RANAPAY INDIA PRIVATE LIMITED
GIFT CARD / VOUCHER OPERATIONS, REDEMPTION & LIFECYCLE MANAGEMENT POLICY
POLICY NO. 19 | VERSION 1.0
EFFECTIVE DATE: 29 SEPTEMBER 2026
| Document Control | Details |
|---|---|
| Company | RANAPAY INDIA PRIVATE LIMITED |
| CIN | U72900UP2021PTC140275 |
| Registered Office | D30, Vibhuti Khand, Gomti Nagar, Lucknow, Uttar Pradesh – 226010 |
| Website | ranapay.in |
| Business Context | Gift Cards, Gift Vouchers & Virtual Gift Products through applicable authorised/regulated partners |
| Policy Owner | Operations / Compliance / Technology / Partner Management |
| Review Frequency | At least annually / event driven |
| Classification | Confidential – Controlled Operations Document |
1. PURPOSE
This Policy establishes operational controls for the end-to-end lifecycle of gift cards and vouchers handled by RanaPay through applicable authorised partners, from product configuration and issuance through activation, delivery, redemption, expiry, cancellation, blocking, reconciliation and closure.
2. OBJECTIVES
- Maintain accurate product and voucher records.
- Protect customers from unauthorised or fraudulent use.
- Ensure controlled issuance and activation.
- Support accurate redemption and balance processing.
- Manage expiry, cancellation and reissue consistently.
- Maintain reconciliation and audit trails.
- Coordinate operational issues with authorised partners.
3. SCOPE
This Policy applies to gift cards, gift vouchers, virtual voucher products, related orders, codes, balances, redemption events, refunds/cancellations, partner settlement records and supporting systems/processes operated by or for RanaPay.
4. LIFECYCLE
- Product onboarding/configuration
- Order creation
- Issuance
- Activation
- Delivery
- Customer possession/use
- Redemption
- Balance/status update
- Expiry or closure
- Cancellation/refund where applicable
- Reconciliation and record retention
5. PRODUCT ONBOARDING
A gift-card/voucher product shall be onboarded only after appropriate commercial, operational, compliance, technical and partner approvals. Product terms, denomination, validity, redemption rules and responsible partner shall be documented.
6. PRODUCT MASTER DATA
- Product name and identifier
- Denominations
- Currency
- Validity/expiry terms
- Issuer/authorised partner
- Redemption channels
- Applicable restrictions
- Customer-facing terms
- Settlement/reconciliation identifiers
7. ISSUANCE CONTROLS
- Validate order and customer inputs.
- Confirm product availability.
- Generate or obtain authorised voucher credentials.
- Record issuance reference.
- Apply appropriate fraud/risk controls.
- Update status and deliver through approved channel.
8. UNIQUE VOUCHER IDENTIFIERS
Voucher codes, serial numbers, tokens or equivalent identifiers shall be unique and protected against unauthorised disclosure, duplication or predictable generation.
9. ACTIVATION
Where activation is required, activation shall occur only through an approved process and shall be recorded with relevant timestamp, reference and status.
10. DELIVERY
Voucher credentials shall be delivered only through approved customer or partner channels. Sensitive codes should not be unnecessarily exposed in logs, support tickets or internal communications.
11. CUSTOMER USE & REDEMPTION
Redemption shall be processed through the authorised issuer/merchant/partner mechanism and shall be subject to product-specific terms, balance, validity and applicable restrictions.
12. REDEMPTION VALIDATION
- Validate voucher/product status
- Validate balance or denomination
- Validate redemption eligibility
- Confirm transaction reference
- Record successful or failed redemption
- Update applicable status/balance
13. PARTIAL REDEMPTION / BALANCE
Where the product supports partial redemption, the remaining balance shall be accurately maintained by the authorised system or partner. Balance discrepancies shall be investigated and reconciled.
14. EXPIRY
Expiry shall follow the applicable product and partner terms. Expired vouchers shall not be reactivated except where specifically authorised under applicable terms and controls.
15. BLOCK / SUSPENSION
A voucher may be blocked or suspended where fraud, compromise, duplicate use, technical error, customer protection requirement or other authorised reason is identified, subject to applicable terms and partner procedures.
16. LOST / STOLEN CODES
Customers shall be informed of the applicable responsibility and recovery process. Replacement or reissue, where offered, shall require appropriate verification and partner confirmation.
17. REFUND / CANCELLATION
Refunds or cancellations shall be processed according to the applicable product terms, partner agreement and Refund, Cancellation & Chargeback Policy.
