App Development in Oman: OMR Costs, PDPL Transfer Rules and a 7-Hour Overlap
Founder & Lead Engineer, RAITHub
A first release of a custom web app for an Omani business costs roughly OMR 6,000 to 24,900: 400 to 830 engineering hours at OMR 15 to 30 an hour, about $39 to $78. Oman's Personal Data Protection Law and its 2024 executive regulations govern sending personal data abroad, so settle hosting and access before you sign. A Dhaka team shares about 7 working hours with Muscat.
This guide is for founders, family businesses and product managers in Oman who are pricing a web product: a customer portal, a booking or ordering system, a field-service tool, or an internal dashboard that replaces a spreadsheet. The hour counts are a worked model that shows where the money goes. They are not a quote. RAITHub is a software studio based in Dhaka, Bangladesh, with no office in Oman, and it delivers in English. It builds web apps and progressive web apps (PWAs: web apps a user can add to the home screen and open like an installed app). It does not build native iOS or Android apps. If you searched for a mobile app development company in Oman, the PWA is the scope priced here.
What hourly rates should an Omani company expect from developers?
Published Oman-only rate data is thin, so the fairest benchmarks are global and regional ones, converted to rials. Clutch's software development pricing page says most listed companies charge $24 to $49 an hour, and puts the average reviewed project at about $132,480, which is roughly OMR 51,000. Arc.dev's 2026 survey of 5,302 freelance developers gives the regional spread.
Conversions use OMR 0.385 to the US dollar, the rate Wise's USD to OMR page showed when we checked on 1 October 2026, rounded to one decimal.
| Benchmark | USD per hour | OMR per hour (at 0.385) |
|---|---|---|
| Most software companies listed on Clutch | $24 to $49 | OMR 9.2 to 18.9 |
| Freelancers in South Asia (Arc.dev) | $22 to $55 | OMR 8.5 to 21.2 |
| Freelancers in Eastern Europe (Arc.dev) | $40 to $85 | OMR 15.4 to 32.7 |
| Freelancers in Western Europe (Arc.dev) | $70 to $120 | OMR 27.0 to 46.2 |
| Freelancers in the US and Canada (Arc.dev) | $82 to $130 | OMR 31.6 to 50.1 |
An hourly figure on its own tells you little. Two vendors at the same rate can quote totals that differ by a factor of two, because one has priced a smaller scope, fewer tests or no admin panel. Compare the hours and the exclusions, not the rate. The Saudi Arabia cost guide runs the same exercise in riyals if you are also selling into the Kingdom.
What does a custom web app cost in Oman, item by item?
Take a typical first release: one main workflow, two or three kinds of user, an admin area, card and local debit payments through a gateway, and an interface in Arabic and English. The model below puts that at 400 to 830 hours. At OMR 15 an hour the total is OMR 6,000 to 12,450; at OMR 30 an hour it is OMR 12,000 to 24,900.
| Work item | Hours (model) | At OMR 15/hour | At OMR 30/hour |
|---|---|---|---|
| Discovery workshops and a written specification | 30 to 50 | OMR 450 to 750 | OMR 900 to 1,500 |
| Accounts, login and user roles | 40 to 80 | OMR 600 to 1,200 | OMR 1,200 to 2,400 |
| The main workflow (orders, bookings, jobs or applications) | 120 to 240 | OMR 1,800 to 3,600 | OMR 3,600 to 7,200 |
| Admin area, exports and reports | 40 to 90 | OMR 600 to 1,350 | OMR 1,200 to 2,700 |
| Gateway payments, webhooks and refunds | 50 to 110 | OMR 750 to 1,650 | OMR 1,500 to 3,300 |
| Arabic right-to-left layouts and two-language content | 40 to 100 | OMR 600 to 1,500 | OMR 1,200 to 3,000 |
| Automated tests, including both text directions | 60 to 120 | OMR 900 to 1,800 | OMR 1,800 to 3,600 |
| Environments, deployment pipeline and monitoring | 20 to 40 | OMR 300 to 600 | OMR 600 to 1,200 |
| Total | 400 to 830 | OMR 6,000 to 12,450 | OMR 12,000 to 24,900 |
What moves a project toward the upper end: a second workflow, links into an ERP or government system you do not control, and a scope that keeps changing after the build starts. What the model leaves out: translation and copywriting, paid subscriptions such as email or maps, and monthly running costs like hosting and gateway fees. A written specification is the lowest-cost way to keep a quote honest; how to write an MVP spec for an agency shows what to put in it. For a quick range on your own feature list, try the MVP cost estimator.
Why does rial money need three decimal places in the database?
One Omani rial is 1,000 baisa, and ISO 4217 assigns the rial 3 minor-unit digits where the dollar has 2 (ISO 4217 code list). Software written around cents quietly turns OMR 4.125 into OMR 4.13. On one order that is 5 baisa; across thousands of orders, refunds and VAT lines it becomes a reconciliation problem that your accountant finds before you do.
