Żappka Fintech
Buy Now Pay Later and credit card features built into Żappka, the Żabka retail app used by 8 million people in Poland. Delivered together with PKO Bank Polski, with the bank reviewing the security of every release.
The challenge
Adding lending and card products to an app with 8 million users makes every defect expensive: a bug that hits 0.1% of sessions means thousands of people locked out of a payment. Consumer credit is regulated, so the mobile client is part of the compliance surface, not just a frontend, and the retail app could not degrade while the financial features shipped underneath it.
Our approach
Payment flows are state machines with money attached, so we built them in SwiftUI and The Composable Architecture, where every state transition is explicit and testable. Under them sits a client-side security layer: RSA-encrypted payloads, JWT authentication with signature verification, token rotation, and Keychain-backed storage. Every path was designed backwards from its failure modes, including 3DS step-up, declines with a clear next step, and retries that never double-charge.
The outcome
BNPL and a credit card issued with PKO Bank Polski shipped to production inside an app used by 8 million people, with each release passing the bank's security review.