Your buyer checks their own booking. Nobody has to call.
Buyer Connect is the portal a home buyer signs into after they book — their unit, their payment schedule, their receipts, their paperwork, their KYC and the progress on their tower. It wears your brand, not ours. It shows one buyer exactly one booking. And it is included in every plan, at no extra cost.
- Included in every plan
- Phone + 6-digit OTP — no password
- Your brand, your colour, your logo
- One buyer, one booking
- Off until you switch it on
- Row-level tenant isolation
- DPDP Act 2023
One address. Six screens. Nothing your team has to re-type.
Buyer Connect is not a second database. It reads the records your sales, collections and documentation teams already maintain in Saudaflow, and shows the buyer their slice of them. A receipt entered on the CRM at 4:30 pm IST is on the buyer’s phone at 4:30 pm IST, because it is the same row.
Overview
Unit, tower and project. Booking number, configuration, carpet area, booking date. Agreement value with a received/balance bar, the next demand and how many days it is away. Your announcements, your FAQ answers, and a card that dials your team.
Payments
The milestone plan in sequence — name, percentage of value, amount due, due date and state: Planned, Due, Demanded, Partial, Paid or Waived. Then every receipt, including bounced and reversed ones. A list that quietly disagrees with the paid-to-date figure above it costs more trust than a bounced cheque does.
Documents
Paperwork and identity documents, grouped, each with the status your team set and a download button only when a real file exists behind it. Reviewer notes, compliance remarks and internal metadata are withheld by the API — there is nothing here to leak.
KYC
Verified, waiting on you, and needs a fresh copy — counted, with the checklist under them. The guidance line beside each document is derived from its status. The reviewer’s private note is never sent to the buyer’s device.
Construction Optional
The site updates you publish, for that buyer’s project — title, percent complete, photos and the date you published them. Off at the org level means the tab is not there at all, not a greyed-out shell.
Help
A ticket with a number, a category — Payment, Documents, Construction, Possession, KYC, Something else — and a thread your team replies on. Messages your staff flag as internal are stripped server-side before the thread leaves the building.
The portal is built. The SMS that carries the sign-in code is not yet live.
Codes are generated, hashed and rate-limited today, and every screen behind them works — but Saudaflow has no SMS provider wired in yet, so no buyer can finish signing in in production. Sending a transactional OTP in India needs a DLT-registered sender ID and template with TRAI, which is a two-to-three week registration, not a code change.
Turn the portal on for staging and rehearsal now. Don’t print the link on a possession letter until we tell you the sender is live. We would rather say this here than have you find out from an angry buyer.
From booking to a buyer who stops phoning
Six steps, in the order they actually happen. Five of them are things your team already does; only one is new work, and it is done once for the whole organisation.
-
The booking goes into the CRM
Your team books A-1104 the way they already do — unit, configuration, agreement value, milestone plan, contact. The buyer’s mobile number is already on that contact record. That number is the invitation. There is nothing extra to send.
Sales · no new step
-
You switch the portal on and brand it
Settings → Buyer Connect. Brand name, accent colour, logo, support phone and email, plus the questions buyers keep asking. Until somebody saves that page your organisation has no portal at all — a builder has to turn this on deliberately, so nobody’s customer data is ever published by default.
Ops admin · once
-
You hand out one address
Your portal lives at app.saudaflow.in/buyer/<your-slug>. One link for every buyer — print it on the allotment letter, put it in the welcome message, paste it into the WhatsApp reply. It is not a per-buyer secret and it is not a password to look after.
Builder · copy the link
-
The buyer signs in with a code
They type their 10-digit mobile number and a six-digit code we text them. No password, no invite e-mail, no account to create, nothing to remember on a shared handset. A number that isn’t on a booking simply never receives a code — and the screen never says which it was, so nobody can fish for your customer list.
Buyer · about 30 seconds
-
The session resolves to exactly one person
Verifying the code pins one contact into the session. Every screen after that is filtered by your organisation and that contact — a booking id in the URL is a hint the server re-proves before it returns a byte, never an authority. There is no “list all bookings” surface in the buyer API at all.