A safe pattern is to store whole baisa as an integer and let the runtime tell you how many digits each currency has, rather than hard-coding 2:
-- PostgreSQL: amounts are integer minor units (baisa for OMR, cents for USD).
CREATE TABLE payment (
id bigserial PRIMARY KEY,
currency char(3) NOT NULL CHECK (currency IN ('OMR', 'USD')),
amount_minor bigint NOT NULL CHECK (amount_minor >= 0),
created_at timestamptz NOT NULL DEFAULT now()
);
// TypeScript: Intl already knows OMR has 3 decimals and USD has 2.
function minorDigits(currency: string): number {
return new Intl.NumberFormat('en', { style: 'currency', currency })
.resolvedOptions().maximumFractionDigits ?? 2
}
export function formatMinor(amountMinor: number, currency: string): string {
const major = amountMinor / 10 ** minorDigits(currency) // display only; never store this
return new Intl.NumberFormat('en', { style: 'currency', currency }).format(major)
}
formatMinor(4125, 'OMR') // "OMR 4.125"
formatMinor(4125, 'USD') // "$41.25"
Keep arithmetic on the integers and only divide for display. Before go-live, test edge amounts such as OMR 0.001 and a full refund of a discounted order, and read your gateway's documentation for the unit it expects, since some take decimal strings and some take minor units. Testing payments and webhooks covers the failure cases worth automating.
On proof: RAITHub has shipped Stripe rent collection in PropDesk, and bKash, Nagad, SSLCommerz and cash on delivery in TheSkinProof, which is the founder's own marketplace venture rather than a client project. It has not integrated an Omani payment gateway or local debit network. That work would be quoted as new, reusing the same habits: the webhook decides the order state, every handler can safely run twice, and money stays in integers. For card and buy-now-pay-later options across the Gulf, see the GCC checkout guide.
What does Oman's PDPL say about sending data to an overseas developer?
This is general information, not legal advice. Confirm the current position with your adviser and the regulator, the Ministry of Transport, Communications and Information Technology (MTCIT). The points below come from the English translations published on qanoon.om, which are unofficial; the Arabic text is what counts. We checked Article 37 against the Arabic text of Ministerial Decision 34/2024 on 1 October 2026.
The Personal Data Protection Law, issued by Royal Decree 6/2022, was published in the Official Gazette in February 2022 and took effect a year later, with MTCIT as the ministry in charge. Its Article 23 lets a controller transfer personal data outside the Sultanate "according to the controls and procedures determined by the regulation", and forbids a transfer where the data was processed in breach of the law or where the transfer would harm the person concerned.
Those controls arrived in the executive regulation, Ministerial Decision 34/2024, dated 28 January 2024 and in force from the day after its Gazette publication in early February 2024. The decision gave organisations one year to bring their processing into line. In the translation, the transfer provisions sit in Articles 37 to 40:
| Provision (per the qanoon.om translation) | What it asks for | What it means for a build contract |
|---|---|---|
| Article 37: basis for the transfer | Explicit consent for transfers outside Oman, and no harm to national security or the state's higher interests; the Arabic text lists two exceptions to consent: a treaty obligation, or data anonymised so no one can be identified | Ask your adviser which basis covers your users; synthetic or anonymised test data may avoid the question for development work |
| Article 38: level of protection | The overseas processor must protect the data at a level no lower than the law requires | Put security measures, confidentiality and deletion on exit into the processing agreement |
| Article 39: transfer assessment | An assessment covering the type, volume and sensitivity of data, the purpose, how long and how often, the route it takes, and the risks to individuals | Your vendor should help you fill this in with a plain data-flow diagram |
| Article 40: the Ministry can ask | MTCIT may request the assessment reports | Keep the assessment current as features change, not only at kickoff |
Two more timings from the regulation shape your vendor contract. Article 30 requires a breach that threatens individuals' rights to be reported to the Ministry within 72 hours of discovery, and Article 32 requires affected individuals to be told within 72 hours where the breach causes serious harm or high risk. So the contract should oblige your developer to tell you much sooner than that. The law itself sets fines that climb to between OMR 100,000 and 500,000 for the most serious offences under Article 29. MTCIT also publishes a self-assessment for controllers and processors on its site, which is a sensible starting checklist.
RAITHub signs data processing agreements and standard contractual terms and works within your controls. It does not claim to meet the PDPL for you; that duty stays with the controller.
How can an offshore team build the product without touching Omani personal data?
Mostly by keeping real data out of the development loop. What follows is engineering practice, not a legal reading; whether remote support access counts as a transfer in your case is for your adviser.
- Decide the hosting country with your adviser first. Hosting in a neighbouring Gulf region is still hosting outside Oman. AWS, for example, lists regions in Bahrain and the UAE (AWS Regions), and each is a separate country from the law's point of view.
- Production belongs to you. The cloud account, domain and database are in your name; the team deploys through a pipeline whose keys you can rotate.
- Generated data in every non-production environment. Seed scripts create realistic but fake customers, so staging never holds a copy of production.
- Row-level controls where staff roles differ. The Postgres row-level security guide shows how the database itself can refuse rows a role should not see.
