Skip to main content
Web Applications Β· Gig Economy

Temper Freelance Marketplace

Event-driven freelance marketplace for Temper: AI skill matching, offline-capable Flutter apps and Stripe Connect escrow payments.

Temper Freelance Marketplace product cover

Temper Freelance Marketplace overview

Temper is a multi-tenant freelance marketplace that connects corporate clients with freelancers for shift-based work. Next Olive engineered its current platform, migrating a legacy monolith into an event-driven microservices environment built for global scale. The scope covered a responsive React web application, cross-platform Flutter mobile apps with full offline capability, an AI-powered skill-matching core, a Stripe Connect payment and escrow system, and an automated AWS infrastructure baseline designed for 99.99 percent uptime.

Four engineering objectives framed the work: deconstruct the monolithic core into domain-driven microservices, put an asynchronous communication layer in place for transactional messaging, enforce SOC 2 Type II, GDPR and HIPAA controls directly in the data and infrastructure architecture, and build a mobile engine that can carry out complex operations with limited or no network connectivity. The result turns the gig-economy experience from a chain of fragile database operations into an event-sourced, resilient distributed system.

Challenge in Gig Economy operations

The inherited stack ran as a synchronous PHP application on a single, over-provisioned virtual machine, coupled directly to an unindexed, single-node relational database. That coupling caused severe resource contention at peak times, long database lock queues whenever payments ran concurrently, and ungraceful failures when bursts of real-time notifications flooded the application runtime.

The client experience had matching weaknesses. The frontend was not optimised for responsive layouts, the mobile presentation layers were entirely separate, duplicated codebases, and mobile clients kept in sync with the backend through aggressive polling, which exhausted server resources and caused cascading thread-pool failures. Temper needed a platform that could absorb the volatile traffic patterns typical of gig work, such as localised morning shift updates and end-of-week timesheet processing, without human intervention and without losing a payment or a message.

Solution architecture & delivery

The backend is a set of decoupled Node.js (TypeScript) and Go microservices communicating asynchronously over an Apache Kafka event bus. Each service owns its own datastore, so there is no shared-table contention: the user management service holds identity state, the billing service keeps transactional ledgers, the matching service evaluates marketplace dynamics. Kafka topics carry a minimum replication factor of three across independent availability zones, with entity IDs as message keys so every event for a given contract or account lands on the same partition in order. An Envoy API gateway in the private subnet terminates TLS, applies rate limits, validates Okta-issued RS256 JSON Web Tokens against the JWKS endpoint and injects tenant ID, scopes and role claims into request headers so downstream services enforce RBAC without their own authentication lookups.

The matching engine is a hybrid of semantic search and hard constraints. When a client publishes a job, the ingestion service sanitises the text and publishes a JOB_CREATED event; an inference worker consumes it and runs a transformer forward pass to produce a 1,536-dimensional embedding, which is written to PostgreSQL with the pgvector extension under an HNSW index (M 16, ef_construction 64). A match request runs a cosine distance query and then filters through SQL constraints for geohash proximity, verified skill certifications, calendar availability and hourly wage windows, returning ranked candidates to the hiring manager in under 200 milliseconds across millions of profiles.

The web app uses React 18 with Next.js server-side rendering and Tailwind CSS. The Flutter mobile app compiles to native ARM code for iOS and Android and uses BLoC state management over a synchronisation engine and an embedded SQLite cache. Every offline write is appended to a local transaction log with a vector clock and transaction hash; on reconnection the client sends the unsynchronised set to the gateway, which applies mutations sequentially where no intervening writes exist and otherwise resolves conflicts with deterministic timestamp-based last-write-wins before replicating the final state back down. Notifications run through a Go connection broker that holds thousands of idle WebSocket links with non-blocking I/O multiplexing and, when a client is backgrounded or offline, hands the payload to Firebase Cloud Messaging or Apple Push Notification service, so hiring changes, shift cancellations and messages arrive within sub-second thresholds.

Payments run through a dedicated microservice on Stripe Connect. Funding a shift captures a Stripe Payment Intent into an escrow ledger record with an immutable verification token; once the freelancer uploads verified work logs and the client approves in the app, the escrow service validates the signature, updates its ledger and fires a Stripe transfer to the freelancer's connected account. Card data is captured by Stripe Elements and SDK secure fields and never enters the platform, and the payment namespace has network policies blocking egress to other services, which keeps the module PCI-DSS compliant. Infrastructure is Terraform-provisioned AWS: multi-AZ VPCs with public subnets for Network Load Balancers and NAT gateways, private subnets for the Amazon EKS cluster and Kafka brokers, and isolated database subnets for RDS PostgreSQL Multi-AZ and Redis Enterprise. GitHub Actions runs unit tests, SonarQube analysis and Trivy scans on every pull request, pushes commit-tagged images to ECR, and ArgoCD rolls them out as canaries from 5 percent to 100 percent with automatic rollback. Istio enforces mutual TLS between pods, Calico network policies deny cross-namespace traffic by default, AES-256 encryption keys in AWS KMS rotate every ninety days, CrowdStrike Falcon runs at kernel level on every node, and OpenTelemetry traces flow to Prometheus and Grafana with logs in OpenSearch and alerts routed to PagerDuty.