Enforced in the API · not in the browser
-
It updates itself, and you keep the switches
Nothing is copied or re-keyed. Seven switches decide what a buyer can see — cost sheet, construction feed, indicative value, online payment, and site-visit, rent-out and resale requests. Turn the whole portal off and live sessions stop working on the buyer’s very next tap, not whenever their token happens to expire.
Automatic · reversible in one click
What it actually looks like
These are HTML mockups, not photographs — built from the shipped screens, using the portal’s own colours, its own field names and its own states. Money is in ₹ with lakh and crore grouping, dates are DD/MM/YYYY and every clock in the portal is IST, because that is what the product does. Book a demo and you will see the live thing with your own project in it.
Buyer portal
Enter the code
We sent a 6-digit code to +91 98765 43210.
4172
Code valid for 4m 12s
Open my portal
← Change numberResend in 18s
Only the number your builder has on file can open this portal. We never show it in full again.
Trouble signing in? Call your relationship manager.
Signing in — step two of two Mid-entry: four of the six digits are in, so the button is still disabled and the code’s own countdown is running. One autofill-friendly field, not six boxes, because six boxes break SMS autofill on both iOS and Android. Five wrong tries burn the code; five codes an hour is all one number can ask for. HTML mockup of the real screen
- Booking
- BKG-2026-0417
- Configuration
- 3 BHK
- Carpet area
- 1,170 sq ft
- Booked on
- 14/02/2026
Agreement value
₹1,85,31,450
- Received
- ₹1,01,92,298
- Balance
- ₹83,39,152
Payment schedule →
Demand
Next payment due
On completion of 10th slab₹18,53,145
Overdue by 4 days
3 of 4 verified
Overview, on a phone The four questions a buyer arrives with, answered above the fold: what did I buy, what do I owe next, what is still stuck on me, how is the building coming along. Navigation sits at the bottom, in thumb reach. The header wears the builder’s logo and accent colour — Saudaflow’s mark appears on the sign-in screen and nowhere else. HTML mockup of the real screen
Agreement value
Your payments so far
₹1,85,31,450
- Received
- ₹1,01,92,298
- Balance
- ₹83,39,152
- Paid
- 55%
Demand
Next payment due
On completion of 10th slab₹18,53,145
Overdue by 4 days
Pay by NEFT, RTGS or cheque using the bank details on your demand letter. Your relationship manager can resend it.
Milestones
Payment schedule
8 milestones in your plan
- On booking₹18,53,145
- On agreement₹37,06,290
- On completion of plinth₹27,79,718
- On completion of 5th slab₹18,53,145
- On completion of 10th slab₹18,53,145
- On completion of 15th slab₹18,53,145
Received
Receipts
Reversals and bounced payments are shown too.
- RCP-2026-0142₹18,53,145
- RCP-2026-0198₹37,06,290
- RCP-2026-0221−₹2,00,000
Total received: ₹1.02 Cr
Payments — the plan, the money in, and what is next Amounts are the plan amounts the server sent, never re-derived in the browser. The overdue milestone says so in words as well as in colour. The reversed receipt is on the list on purpose: a receipt list that quietly disagrees with the received figure above it is how a buyer decides you are hiding something. “Receipt on file” is a chip rather than a button because the receipt scan is not yet fetchable through the buyer API — document downloads work today, receipt scans do not. Online payment is off for this builder, so the portal tells the buyer how to pay instead of showing a button that goes nowhere. HTML mockup of the real screen
Your buyers’ address
https://app.saudaflow.in/buyer/lodha-vista
Copy link
Buyers sign in with the mobile number on their booking — the number saved on their contact record. No password, no invite: they type the number, we text a 5-minute code, and the session resolves to exactly one buyer. A number that isn’t on a booking simply never receives a code.
No SMS is being sent in this build. Buyer sign-in codes are generated and stored, but the SMS seam is not implemented — nothing leaves the server, so no buyer can complete sign-in today, whatever this page says. It needs a DLT-registered sender and template (a 2–3 week TRAI registration) plus the provider wired into the API. Turn the portal on for staging and rehearsal; don’t print the link on a possession letter yet.
Signed in now34
Open questions6
Open requests3
Published updates18
What buyers can see
Each switch changes a real screen in a customer’s hand
Everything optional is off until you turn it on.
