Published
AvaFin - Lending App for a KNF-Supervised Lender
- Pull requests
- Nearly 500
- Tickets
- 430+
- Integrations
- 9
- Domain modules
- 13
Case study: AvaFin Poland mobile app
Project summary
In January 2026 AvaFin asked Order Group to build a native mobile app for iOS and Android, starting from an empty repository. The app has to cover the whole customer journey while consumer credit rules are changing. The EU Consumer Credit Directive (EU) 2023/2225, known as CCD2, is due to apply from 20 November 2026 and changes pre-contractual information, creditworthiness assessment and the rules for selling credit online. Work on the Polish implementing bill was suspended in May 2026, so the 2011 Consumer Credit Act still applies in Poland and the final Polish rules are not known yet. The loan application flow could not be hard-coded into an app released once every few weeks. The work runs as continuous development, with no end date.
AvaFin Holding was founded in 2012 and changed its name from CreamFinance to AvaFin in 2023. According to AvaFin, the group had 1.6 million customers in five markets in Europe and Latin America in 2024. It has operated in Poland since 2013, earlier under the Lendon brand. The Warsaw-based AvaFin Poland sp. z o.o. is a lending institution under Polish law, supervised by KNF. As of 8 October 2026 it offers short-term loans of PLN 500 to 15,000 for 30 days (up to PLN 5,000 for a first loan). A first instalment loan goes up to PLN 30,000 over 36 months.
The market has also consolidated. According to the Polish Union of Entrepreneurs and Employers (ZPP), the number of active lending institutions fell from about 500 to about 100 after Poland's anti-usury law, and about 80% of non-bank loan applications are rejected. The lenders who remain compete on the quality of their digital channel.
Four areas of the AvaFin app
One app from the calculator to repayment
The app leads a guest from the calculator and registration, through the application and account verification, to the customer panel. Order Group is responsible for the mobile app and its integrations, and the app connects to AvaFin's central system. The project is part of our fintech software development work.
- The native app for iOS and Android is built in React Native and Expo, with one team and one codebase for both platforms.
- The calculator works for guests and logged-in customers: amount, period, cost, APR, repayment date and promo codes. Prices come from the same pricing engine as the central system, so the amount in the app is the amount in the agreement.
- Registration runs in a multi-step wizard with an SMS code for the phone number and address suggestions.
- The customer panel shows the amount to repay, the due date or days overdue, the available limit and the loan history with PDF documents, and lets customers repay, request overpayment refunds and accept extension offers.
- Self-service replaces the hotline: customers request changes to their phone number, address, employment, income or bank account, and the home screen reminds them about unfinished requests.
- Customers can reach support from every screen, including offline and from the app's PIN screen, with Genesys chat built into the app.
- Push notifications open the right screen directly through deep links.
A loan application flow driven by the central system
In many lending apps the order of the application steps lives in the app's code. Any change to the process, even one new field required by law, means a new version, app store review and waiting until customers update. In AvaFin's app the central system decides the order of the steps. After each step the app fetches the current state and works out what to show next.
- Two flows run on one engine: the first loan after registration and a repeat loan for an existing customer.
- AvaFin changes the order or scope of the steps in its central system, and the app picks the change up at the next step, with no new app version.
- The application analysis screen polls for the decision and matches it to the right loan, even for customers with a long loan history.
- When a change has to go into the code, a forced update driven by a version threshold in Firebase Remote Config makes sure customers get the new version.
When the Polish rules implementing CCD2 are settled, AvaFin can adjust the application flow in its central system instead of waiting for app store review of a new version.
Bank account verification and the first loan inside the app
Account verification is one of the steps where lending apps lose applicants. In AvaFin's app the customer chooses one of two ways, and the app follows the status and keeps them moving even when something goes wrong.
- Kontomatik lets the customer log in to their bank and share the account history, during registration, in the application and when changing the account in the profile.
- Autopay offers a verification transfer instead, and the same gateway later handles repayments.
- The app monitors the verification status and handles failures and timeouts, so the application stays open.
- Fraud prevention with RiskIdent DEVICE IDENT on the first application is built and, as of October 2026, in testing. The device identifier contains no personal data.
- Every integration goes through a data mapping layer, so a change in a partner's API does not spread across the whole app.
