RANAPAY INDIA PRIVATE LIMITED
GIFT CARD ISSUANCE & PRODUCT GOVERNANCE POLICY
POLICY NO. 06 | VERSION 1.0
EFFECTIVE DATE: 29 SEPTEMBER 2026
| Document Control | Details |
|---|---|
| Company | RANAPAY INDIA PRIVATE LIMITED |
| CIN | U72900UP2021PTC140275 |
| Registered Office | D30, Vibhuti Khand, Gomti Nagar, Lucknow, Uttar Pradesh – 226010 |
| Website | ranapay.in |
| Business Context | Gift Cards, Gift Vouchers & Virtual Gift Products through applicable authorised/regulated partners |
| Policy Owner | Product / Compliance / Operations |
| Review Frequency | At least annually / event driven |
| Classification | Confidential – Controlled Compliance Document |
1. PURPOSE
This Policy establishes the governance framework for designing, approving, launching, issuing, distributing, activating, redeeming, monitoring, modifying and retiring gift cards, gift vouchers and virtual gift products offered by RanaPay through applicable authorised or regulated partners.
2. REGULATORY ROLE PRINCIPLE
RanaPay shall clearly distinguish its role from the role of the PPI issuer, bank or other regulated entity. Where a product involves regulated issuance or stored-value functionality, the relevant authorised entity shall be identified and the product shall operate within the approved contractual and regulatory structure.
3. OBJECTIVES
- Ensure every product has documented ownership and approval.
- Prevent unauthorised or misleading product issuance.
- Define product terms, limits and customer journey.
- Integrate fraud, security, KYC and customer-protection controls.
- Control changes to live products.
- Maintain complete product and issuance records.
- Ensure orderly suspension or retirement.
4. SCOPE
This Policy covers physical and virtual gift cards, gift vouchers, e-vouchers, brand-specific vouchers, digital codes and related products handled through RanaPay's approved business and partner arrangements.
5. PRODUCT CLASSIFICATION
- Gift Card
- Gift Voucher
- Virtual Gift Card
- Digital Voucher / E-code
- Brand-specific product
- Partner-issued product
- Other approved stored-value or prepaid-related product
The classification shall identify whether the product is regulated, non-regulated, partner-issued or otherwise subject to specific contractual requirements.
6. PRODUCT OWNERSHIP
Each product shall have a designated Product Owner responsible for maintaining product documentation, coordinating approvals, monitoring performance and initiating review when material changes occur.
7. NEW PRODUCT APPROVAL
- Prepare product proposal.
- Identify issuer/partner and regulatory role.
- Complete legal/compliance assessment.
- Define customer journey and terms.
- Assess fraud, security and operational risks.
- Confirm settlement and reconciliation process.
- Obtain required management/partner approvals.
- Complete technical testing.
- Approve launch.
8. PRODUCT DOCUMENTATION
- Product description
- Issuer/partner details where applicable
- Denomination/value
- Validity/expiry
- Activation rules
- Redemption rules
- Usage restrictions
- Refund/cancellation terms
- Customer support process
- Fraud controls
- Settlement model
- Technical/API dependencies
9. ISSUANCE PROCESS
Gift cards/vouchers shall be issued only through approved systems and partner arrangements. Issuance controls shall prevent duplicate, unauthorised, invalid or inconsistent product creation.
- Unique product/code/reference
- Authorised issuance source
- Transaction/reference record
- Applicable value
- Activation status
- Creation timestamp
- Partner/merchant reference
10. ACTIVATION
Where activation is required, activation shall occur only after the applicable transaction and system checks are completed. The system shall maintain an auditable activation status.
11. REDEMPTION
Redemption shall be processed according to product terms and applicable partner rules. Duplicate, expired, blocked or already-redeemed instruments shall be rejected or escalated according to the defined process.
12. VALUE / LIMIT CONTROLS
Applicable denomination, transaction, velocity or other limits shall be defined by the approved product structure, applicable partner rules and law. Limits shall not be changed without appropriate approval.
13. CUSTOMER TERMS & DISCLOSURES
Customers shall receive clear information on value, validity, redemption, restrictions, refunds/cancellation, customer support and applicable issuer/partner information where required.