Cost sheetOn: buyers open the approved cost sheet for their unit — every charge, every tax, the total. Off: the panel disappears from their portal.
Construction progressOn: the updates you publish appear on the buyer’s progress feed. Off: nothing shows, even for updates already published.
Today’s indicative valueOn: an estimate from your own circle-rate table, carrying a disclaimer that it is not a valuation, not an offer and not a price. Buyers screenshot numbers — leave it off unless your circle rates are current.
Online paymentOn: the next demand shows a “send me a payment link” action. There is no payment gateway behind it in this build — it raises a callback request for your team. No money moves inside Saudaflow.
Site visit requestsOn: buyers can ask to visit the site, with a preferred date. It lands in the buyer requests queue.
Rent-out requestsOn: buyers can ask you to help let their unit out — a lettings lead from someone who already bought.
Resale requestsOn: buyers can ask you to help resell — resale inventory you would otherwise never hear about.
Sign-in
How long a code lasts, and how long a buyer stays signed in
Code is valid for — 5 minutes
Stay signed in for — 30 days
The portal keeps its token in the browser tab only, so closing the tab ends the session regardless.
Your side of it — Settings → Buyer Connect One page, one save. Every switch names its consequence in the buyer’s words, because everything on this screen reaches a customer. The counters are live: buyers signed in right now, questions waiting on your team, open requests, updates you have published. The red note is real product copy — we would rather a builder read it here than discover it on a possession letter. HTML mockup of the real screen
Two people stop being frustrated at the same time
The buyer who has paid you eighty lakh rupees and cannot find out whether their cheque cleared. And the executive who is meant to be selling the next flat and is instead reading a payment ledger down the phone.
For the buyer
The person who boughtSix phone calls they no longer have to make — and six calls your team no longer has to take. These are the exact questions the screens answer.
- “Has my payment gone in?” Every receipt your team records appears against their unit with the amount, the method and the date — including the ones that bounced or were reversed.
- “What do I owe next, and by when?” The next demand, its amount, and a due line in plain words: due today, due in 12 days, overdue by 4 days.
- “Can you WhatsApp me a copy of the agreement?” Their paperwork is a download on their own phone at 11pm, not a favour from whoever is at their desk.
- “What is still pending from my side?” KYC counted — verified, waiting on you, needs a fresh copy — with the checklist underneath.
- “How is the tower coming along?” Your published site photos and percent complete, dated, if you switch the construction feed on.
- “Who do I even ask?” A ticket with a number and a thread your team replies on, or a tap-to-call to the number you configured. Their booking is attached automatically, so nobody starts with “which flat is this?”
The portal never explains a decision your team has not made. If a milestone has no plan yet, it says your builder hasn’t published one — it does not invent a date.
For the builder and the channel partner
Your sidePost-sales in Indian real estate is mostly repeat questions. This takes the repeat questions off the floor without taking the relationship away.
- Fewer status calls into a team that is meant to be selling. Every answer the portal gives is a call your post-sales desk does not take — and the FAQ you write on the settings page is literally there for the ones it keeps taking.
- Fewer document re-sends. The allotment letter, the agreement and the demand letter sit on the buyer’s phone. Nobody scrolls back through six months of WhatsApp looking for a PDF from March.
- Faster collections. A buyer looking at “overdue by 4 days” against a named milestone acts sooner than one waiting for a demand letter to be re-sent. The number in front of them is the number in your ledger.
- Trust at handover — which is where referrals come from. Nothing about the money is hidden, reversals included. The buyer who felt informed for three years is the buyer who sends you their brother-in-law.
- Channel partners stop chasing your accounts team. Their buyer has the status first-hand, so the CP’s “just checking on Priya’s receipt” call never gets made.
- Rent-out and resale leads from people who already bought. Two switches let a buyer ask you to let their flat out or help resell it — inventory that otherwise walks to a broker outside your building.
- No extra licence, on any plan. Essential, Professional and Custom all carry it — ₹799, ₹899 and ₹1,199 per seat per month, billed quarterly — or annually for 10% less (₹8,628, ₹9,708 and ₹12,948 a seat for the year), plus 18% GST. Buyers are not seats; you are never charged for the people logging in to look at their own booking.
