Custom Kiosk Software Development

Kiosk software for one unattended transaction that recovers.

We build a bounded self-service workflow around session reset, accessibility, identity, catalogue or booking lookup, scanning, peripherals, payment handoff, printing or dispensing, offline state, remote configuration, health monitoring, support, and reconciliation. The operator, hardware and payment vendors, security teams, and advisers own identity, age, payment, safety, accessibility, privacy, regulatory, and service decisions.

50 Search evidenceStarts at $35K Focused first releaseAdjacent proof Evidence boundary

The problem

Sound familiar?

  • Does a disconnected scanner, printer, terminal, API, or network leave the public screen stuck with no safe recovery path?

  • Can operations see which unit, application version, peripheral, session, transaction, receipt, and backend record belong to an incident?

Short answer

Kiosk software runs a bounded self-service transaction on managed hardware, resets each public session, coordinates peripherals and backend systems, handles offline and failure states, and reports fleet health remotely. Compatibility must be proven on target devices. RaftLabs scopes one device profile and workflow first, starting at $35,000 over 12 to 16 weeks.

The payment completed. The kiosk printed an error.

The terminal approved the charge, the printer disconnected, and the kiosk retried the whole transaction when the user tapped again. Operations saw two backend records and no usable receipt. An unattended flow needs explicit device and transaction states, idempotency, recovery, session cleanup, and remote evidence.

Adjacent device and transaction evidence

10,000
transactions in three months
Mobile POS case, not kiosk hardware
Under 10 MB
offline-capable sync utility
Gas-station operations case
$35K
starting focused kiosk release
One device profile and workflow

The mobile POS case proves payment software delivery, while the gas-station operations case demonstrates a lightweight offline-capable edge utility. Neither was a public kiosk. These examples do not guarantee hardware, peripheral, payment, certification, uptime, unattended operation, accessibility, security, or fleet outcomes.

Build a kiosk when one self-service transaction, target device, environment, and support model are already defined.

A tablet web page is not automatically an unattended system; the device, application, peripherals, backend, fleet, and operations form one product.

A fit
01

A repeated self-service flow benefits from fixed hardware and must run with limited staff intervention across one or more locations.

02

Operations, IT, security, privacy, accessibility, payments, facilities, support, and product owners can approve release.

03

Target hardware plus representative users, disconnects, peripheral faults, reboots, abandoned sessions, transactions, and support cases are available.

Not a fit
  • A responsive web page on a staffed tablet covers the need, or hardware, environment, workflow, and operational ownership are still unknown.
  • The request assumes an operating system, terminal, reader, printer, scanner, enclosure, or vendor works without device-level proof.
  • The operator expects software alone to guarantee uptime, accessibility, identity, payment, safety, security, compliance, or labour savings.

Choose the interface by the operating environment

NeedBest fitPrimary boundary
Personal device with a signed-in userMobile or web appUser-owned device, browser or app lifecycle, account, and network
Staff-operated fixed terminalPOS or staff workstationTrained operator, supervised peripherals, shift controls, and support
Public unattended self-serviceKiosk systemSession isolation, managed device, peripherals, failure recovery, fleet health, and staff fallback
Telemetry and control across embedded assetsIoT platformProvisioning, device identity, data, commands, fleet state, updates, and operations

Scope

What belongs in one unattended transaction

  • 01
    Session, privacy, and accessibility
    Start from a clean state, state the task and limits, support required language and accessibility modes, minimise data, time out safely, confirm cancellation, clear local and visible personal information, and prevent the next user from seeing prior state.
  • 02
    Managed device and application lifecycle
    Configure supported single-purpose mode, auto-launch, health check, application and operating-system version, signed update, maintenance window, rollback, reboot, storage limits, remote configuration, logs, and authorised service access on target hardware.
  • 03
    Peripheral and backend adapters
    Isolate scanner, printer, terminal, reader, camera, dispenser, or sensor drivers from the core workflow. Track connection, readiness, job, acknowledgement, error and recovery, then reconcile each device event with the backend record.
  • 04
    Transaction and offline state
    Use stable session and transaction keys, explicit state transitions, local encryption where approved, bounded offline operations, retry without duplication, confirm backend status, issue receipts only from known state, and route ambiguity to staff.
  • 05
    Fleet monitoring and support
    Show unit, site, app and OS version, connectivity, peripheral health, queue age, storage, restart, update, transaction and reconciliation failures. Alert named owners and provide safe staff intervention, evidence, recovery, and escalation.