14. FRAUD CONTROLS
- Secure code generation
- Controlled issuance
- Velocity controls
- Duplicate detection
- Redemption monitoring
- Suspicious activity escalation
- Compromised-code handling
- Partner fraud coordination
15. KYC / CUSTOMER ELIGIBILITY
Where KYC, age, customer eligibility or other verification requirements apply, the product journey shall incorporate the responsibility and controls defined under the KYC & Customer Due Diligence Policy and applicable partner requirements.
16. TECHNOLOGY & API CONTROLS
Product systems and APIs shall use appropriate authentication, authorisation, logging, error handling and security controls. Production issuance credentials shall be restricted to authorised systems and personnel.
17. TESTING BEFORE LAUNCH
- Functional testing
- Issuance testing
- Activation testing
- Redemption testing
- Refund/reversal testing
- Fraud-control testing
- API/security testing
- Settlement/reconciliation testing
- Customer communication testing
18. CHANGE MANAGEMENT
Material changes to value, validity, redemption, issuer/partner, customer eligibility, transaction limits, technical integration or commercial terms shall undergo documented impact assessment and approval before deployment.
19. INCIDENT & PRODUCT SUSPENSION
RanaPay may suspend affected issuance or redemption activity where there is a material fraud, security, regulatory, partner or operational risk, subject to applicable contractual and legal requirements.
- Identify issue.
- Assess customer and business impact.
- Contain or suspend where appropriate.
- Notify relevant partner/management.
- Investigate.
- Implement remediation.
- Approve restart.
- Document closure.
20. REFUNDS, REVERSALS & CHARGEBACKS
Refund, reversal and chargeback handling shall follow the approved Refund, Cancellation & Chargeback Policy and relevant product/partner terms.
21. SETTLEMENT & RECONCILIATION
Issuance, activation, redemption, refund and settlement records shall be reconciled according to the applicable operating model. Exceptions shall be investigated and documented.
22. PRODUCT MONITORING
- Sales/issuance volumes
- Redemption volumes
- Failure rates
- Fraud alerts
- Refund/reversal trends
- Customer complaints
- Settlement exceptions
- Partner performance
- Security incidents
23. PRODUCT RETIREMENT
Product retirement shall include controlled suspension of new issuance, handling of outstanding customer obligations, partner communication, settlement closure, data/record retention and customer support.
24. THIRD-PARTY / PARTNER CONTROLS
Partners involved in product issuance, distribution, processing, redemption or settlement shall be managed under the PPI Issuer / Bank Partner Management Policy and Third-Party / Vendor Risk Management Policy.
25. RECORD KEEPING
- Product approval documents
- Product specifications
- Partner approvals
- Issuance records
- Activation/redemption records
- Changes and approvals
- Testing evidence
- Incidents
- Complaints
- Settlement/reconciliation records
- Retirement records
26. AUDIT & MONITORING
RanaPay may conduct periodic reviews of product governance, issuance controls, customer disclosures, partner arrangements, fraud controls, security, settlement and records.
27. RESPONSIBILITY MATRIX
| Function | Responsibility | Escalation |
|---|---|---|
| Product | Product design, documentation and lifecycle | Management / Compliance |
| Compliance | Regulatory/product compliance assessment | Management |
| Operations | Issuance, activation, redemption and support processes | Operations Head |
| Technology | Systems, APIs, security and testing | Technology/Security Head |
| Finance | Settlement and reconciliation | Finance Head |
| Partner Management | Issuer/bank/merchant coordination | Management / Compliance |
| Fraud/Risk | Fraud controls and monitoring | Compliance / Management |
28. POLICY EXCEPTIONS
Exceptions shall be documented, risk-assessed and approved by an authorised function. No exception may bypass mandatory legal, regulatory or partner requirements.
29. REVIEW & AMENDMENT
This Policy shall be reviewed at least annually and whenever there is a material change in product structure, partner model, regulatory requirements, technology or risk profile.
30. APPROVAL
| Role | Name / Designation | Signature / Date |
|---|---|---|
| Prepared By | Product / Compliance / Operations | |
| Reviewed By | Legal / Risk / Management | |
| Approved By | Director / Authorised Signatory |
