Platform · Across the platform

What holds true on every surface

Branding, integrations, security, and the API are not features of one app. They apply to all eight surfaces and the engine underneath — which is what makes the platform yours to operate rather than ours to rent you.

Request Quote See what's covered
01
White-label & branding
Your brand on every app, domain, message, and store listing.
You own the assets
02
Integrations
Payments, maps, messaging, accounting, and POS connectors.
24 connectors
03
Security & compliance
PCI DSS, GDPR, RBI, SAMA, and HIPAA-aligned configurations.
Per market
04
API & docs
REST API, webhooks on every state change, public reference.
Open to your devs
01 · Across the platform

White-Label & Branding

Nothing in the product signals DeliveryStack to your customers, your partners, or your vendors. The brand on every touchpoint is yours, and so is the asset it lives on.

AppsYour name, icon, splash, palette, and typography on all eight surfaces
Store listingsPublished under your Apple and Google developer accounts
DomainsOrdering site, booking site, and consoles on your own domain
MessagingSMS sender ID, push, WhatsApp, and email templates in your voice
DocumentsInvoices, receipts, and settlement statements carry your identity
OwnershipListings, domain, install base, and data remain yours
Branded touchpoints
App icon
Home screen and store
Splash & onboarding
First-run screens
In-app theme
Palette and type
Web storefront
Your domain
Consoles
Admin and fleet
Notifications
Push and SMS
Email
Receipts and updates
Invoices
Vendor and corporate
If the engagement ends, the store listings, domain, install base, and data stay with you.
02 · Across the platform

Integrations

Twenty-four connectors ship configured. Anything outside the list is built against the same interface, per region.

STStripe
Cards, wallets, and payouts in 40+ markets.
Payments
RARazorpay
Cards, UPI, netbanking, and route settlements.
Payments
PAPayPal
Consumer checkout and partner disbursement.
Payments
PAPaytm
Wallet and UPI for the Indian market.
Payments
CHCheckout.com
Card acquiring for Gulf and European markets.
Payments
CACash
Collection tracked and reconciled against payouts.
Payments
GOGoogle Maps
Geocoding, routing, distance matrix, and tiles.
Maps
MAMapbox
Tiles, navigation, and offline-capable routing.
Maps
HEHERE
Routing and traffic where Google coverage is thin.
Maps
OPOpenStreetMap
Self-hosted tiles for cost-sensitive deployments.
Maps
TWTwilio
SMS, voice, and number masking for calls.
Messaging
WHWhatsApp Business
Order updates and support on WhatsApp.
Messaging
FIFirebase
Push notifications across iOS and Android.
Messaging
SESendGrid
Transactional email and receipts.
Messaging
MSMSG91
SMS and OTP with an Indian sender ID.
Messaging
INIntercom
In-app support chat for customers and partners.
Messaging
QUQuickBooks
Settlement and invoice export to accounting.
Business
XEXero
Ledger sync for payouts and commissions.
Business
ZOZoho Books
Invoicing and GST handling for Indian operators.
Business
SASAP / ERP export
Structured export for enterprise finance systems.
Business
SQSquare POS
Catalogue and order sync for vendor counters.
Vendor systems
TOToast
Menu and order sync for restaurant operators.
Vendor systems
PEPetpooja
Restaurant POS and inventory sync for India.
Vendor systems
INInventory API
Stock levels and sold-out state from your own system.
Vendor systems
24 connectors shown. Need something not listed? We'll scope the connector. Tell us what you run
03 · Across the platform

Security & Compliance

Payment, privacy, and health-data obligations differ by market. The platform is configured to the regimes you actually operate under.

PCI DSSGDPRRBI guidelinesSAMA (Saudi)HIPAA-alignedSOC 2 practices
Data residency
Your database instance in the cloud region you choose, with export on demand.
Encryption
TLS in transit and encryption at rest, with key rotation handled by Aalpha.
Access control
Role-based permissions across every console, with SSO available.
Payment scope
Card data stays with the gateway; the platform never stores raw card numbers.
Audit logging
Every configuration and order state change attributed and timestamped.
Retention
Retention windows and deletion requests configured to your jurisdiction.
04 · Across the platform

API & Docs

A REST API over the same objects the apps use, webhooks on every state change, and a public reference your developers can read before signing anything.

REST endpoints
Orders, trips, partners, vendors, zones, and settlements.
Webhooks
Every state change pushed to your endpoint with retry and signature.
Read API
Pull raw event and trip data into your own warehouse.
Sandbox
A test environment with seeded data before you touch production.
Read the API reference
POST /v1/orders
# create an order on behalf of a vendor
curl -X POST https://api.yourbrand.com/v1/orders 
  -H "Authorization: Bearer $KEY" 
  -d '{"vendor_id":"v_18f2","items":[…],
       "drop":{"lat":12.971,"lng":77.641}}'

# webhook fired on every state change
order.assigned  → { id, partner_id, eta }
order.completed → { id, proof, total }
REST
JSON over HTTPS
Webhooks
Signed, retried
Sandbox
Before production

Platform-Wide FAQ

Ownership, compliance, and what your developers can reach.

Still have questions? Talk to our team

Does white-label mean a skin, or real ownership? +

Real ownership of the customer-facing assets. Apps are published under your developer accounts, the domain is yours, and the install base and data stay with you if the engagement ends. Aalpha's name appears nowhere your customers can see it.

What if the integration we need isn't in the 24? +

Most requests are a connector against the same interface rather than platform work. Send us what you run — payment processor, POS, accounting system — and we'll tell you whether it's configuration, a connector build, or genuinely custom.

Are you certified for PCI DSS and SOC 2? +

Card data is handled by certified gateways, so the platform stays out of the card-storage scope. For GDPR, RBI, SAMA, and HIPAA-aligned deployments we configure residency, retention, and access controls to the regime, and document the setup for your auditors.

Can our developers build on top of the platform? +

Yes. The REST API and webhooks cover the same objects the apps use, and a sandbox with seeded data is available before production access. The reference is public — your team can read it before you commit to anything.

Who owns the data we generate? +

You do. It lives in a database instance dedicated to you, in your chosen region, and is exportable in full in standard formats at any point, including at the end of the engagement.

Bring Us Your Requirements List

Send the integrations you need, the regimes you operate under, and the systems you already run. We'll come back with what is configuration, what is a connector, and what is custom work.

Across the platform · Quick facts
Applies to All 8 apps + engine
Connectors 24 shipped, more on request
Compliance Configured per market
API access REST · webhooks · sandbox
Every item here applies to all eight apps and the engine — not to a premium tier.