Configuring the portal needs the Settings permission; working the buyer question queue needs Contacts. A post-sales executive can answer buyers without holding the keys to your organisation’s configuration.
The one surface where a leak is visible to your customer
A buyer portal is the only screen in Saudaflow where a mistake is seen by the person who paid you. It is built accordingly, and the rules below are enforced in the database and the API rather than by a front-end remembering to hide something.
One buyer, one booking
A verified session resolves to exactly one contact. Every read is filtered by your organisation and that contact inside the query, before a byte comes back. There is no “list all bookings” endpoint in the buyer API to find.
Per-tenant isolation, in the database
Separation between builders is enforced by Postgres row-level security, not by application code remembering to add a clause. RLS is ENABLEd and FORCEd, so the rule holds even for the connection our own API uses.
Nothing internal crosses over
Staff notes, commission, the owning channel partner, reconciliation state, compliance remarks and any message your team marks internal are not in the buyer payloads at all — so a future bug has nothing to leak.
Secrets are never stored in the clear
The sign-in code is kept as a SHA-256 hash; the session token is a hash of 32 random bytes. The raw token is handed to the buyer’s tab once and never rides in a URL, so it cannot land in a server log, a Referer header or their browser history.
Nobody can fish for your customer list
Asking for a code does identical work and returns an identical response whether the number belongs to a buyer of yours, a stranger, or nobody at all. Five codes an hour per number; five wrong tries per code, then that code is dead.
Audited, and revocable now
Every code request, failed attempt, sign-in and sign-out is written to your organisation’s append-only audit log with the number masked. Switch the portal off and live sessions stop working on the buyer’s very next tap.
Built for the DPDP Act 2023. No advertising or retargeting pixels run on the portal. The buyer’s session token lives in the browser tab and dies with it — which matters, because buyer portals get opened on a spouse’s or a son’s handset far more often than any product spec admits.
The questions builders actually ask
Anything else, ask it on the demo call — or read how we handle data.
Does the buyer have to install anything?
No. It is a web page at the address you hand out, and it is built phone-first: 44px targets, navigation at the bottom of the screen in thumb reach, one-handed use, and 16px inputs so iOS doesn’t zoom the page when a field is tapped. It works on the browser that came with the phone.
What if one buyer has two flats with us?
The header grows a booking switcher and every tab answers about the booking they picked. A buyer with one flat never sees it — that is most buyers, and an extra control on a phone screen for a case that does not apply is a cost, not a feature.
How does it know which buyer is which?
By the mobile number, matched against the contact record your team already keeps: the primary phone, the alternate phone, and every number in that contact’s phone list. So a joint applicant whose number sits on the same contact can sign in.
If you want a second person — a spouse, a son who handles the paperwork — to have their own access, put their number on that contact record. The portal does not resolve two separate contacts against one booking today.
A buyer lost their phone. What do we do?
A portal session lives in the browser tab, so closing the tab already ends it. You set the maximum length yourself — anything from 24 hours to a year, with 30 days the usual choice — and signing out revokes the session on the server, not just on the device.
If you need everyone out at once, switching the portal off stops every live session on its very next request. There is no per-buyer “revoke this session” button in the CRM yet; the whole-portal switch and the session clock are what exist today.
Can the buyer pay from the portal?
Not yet, and we are not going to pretend otherwise. Switch “online payment” on and the next demand shows a request a payment link action, which raises a real, audited request for your team to act on. No payment gateway sits behind it and no money moves inside Saudaflow.
With the switch off — the default — the portal tells the buyer to pay by NEFT, RTGS or cheque using the bank details on their demand letter, which is what they were going to do anyway.
Does it cost extra?
No. Buyer Connect is included in every plan — Essential, Professional and Custom, at every team size. Billing is quarterly or annual, never month to month, and annual takes 10% off; the ₹799 / ₹899 / ₹1,199 you see quoted are the per-seat monthly rates.
Buyers are not seats. You are never charged for the people signing in to look at their own booking, however many of them there are.
See your own booking in it.
A 30-minute call. We set the workspace up with you, put one of your real projects and one real booking in, and open the buyer portal on your own phone so you can judge it the way your customer will.
Included in every plan. No card, no self-serve signup. Prices are on the pricing page, not behind the call.