How it works

From target hardware to one recoverable self-service workflow

  1. Phase 1
    01

    Define transaction, device, and ownership

    Choose one use case, environment, users, session, hardware profile, peripherals, backend systems, offline limits, accessibility, support model, owners, risks, and acceptance measures.

  2. Phase 2
    02

    Prove hardware and failure states

    Test exact devices, operating-system builds, drivers, SDKs, payment certification, scanners, printers, network loss, power loss, idle reset, accessibility, tamper cases, remote management, and vendor support.

  3. Phase 3
    03

    Build the bounded kiosk system

    Implement session state, managed mode, application flow, peripheral adapters, backend integration, approved payment handoff, offline behaviour, reset, role access, logs, monitoring, update, recovery, and reconciliation.

  4. Phase 4
    04

    Soak test, deploy, and hand over

    Run repeated and adverse sessions on target hardware, test accessibility, payments, peripherals, disconnects, reboots, updates, support, fleet alerts, reconciliation, rollback, training, and staged rollout.

Risk

What the kiosk contract must settle

Exact hardware
Operating-system name is not enough. Confirm model, build, drivers, ports, power, enclosure, cooling, orientation, peripherals, SDKs, certifications, device management, supply, warranty, and vendor support.
Public session
Protect the previous user's data, constrain navigation and input, prevent unsafe system access, minimise retained information, handle abandonment, reset visibly, and provide accessible staff help.
Payments and identity
Providers and qualified advisers own merchant, payment, identity, age, privacy, security, regulatory, liability, and evidence decisions. Implement only approved certified paths and operational controls.
Unattended recovery
Network, backend, terminal, scanner, printer, dispenser, storage, application, operating system, and power will fail. Define safe behaviour, reconciliation, remote evidence, alert, restart, rollback, and staff fallback.

Scope and price

A focused kiosk system starts at $35,000.

Start with one target device profile, one self-service flow, a bounded peripheral set, one backend integration, recovery, monitoring, reconciliation, and staffed support.

Starts at $35,000

A focused release usually takes 12 to 16 weeks. Payments, identity hardware, several device models, dispensing, certification, or large fleets increase scope.

Unlike a web app, kiosk software owns the public session, managed device, peripherals, offline state, recovery, fleet evidence, and staff fallback.

No hardware or uptime guarantee

RaftLabs proves the contracted flow on agreed target devices. Vendors and operators own hardware supply, networks, facilities, payment services, maintenance, support, and availability.

Failure is designed

Disconnect, decline, jam, empty paper, scanner loss, backend timeout, reboot, abandoned session, update failure, duplicate event, and uncertain transaction belong in acceptance.

Stay on topic

More on IoT & connected devices

Kiosk software questions

A focused kiosk release may include session reset, managed device mode, touch-first flow, accessibility, identity or booking lookup, scanning, payment handoff, receipt or label printing, offline state, remote configuration, health monitoring, update and rollback, support tools, audit, and reconciliation. Scope depends on the exact hardware and environment.

We confirm the exact model, operating-system build, enclosure, display, ports, drivers, SDKs, scanner, printer, terminal, camera, reader, network, remote-management agent, certifications, and vendor support. A listed operating system or past peripheral category does not guarantee another device. Target hardware is tested before production scope is locked.

Only if the selected payment provider, terminal, market, merchant account, certification, risk settings, and transaction type explicitly support it. The provider and operator define limits, authorisation, storage, settlement, reversal, and liability. We implement and test the approved path; we do not promise offline acceptance or PCI compliance by software alone.

Define safe local state, user message, retry, timeout, cancellation, receipt, backend idempotency, reconciliation, session cleanup, application restart, device reboot, remote alert, and staff fallback for each step. Never claim success without confirmed state, and never expose the prior user's information after reset or recovery.

A first release starts at $35,000 and usually takes 12 to 16 weeks. It covers one device profile, self-service flow, peripheral set, backend integration, managed mode, offline and recovery states, remote configuration, monitoring, reconciliation, and handover. Payments, identity devices, several hardware models, dispensing, certification, or large fleets increase scope.

Work with us

Bring the target hardware, self-service flow, environment, and failure cases.

Share device models, operating systems, enclosure, peripherals, payment provider, backend, connectivity, accessibility, privacy, session limits, deployment, fleet, support, and owners.

  • Scope and cost agreed before work starts. No surprises. No obligation.
  • Working prototype within 3 weeks of kickoff.
  • Pay by milestone. You see progress before each invoice.
  • 60-day post-launch warranty. Bug fixes, UI tweaks, and deployment support. No retainer.
  • All conversations are NDA-protected.