Consent and privacy built into the architecture
A lending app uses analytics, campaign attribution and third-party SDKs, and it processes customers' financial data. In AvaFin's app no third-party tool sends data before the customer makes a choice.
- Consent works on three layers: App Tracking Transparency on iOS, the Usercentrics platform for each SDK separately and the consents stored in AvaFin's system.
- Firebase Analytics, Crashlytics and AppsFlyer are switched off natively from app launch and switched on only after the app reads the user's decision.
- Product analytics uses a closed catalogue of events that excludes personal data and anything the customer types.
- Marketing consent is separate for email, SMS, phone, the customer panel and push.
- A GDPR screen in the app covers access to data, rectification, restriction of processing, objection, withdrawal of consent and erasure.
- Every branch of the consent logic is covered by tests.
Security that stays out of the customer's way
The customer logs in once, and after that a PIN or biometrics is enough. Extra confirmation appears only for sensitive operations, and customer data does not leak through the app switcher or a shared phone.
- After login the app uses a PIN and biometrics, and credentials are kept only in the phone's secure storage.
- Before a sensitive operation the customer confirms their identity again on the current screen.
- A privacy screen covers the app when it moves to the background.
- External content (payments, Kontomatik, chat, documents) opens in a secured WebView with an allowlist of domains and HTTPS only.
- The chat is isolated: the conversation is cleared when another customer logs in on the same device.
- Backend error messages never reach the customer directly; the app shows translated, safe messages instead, and offline mode keeps the support contact available.
- Keys and secrets stay out of the code and are injected during the build.
Why build with us: how the team works
The Order Group team works in short pull requests, and every merge automatically builds and distributes a test version for both platforms. The architecture and quality rules are written down in the repository and enforced by checks on every commit and pull request.
- The stack is Expo, React Native, React 19, TypeScript, Redux Toolkit with RTK Query and Expo Router, with the React Compiler switched on.
- The architecture is modular: 13 domain modules, with domain models separated from API contracts.
- Every commit passes formatting, lint and type checks, and every pull request runs lint, TypeScript and unit tests in CI.
- GitHub Actions, Fastlane and EAS send test versions to Firebase App Distribution and TestFlight after every merge, and a weekly check of Apple certificates sends an alert to Slack.
- 25 technical documents in the repository keep product knowledge independent of any single person.
- A dedicated two-day QA pass before release logged a batch of about 50 tickets.
- The same way of working serves another lending client: we have developed the Aasa24 app continuously since 2023.
Answered by the team behind the AvaFin app
Building a lending app: questions we hear
-
Yes, if the backend sets the order of the steps and the app only renders the current state. In AvaFin's app a change to the application path in the central system needs no update in the App Store or Google Play.
-
The application flow, pre-contractual content and messages should be driven from the backend, and the team must ship changes in days. The directive is due to apply from 20 November 2026, and work on the Polish implementing bill was suspended in May 2026, so the final shape of the rules in Poland is still unknown.
-
Through access to the account history (Kontomatik in AvaFin's app) or a verification transfer (Autopay in AvaFin's app). It is worth giving customers both options and handling failures without losing the application.
-
Analytics and attribution SDKs must be off at launch and switched on only after consent. In AvaFin's app consent works on three layers: ATT, Usercentrics and the consents stored in AvaFin's system.
-
Yes. AvaFin's app runs on Expo and React Native with secure credential storage, biometrics and a secured WebView, and Order Group has used the same stack in the Aasa24 app since 2023.
-
As a permanent team developing the mobile app since the first commit in January 2026, with test versions distributed automatically after every merge.
Related case studies
More fintech and mobile work
-
Monetor - A Web Application for Analysing Business FX Risk
The team is doing a tremendously good job and they are evolving with us throughout the process.
-
BizBot - There's No Successful App Without Solid UX
Order Group invests time to define the scope and ask clarifying questions. Their channels of communication lead to smooth remote project management.
-
RAW Cyber - Secure Custom Android Operating System
Even with the challenging demand, the team was able to provide designs and other OS features already. The team managed to deliver on time and they understand the specifics of the security industry.
Planning a lending app?
SO FAR WE HAVE WORKED WITH BRANDS LIKE:
Thank you for your message.
We read every message ourselves and get back to you within 48 hrs on business days.
Something urgent? hello@ordergroup.co