Key features of the Temper Freelance Marketplace

  • AI skill matching: transformer embeddings in PostgreSQL pgvector with HNSW indexing, filtered by location, certifications, availability and wage, in under 200 ms
  • Offline-capable Flutter apps for iOS and Android with SQLite transaction logs, vector clocks and automatic reconciliation on reconnection
  • Responsive React 18 and Next.js web application with server-side rendering
  • Dual-path real-time notifications: a Go WebSocket connection broker for active clients and FCM and APNs push for background states
  • Stripe Connect payments with an escrow ledger state machine that releases freelancer payouts on verified work logs and client approval
  • Domain-isolated Node.js and Go microservices (users, billing, matching, job ingestion, notifications) on an Apache Kafka event bus with replication factor three
  • Okta single sign-on and MFA with tenant-scoped JWT claims enforced at the Envoy gateway and per-service RBAC
  • Compliance built into infrastructure: CloudTrail audit logs in write-once S3, GDPR erasure and pseudonymisation, HIPAA document isolation in object-locked buckets

Who this web application is for

This architecture suits staffing and gig-economy marketplaces, on-demand labour platforms and any two-sided marketplace that must match supply to demand in real time, hold funds in escrow between parties and serve web and native mobile users from one backend. It is particularly relevant where freelancers work in regulated settings such as healthcare, where enterprise clients expect SOC 2 Type II evidence, and where the product must keep working in venues with poor connectivity.

Impact & results

  • Ranked, context-aware candidate matches returned to hiring managers in under 200 milliseconds across millions of profiles
  • Critical alerts such as hiring changes and shift cancellations delivered within sub-second thresholds regardless of app state
  • Aggressive mobile polling replaced by WebSocket push and offline-first sync, removing the thread-pool exhaustion of the legacy system
  • Duplicated native mobile codebases replaced by a single Flutter codebase compiled to native ARM for iOS and Android
  • Database failover completes in under thirty seconds with no data loss through RDS Multi-AZ synchronous replication and Route 53 endpoint remapping
  • Payments moved from lock-prone monolith transactions to an isolated, PCI-DSS compliant escrow service on Stripe Connect
  • Pods scale out within seconds when CPU passes 70 percent or a service exceeds 1,500 requests per second, and nodes drain once utilisation stays below 45 percent for fifteen minutes
  • Canary releases step from 5 percent to 100 percent of traffic with automated rollback, on an infrastructure baseline designed for 99.99 percent uptime

FAQ about the Temper Freelance Marketplace

What problem did the Temper Freelance Marketplace rebuild solve?

Temper's legacy platform was a synchronous PHP monolith on a single over-provisioned virtual machine, coupled to an unindexed single-node database. Peak traffic caused resource contention, concurrent payments queued on database locks, notification floods crashed the runtime, mobile apps were duplicated codebases, and clients synced by aggressive polling. We rebuilt it as event-driven Node.js and Go microservices on Kubernetes with Kafka, offline-capable Flutter apps and an AI matching core.

Which technologies power the Temper Freelance Marketplace?

React 18 with Next.js and Tailwind CSS on the web; Flutter for iOS and Android with SQLite offline storage; Node.js (TypeScript) and Go microservices behind an Envoy API gateway; Apache Kafka; Amazon RDS PostgreSQL with the pgvector extension; a Redis Enterprise cluster; Amazon EKS provisioned with Terraform and deployed via GitHub Actions and ArgoCD; Okta with OAuth 2.0 and OpenID Connect; Stripe Connect; CrowdStrike Falcon and AWS KMS; and Prometheus, Grafana and OpenTelemetry.

How does the AI skill-matching engine work?

When a client publishes a job, a JOB_CREATED event goes to Kafka and an inference worker runs the text through a transformer model to produce a 1,536-dimensional embedding. The vector is stored in PostgreSQL with pgvector under an HNSW index (M 16, ef_construction 64). Matching runs a cosine distance query and filters the results with SQL constraints for geohash location zones, hourly wage windows, verified certifications and calendar availability, returning ranked candidates in under 200 milliseconds.

How are payments and escrow handled between clients and freelancers?

A dedicated payment microservice integrates with Stripe Connect. When a client locks a shift, funds are captured through a Stripe Payment Intent and held in an escrow ledger record with an immutable verification token. Once the freelancer uploads verified work logs and the client approves in the app, the escrow service validates the signature, updates its ledger and fires a Stripe transfer to the freelancer's connected bank account. Card data is captured by Stripe Elements and SDK fields, so it never enters the platform, keeping the module PCI-DSS compliant.

Temper Freelance Marketplace product screens

Build your next marketplace product with Next Olive

Share your requirements β€” we will propose scope, timeline and stack within one business day.