Case study · DADO · 2026

This case study is from a private beta

It documents shipped work at DADO, including internal tooling and real money flows. The access word is on my resume.

Need the word? Email atharva2089@gmail.com with the subject "DADO access". Same-day reply.
Back to the DADO overview

Accounts at DADO: a lifetime record of your gifts, the people you give to and the days that matter. I lead it.

Accounts at DADO: a lifetime record of your gifts, the people you give to and the days that matter. I lead it.

Accounts at DADO: a lifetime record of your gifts, the people you give to and the days that matter. I lead it.

Role

Lead, Accounts

Team

Founder and CEO (PRD), four engineers

Timeline

Aug 2026 to present

Tools

Figma, Claude Code, React, Supabase, Postgres

worldofdado.com
9:41

The account on desktop and a thank-you sent from a phone, both recorded on staging. Names blurred.

The short version

Problem

Most gifting apps forget you after checkout. DADO’s account had to remember the people, the dates and the gifts, and keep each one as private as the member chose. When I joined, six of its controls did not do what they said.

Most gifting apps forget you after checkout. DADO’s account had to remember the people, the dates and the gifts, and keep each one as private as the member chose. When I joined, six of its controls did not do what they said.

What I decided

Build the account as a personal gifting record, with a tab for each part of a life of giving, and make every privacy choice hold on the server, not only on the screen.

Build the account as a personal gifting record, with a tab for each part of a life of giving, and make every privacy choice hold on the server, not only on the screen.

Result

Shipped in the private beta: gifting, occasions, connections and gift history in one place, visibility you set per person, and five data leaks closed.

Shipped in the private beta: gifting, occasions, connections and gift history in one place, visibility you set per person, and five data leaks closed.

The account

Not a settings page. A record of everyone you give to, and everything you gave.

Not a settings page. A record of everyone you give to, and everything you gave.

Not a settings page. A record of everyone you give to, and everything you gave.

Most accounts store a password and an address. DADO’s holds a member’s gifting life: what they gave, who they give to, the dates that matter and what they would love. I lead the whole account. Here it is, tab by tab.

01

My Gifting

My Gifting

My Gifting

Every wish a member runs, every gift they chipped in on, and the drafts they haven’t sent yet. Wishing, contributing and drafts sit in one list, so nothing they started gets lost.

Wishing

Contributing

Drafts

worldofdado.com

A walkthrough on staging: My Gifting, the occasions calendar, wishlists and account security. Parts showing colleagues or personal details were cut.

02

Occasions & Events

Occasions & Events

Occasions & Events

Not a plain calendar or a reminder list. An occasion is a date worth remembering. An event is a time and a place. Members add, change and delete their own, and can host an event by inviting other members, or people who aren’t on DADO yet.

Occasion: a date worth remembering

Event: a time and a place

Invite members and non-members

Adding an event on staging: the type, who it’s for, a location, a time zone and custom details, then an invitation that joins their calendar when they accept.

03

Connections

Connections

Connections

Add people the way you would on any social app, then mark the ones who matter most as close connections. You can add someone who isn’t on DADO yet. When they join, their account links to everything you saved about them. Each person gets a private note that only you can see, better than a phone’s contact card.

Important occasions

Wishlist

Gifting

Preferences & sizes

Family info

Profile

The connection profile screens and tabs were built with Anchal.

worldofdado.com
My Connections with relationship tabs; colleague photos and names blurred

My Connections as shipped, filtered by close connections, family, friends and colleagues. Colleagues blurred.

04

Gift history

Gift history

Gift history

A memory album of gifts, given and received, on DADO or anywhere else. Log a gift adds one from outside DADO, so the record stays complete. From a gift, a member can send another member a thank-you card with a personal message.

Timeline

Log a gift

Thank-you cards

worldofdado.com

Gift history on staging: the timeline, a closed wish, logging a gift from outside DADO and a thank-you card.

05 to 07

Wishlists, Saved and Account details

Wishlists, Saved and Account details

Wishlists, Saved and Account details

The quieter tabs that make the rest work: what a member wants, what caught their eye, and the facts about them that a good gift depends on.