18. REISSUE / REPLACEMENT
Reissue or replacement shall be controlled, documented and linked to the original voucher/order reference to prevent duplicate value or double redemption.
19. FRAUD CONTROLS
- Velocity monitoring
- Repeated redemption detection
- Unusual purchase patterns
- Duplicate or reused code detection
- Compromised credential handling
- High-risk customer/order review
- Partner escalation
20. TRANSACTION MONITORING
Relevant voucher issuance, activation, redemption, refund and cancellation events shall be monitored according to applicable fraud-risk and transaction-monitoring procedures.
21. CUSTOMER SUPPORT
Customer support shall verify appropriate details before disclosing voucher information, changing status, initiating replacement or discussing sensitive transaction information.
22. PARTNER COORDINATION
Operational issues involving an issuer, bank, merchant, payment processor, technology provider or other authorised partner shall be escalated through defined partner contacts.
23. SETTLEMENT & RECONCILIATION
Issued, redeemed, cancelled, refunded and outstanding voucher values shall be reconciled with relevant partner statements or system records at appropriate intervals.
24. EXCEPTION MANAGEMENT
- Unmatched redemption
- Duplicate transaction
- Incorrect denomination
- Incorrect status
- Failed activation
- Settlement mismatch
- Customer dispute
- Technical processing error
Exceptions shall be logged, investigated, resolved or escalated with supporting evidence.
25. SYSTEM ACCESS
Access to voucher-management systems shall follow the Access Control & API Security Policy. Privileged functions such as issuance, status changes, refunds or administrative adjustments shall be restricted and logged.
26. API & INTEGRATION CONTROLS
Partner APIs shall use approved authentication, authorisation, logging, error handling and secure communication mechanisms. API failures affecting customer value shall be reconciled before closure.
27. CUSTOMER DATA
Customer and voucher information shall be handled according to the Data Protection, Privacy & Retention Policy.
28. INCIDENT MANAGEMENT
Suspected voucher fraud, code compromise, systemic redemption errors or material service disruption shall be escalated under the Cyber Incident Response & Cyber Fraud Policy and relevant operational procedures.
29. BUSINESS CONTINUITY
Critical voucher operations shall have appropriate continuity and recovery arrangements consistent with the Business Continuity & Disaster Recovery Policy.
30. RECORD KEEPING
- Product configuration
- Orders
- Issuance records
- Activation records
- Delivery records
- Redemption records
- Refund/cancellation records
- Block/reissue records
- Partner statements
- Reconciliation records
- Customer dispute records
- Exception and incident records
31. AUDIT TRAIL
Material lifecycle events shall maintain sufficient records to establish what happened, when it happened, the relevant reference and the responsible system/user or partner, where practicable.
32. TRAINING
Relevant operations, support, fraud, technology and partner-management personnel shall receive appropriate training on voucher lifecycle controls and customer protection.
33. MONITORING & REVIEW
Management shall periodically review operational metrics, fraud trends, reconciliation exceptions, complaints, partner performance and control weaknesses.
34. NON-COMPLIANCE
Operational breaches or control failures shall be investigated and corrective action shall be taken according to severity and applicable internal procedures.
35. EXCEPTIONS
Exceptions shall be documented, risk-assessed and approved by authorised personnel. Applicable legal, regulatory, contractual and product terms shall not be bypassed.
36. RESPONSIBILITY MATRIX
| Function | Responsibility | Escalation |
|---|---|---|
| Operations | Lifecycle processing, exceptions and operational controls | Operations Head |
| Partner Management | Issuer/merchant/partner coordination | Management |
| Technology | Systems, APIs, availability and technical controls | Technology Head |
| Fraud/Risk | Fraud monitoring, suspicious activity and controls | Risk/Fraud Head |
| Compliance | Policy oversight and applicable requirement assessment | Compliance Head |
| Finance | Settlement and reconciliation | Finance Head |
| Customer Support | Customer verification, complaints and approved assistance | Operations / Compliance |
37. REVIEW & AMENDMENT
This Policy shall be reviewed at least annually and whenever there is a material change in product structure, partner arrangements, technology, redemption process or applicable requirements.
38. APPROVAL
| Role | Name / Designation | Signature / Date |
|---|---|---|
| Prepared By | Operations / Compliance / Technology / Partner Management | |
| Reviewed By | Risk / Legal / Management | |
| Approved By | Director / Authorised Signatory |
