every version of the wording kept, so an old signature always shows the exact text that was agreed to.
  • Marketing: email and SMS campaigns from ready-made templates, aimed at a tier, the win-back list, new signups, or upcoming birthdays. Only people who opted in are ever included, and bounces and STOP replies are suppressed before anything is sent.
  • Scheduling: private events with deposits, classes with waitlists that promote the next person automatically, and one-to-one appointments with staff and room availability.
  • Running the business: staff roles, an activity log, time cards with overtime rules and a payroll export, loyalty points, reviews, reports, multiple locations, and a public API.

How it works

The pass is computed, not stored. The desk works out each guest's entitlement from their payment history instead of trusting the last tier someone clicked. A monthly member who paid three weeks ago shows as valid through a specific date; a lapsed pass reads "expired 5 days ago, ring up a renewal"; and buying a day pass on top of a monthly one no longer erases the membership.

Isolation is architectural. Each business runs as its own process with its own database. A small router maps a request's domain to the right one, so one customer's data cannot leak into another's through a missed filter.

Safe by default. Card details never touch the server. Every form carries a CSRF token, logins are rate-limited, owners can turn on two-factor sign-in, and in production the app refuses to start with placeholder secrets. Money, waivers, and sensitive staff actions are written to an append-only log with who did it and when.

Everything is dormant until it is configured. With no Stripe keys, payments are switched off. With no email or SMS provider, campaigns print to the console instead of sending. A new venue can be clicked through end to end before a single credential exists.

Priced in tiers. Basic, Pro, and Ultimate unlock features per deployment. Anything above a venue's tier is shown and offered as an upgrade rather than hidden or broken.

Where it stands

Passline is production-ready, and the demo is live with a full sample venue: regulars and lapsed guests, live check-ins, birthdays, campaigns, classes, and bookings.