05

Wishlists

Wishlists from DADO and from other platforms, kept together in one place.

06

Saved

Pieces saved while browsing DADO, kept apart from what a member wishes for.

07

Account details

Important dates, preferences and sizes, family information and the DADO profile. Each occasion and preference field carries its own audience.

08

Preferences

Preferences

Preferences

Every part of the profile has an audience. Contact info can be seen by Only me, Close connections or Connections. Important occasions and preference fields carry their own audience, set on each item.

Only me

Close connections

Connections

The owner sets it
Profile visibility
Choose which sections of your profile your connections can see.
Contact info
Your phone number, email address and date of birth, shown to the connections you choose
Who can see this
Only meOnly the connections you mark as close can see this.Connections
Try it: pick an audience.
What each person gets to see
A connection
Contact info
Phone numberhidden
Email addresshidden
Date of birthhidden
A close connection
Contact info
Phone numberhidden
Email addresshidden
Date of birthhidden
Checked where the data is read, so a direct request gets the same answer.

Profile visibility, rebuilt from the shipped screen. Pick an audience and see what a connection and a close connection get back.

Making the promises real

A record this personal only works if the privacy holds. When I joined, six controls did not do what they said.

A record this personal only works if the privacy holds. When I joined, six controls did not do what they said.

A record this personal only works if the privacy holds. When I joined, six controls did not do what they said.

Most account screens were designed, and few had been checked against the data behind them. A setting hid a name on the page while the server still sent it. Family tabs read fields nothing wrote to. Two-factor lived only in the browser.

The controlWhat the data didWhat it does now
Hide amounts raisedA toggle in the wizard, never saved anywhereSaved with the wish and respected by the public page
Hide contributor namesSaved, then ignored when the page loaded its contributorsEnforced where the page gets its data, so no one can see around it
Family info tabRead from a place no screen ever saved to, so blank for everyoneReads what members actually enter in the Family form
Birthday on a connectionMembers added one, but their connections never saw itShown to connections, behind the same setting as anniversaries
Who did this?Notifications stored only the recipientEvery notification records who caused it, showing only a safe name and photo
Two-factorChecked only in the browser, so a stolen login could skip itChecked on the server for each sign-in, and required to pay or delete the account

Six controls: what the data did when I arrived, and what it does now.

Decisions

Four calls that made the account keep its word.

Four calls that made the account keep its word.

Four calls that made the account keep its word.

Decision 01

Every privacy setting is checked on the server, so a direct request gets the same answer as the screen.

Every privacy setting is checked on the server, so a direct request gets the same answer as the screen.

Every privacy setting is checked on the server, so a direct request gets the same answer as the screen.

Why

Hide contributor names was saved and then ignored. Hide amounts raised was never saved at all. A setting that only hides something on screen still hands the data to anyone who asks the server.

What it cost

Two database changes and a rewritten public lookup. None of it shows in a Figma file. It shows when someone asks the server directly.

worldofdado.com
Account preferences: who can see contact info, and gift reminder channels

Preferences as shipped: who can see your contact info, and where DADO reaches you.

Decision 02

The connection profile now reads what members actually save, so family, occasions and birthdays stop showing blank.

The connection profile now reads what members actually save, so family, occasions and birthdays stop showing blank.

The connection profile now reads what members actually save, so family, occasions and birthdays stop showing blank.

Why

Family and Occasions were blank for every connection, because the profile read fields nothing ever wrote to. Preferences showed six of ten fields. Anchal built the profile screens and tabs (PR #207). I built the data that fills them.

What it cost

Eleven database changes in the first pass. One shared list of family relations now drives the grid, the family screen and who can see what.

What members enter
Family form
saves each family member
Occasions form
saves each dated occasion
→
What the profile looked for
an old spouse field
the family members entered
an old anniversary field
the occasions entered
empty for everyone
shown only as the owner's visibility settings allow
→
What the dossier shows
Connection
Family infoOccasionsPreferences
Nothing here yet
Preference fields shown6 of 10
A birthday is shared only when the member's own setting allows it.