- Break-glass access only. If an incident needs production, you approve a time-boxed login and it is logged.
Larger Omani buyers, banks and government-linked companies will ask about these controls in procurement. Answering a first security questionnaire without SOC 2 helps you give honest answers.
Is a Dhaka team a practical choice for a company in Muscat?
For many web products, yes. Oman runs on UTC+4 and Dhaka on UTC+6, and neither uses daylight saving, so with a 9:00 to 18:00 day in both cities the two teams overlap for about 7 hours, from 9:00 to 16:00 Muscat time. That is enough for a morning stand-up, same-day review of a staging build and a live call when something is unclear. The working week is agreed per client, so it can follow your company's week.
| Question | Agency in Oman | Team in Dhaka |
|---|---|---|
| Shared hours with Muscat | The whole day | About 7 hours, with a written handoff at the end of each day |
| Face-to-face workshops and Arabic-speaking staff | Normally possible | Video calls only; delivery in English |
| Cross-border transfer paperwork | Less, if the team and hosting stay in Oman | A transfer assessment and a processing agreement, agreed with your adviser |
| Tenders that require a local vendor | Eligible | Usually not eligible |
| Main driver of the final bill | Scope discipline | Scope discipline and clear written specs |
If you are weighing any Bangladesh vendor, the checks in is it safe to hire a software agency in Bangladesh apply, and working with an offshore team from the UAE describes a Gulf routine that transfers well to Muscat. Arabic interfaces need their own test pass; the Arabic RTL QA checklist lists it. RAITHub builds and tests right-to-left layouts but does not write or translate Arabic copy.
Why RAITHub for this
- Money handling that has run in production. Stripe in PropDesk; bKash, Nagad and SSLCommerz in TheSkinProof; 9 payment gateways in PadhAI. An Omani gateway would be new for RAITHub and priced that way.
- Tests written with the code. TheSkinProof has 750+ automated tests over 217 API endpoints, and PropDesk has 1,024. Baisa rounding and both text directions get dedicated cases.
- Permission models built before. Sundor Skin uses 146 PostgreSQL tables with row-level security, 88 permission codes and 12 staff roles, the kind of design that keeps a vendor's view of your data narrow.
- Seven shared hours. Enough overlap with Muscat for daily decisions, plus written handoffs for the rest.
- A fixed, written quote. A free 15-minute technical audit first, then scope, assumptions and exclusions in writing. You own the code and IP, under an NDA.
When you don't need us
- Your product has to be a native iOS or Android app. RAITHub builds web apps and PWAs only; hire a mobile team.
- You want the project run in Arabic, or Arabic copy written for you. RAITHub delivers in English.
- A tender or ministry contract requires an Omani-registered vendor or people on site in Muscat.
- Procurement demands certifications. RAITHub holds no SOC 2 or ISO 27001 certificate.
- You need someone to interpret the PDPL. That is work for an Omani data protection lawyer, not a software studio.
- A ready-made product fits. If an existing booking, store or CRM service covers your process and accepts local payments, subscribe instead of building.
To price your own scope, read about the MVP development service and then book the free 15-minute technical audit. Bring a description of your main workflow, the payment methods your customers use, and your adviser's view on where the data should live.
Last reviewed: 1 October 2026. Rate benchmarks and the exchange rate checked on 1 October 2026. Legal points are general information from unofficial English translations on qanoon.om; confirm them with your adviser and MTCIT.
Frequently asked questions
How much does app development cost in Oman?
For a first release of a custom web app with one main workflow, gateway payments and Arabic and English screens, an illustrative model gives 400 to 830 hours, or roughly OMR 6,000 to 24,900 at OMR 15 to 30 an hour. Translation, subscriptions and hosting are extra.
Does RAITHub build mobile apps for Omani companies?
No. RAITHub builds web apps and progressive web apps, which open in the browser and can be added to a phone's home screen. Native iOS and Android apps need a mobile specialist.
Which law governs personal data in Oman?
The Personal Data Protection Law issued by Royal Decree 6/2022, with its executive regulation in Ministerial Decision 34/2024. The Ministry of Transport, Communications and Information Technology oversees it. This is general information; confirm details with your adviser.
Can an Omani company use a developer in Bangladesh?
It can, if the transfer rules in the executive regulation are met. As translated on qanoon.om, they include a basis such as consent, a transfer assessment and protection no lower than Omani law. Giving the team synthetic data and keeping production in your own account reduces what leaves Oman.
How quickly must a data breach be reported in Oman?
Per the translated executive regulation, within 72 hours of discovery to the Ministry, and within 72 hours to affected individuals where the breach causes serious harm or high risk. Your vendor should be contractually bound to alert you well before that.
How many hours does a Dhaka team overlap with Muscat?
About 7 hours, from 9:00 to 16:00 Muscat time, assuming a 9:00 to 18:00 day in both cities. Neither city uses daylight saving, so the overlap stays the same all year, and the working week is agreed per client.
Related posts
Ready to discuss your project?
Book a free 15-minute technical audit with our engineering team.