Before and after: the profile read empty fields. Now it reads what members save, within the owner’s own settings.

Decision 03

Every notification now says who caused it, and a thank-you became a card with a page of its own.

Every notification now says who caused it, and a thank-you became a card with a page of its own.

Every notification now says who caused it, and a thank-you became a card with a page of its own.

Why

Notifications saved only who received them, so the bell showed an icon and nothing else. Now each one records who caused it, read through a small profile lookup that returns four fields.

What it cost

My first version exposed whole profiles to anyone named in a notification. I reversed it the same day, so one change became two.

Two kinds of notification
From DADONo person behind it. It leads with its type icon.
Caused by a personThe server records who did it and shows only four safe details, including their name and photo.
Faces blurred here. An anonymous pledge carries no face.
Notifications
All0Mentions0Unread0
Today
Thank You
sent you a thank-you card. Open it to view and download.
Your concierge request is underway
Our team has started on it.
Occasion accepted
added to their calendar.
Similar occasions found
Review them in Occasions and events.
worldofdado.com
The notification bell open over a connection page; names blurred

The bell as shipped, and a thank-you sent on a phone: pick a card, write the note, and the card opens on a page of its own. Names blurred.

Decision 04

I closed five data leaks the afternoon I found them, and moved two-factor from the browser to the server.

I closed five data leaks the afternoon I found them, and moved two-factor from the browser to the server.

I closed five data leaks the afternoon I found them, and moved two-factor from the browser to the server.

Why

A QA pass turned into a security pass. The leaks ranged from phone numbers and shipping addresses to anyone being able to write payment records. I confirmed each one on the live database before fixing it, and checked each fix the same way.

What it cost

None of the 38 users had two-factor on, so I confirmed live that the change locked nobody out. Sessions older than the window now see an error, logged as a follow-up.

The five leaks, what each exposed, and the fix
WhereWhat leakedThe fixStatus
Connection profileWhat leakedAny signed-in user, by adding themselves as a contactThe fixNeeds a connection both people accepted, which cannot be faked.Closed
Personal detailsWhat leakedFull name, phone and birthdate to any signed-in user on a public wishThe fixA display-only lookup that returns four safe fieldsClosed
Invite lookupWhat leakedThe whole wish record, shipping address includedThe fixA fixed list of safe fields, with no shipping address and no minor’s consent recordClosed
Explore pageWhat leakedRecipient addresses to anonymous visitorsThe fixOnly safe fields are returned, never the whole recordClosed
TransactionsWhat leakedAny user could write payment recordsThe fixBrowsers can no longer write payment records. Only the payment processor can.Closed

The five leaks, what each exposed, and the fix. Engineers on the team confirmed every fix. There has been no outside audit.

Also decided

01

A member’s birthday shows on both connection views, behind the one important-dates setting they control.

02

Thank-you cards are saved, notify the giver and open from a private link, so someone without an account can see one.

03

Paying, adding a card and deleting the account all need two-factor confirmed on the server.

04

Setting a default card or address happens in one step that cannot half-fail. Deleting a card also removes it at Stripe.

05

Notification toggles show a toast and revert when a save fails, instead of failing silently.

06

Deactivate and Delete are real actions. Deletion is scheduled, and signing back in cancels it.

Full decision traces available on request.

Outcome

Shipped in the beta. Measured by what can no longer happen.

Shipped in the beta. Measured by what can no longer happen.

Shipped in the beta. Measured by what can no longer happen.

6

account controls made to do what they promise

5

live leaks closed and verified on production

10

preference fields on a connection, up from 6

0

members locked out when two-factor moved

The beta is private, so how members use the account is not measured yet, and there has been no outside security audit.

Reflection

Reading the logic behind each screen found all six broken promises. None of them were visible in Figma.

The team’s 307-case QA workbook, run by twelve people before the beta, logged two of the five leaks on its own.

What I kept

Audit the data before the screens.

Audit the data before the screens.

The dossier was redesigned, and then its tabs turned out empty for a data reason. Next time I would reverse the order.