RanaPay

RANAPAY INDIA PRIVATE LIMITED

GIFT CARD / VOUCHER OPERATIONS, REDEMPTION & LIFECYCLE MANAGEMENT POLICY

POLICY NO. 19 | VERSION 1.0

EFFECTIVE DATE: 29 SEPTEMBER 2026

Document ControlDetails
CompanyRANAPAY INDIA PRIVATE LIMITED
CINU72900UP2021PTC140275
Registered OfficeD30, Vibhuti Khand, Gomti Nagar, Lucknow, Uttar Pradesh – 226010
Websiteranapay.in
Business ContextGift Cards, Gift Vouchers & Virtual Gift Products through applicable authorised/regulated partners
Policy OwnerOperations / Compliance / Technology / Partner Management
Review FrequencyAt least annually / event driven
ClassificationConfidential – Controlled Operations Document

1. PURPOSE

This Policy establishes operational controls for the end-to-end lifecycle of gift cards and vouchers handled by RanaPay through applicable authorised partners, from product configuration and issuance through activation, delivery, redemption, expiry, cancellation, blocking, reconciliation and closure.

2. OBJECTIVES

  • Maintain accurate product and voucher records.
  • Protect customers from unauthorised or fraudulent use.
  • Ensure controlled issuance and activation.
  • Support accurate redemption and balance processing.
  • Manage expiry, cancellation and reissue consistently.
  • Maintain reconciliation and audit trails.
  • Coordinate operational issues with authorised partners.

3. SCOPE

This Policy applies to gift cards, gift vouchers, virtual voucher products, related orders, codes, balances, redemption events, refunds/cancellations, partner settlement records and supporting systems/processes operated by or for RanaPay.

4. LIFECYCLE

  • Product onboarding/configuration
  • Order creation
  • Issuance
  • Activation
  • Delivery
  • Customer possession/use
  • Redemption
  • Balance/status update
  • Expiry or closure
  • Cancellation/refund where applicable
  • Reconciliation and record retention

5. PRODUCT ONBOARDING

A gift-card/voucher product shall be onboarded only after appropriate commercial, operational, compliance, technical and partner approvals. Product terms, denomination, validity, redemption rules and responsible partner shall be documented.

6. PRODUCT MASTER DATA

  • Product name and identifier
  • Denominations
  • Currency
  • Validity/expiry terms
  • Issuer/authorised partner
  • Redemption channels
  • Applicable restrictions
  • Customer-facing terms
  • Settlement/reconciliation identifiers

7. ISSUANCE CONTROLS

  1. Validate order and customer inputs.
  2. Confirm product availability.
  3. Generate or obtain authorised voucher credentials.
  4. Record issuance reference.
  5. Apply appropriate fraud/risk controls.
  6. Update status and deliver through approved channel.

8. UNIQUE VOUCHER IDENTIFIERS

Voucher codes, serial numbers, tokens or equivalent identifiers shall be unique and protected against unauthorised disclosure, duplication or predictable generation.

9. ACTIVATION

Where activation is required, activation shall occur only through an approved process and shall be recorded with relevant timestamp, reference and status.

10. DELIVERY

Voucher credentials shall be delivered only through approved customer or partner channels. Sensitive codes should not be unnecessarily exposed in logs, support tickets or internal communications.

11. CUSTOMER USE & REDEMPTION

Redemption shall be processed through the authorised issuer/merchant/partner mechanism and shall be subject to product-specific terms, balance, validity and applicable restrictions.

12. REDEMPTION VALIDATION

  • Validate voucher/product status
  • Validate balance or denomination
  • Validate redemption eligibility
  • Confirm transaction reference
  • Record successful or failed redemption
  • Update applicable status/balance

13. PARTIAL REDEMPTION / BALANCE

Where the product supports partial redemption, the remaining balance shall be accurately maintained by the authorised system or partner. Balance discrepancies shall be investigated and reconciled.

14. EXPIRY

Expiry shall follow the applicable product and partner terms. Expired vouchers shall not be reactivated except where specifically authorised under applicable terms and controls.

15. BLOCK / SUSPENSION

A voucher may be blocked or suspended where fraud, compromise, duplicate use, technical error, customer protection requirement or other authorised reason is identified, subject to applicable terms and partner procedures.

16. LOST / STOLEN CODES

Customers shall be informed of the applicable responsibility and recovery process. Replacement or reissue, where offered, shall require appropriate verification and partner confirmation.

17. REFUND / CANCELLATION

Refunds or cancellations shall be processed according to the applicable product terms, partner agreement and Refund, Cancellation & Chargeback Policy.

18. REISSUE / REPLACEMENT

Reissue or replacement shall be controlled, documented and linked to the original voucher/order reference to prevent duplicate value or double redemption.

19. FRAUD CONTROLS

  • Velocity monitoring
  • Repeated redemption detection
  • Unusual purchase patterns
  • Duplicate or reused code detection
  • Compromised credential handling
  • High-risk customer/order review
  • Partner escalation

20. TRANSACTION MONITORING

Relevant voucher issuance, activation, redemption, refund and cancellation events shall be monitored according to applicable fraud-risk and transaction-monitoring procedures.

21. CUSTOMER SUPPORT

Customer support shall verify appropriate details before disclosing voucher information, changing status, initiating replacement or discussing sensitive transaction information.

22. PARTNER COORDINATION

Operational issues involving an issuer, bank, merchant, payment processor, technology provider or other authorised partner shall be escalated through defined partner contacts.

23. SETTLEMENT & RECONCILIATION

Issued, redeemed, cancelled, refunded and outstanding voucher values shall be reconciled with relevant partner statements or system records at appropriate intervals.

24. EXCEPTION MANAGEMENT

  • Unmatched redemption
  • Duplicate transaction
  • Incorrect denomination
  • Incorrect status
  • Failed activation
  • Settlement mismatch
  • Customer dispute
  • Technical processing error

Exceptions shall be logged, investigated, resolved or escalated with supporting evidence.

25. SYSTEM ACCESS

Access to voucher-management systems shall follow the Access Control & API Security Policy. Privileged functions such as issuance, status changes, refunds or administrative adjustments shall be restricted and logged.

26. API & INTEGRATION CONTROLS

Partner APIs shall use approved authentication, authorisation, logging, error handling and secure communication mechanisms. API failures affecting customer value shall be reconciled before closure.

27. CUSTOMER DATA

Customer and voucher information shall be handled according to the Data Protection, Privacy & Retention Policy.

28. INCIDENT MANAGEMENT

Suspected voucher fraud, code compromise, systemic redemption errors or material service disruption shall be escalated under the Cyber Incident Response & Cyber Fraud Policy and relevant operational procedures.

29. BUSINESS CONTINUITY

Critical voucher operations shall have appropriate continuity and recovery arrangements consistent with the Business Continuity & Disaster Recovery Policy.

30. RECORD KEEPING

  • Product configuration
  • Orders
  • Issuance records
  • Activation records
  • Delivery records
  • Redemption records
  • Refund/cancellation records
  • Block/reissue records
  • Partner statements
  • Reconciliation records
  • Customer dispute records
  • Exception and incident records

31. AUDIT TRAIL

Material lifecycle events shall maintain sufficient records to establish what happened, when it happened, the relevant reference and the responsible system/user or partner, where practicable.

32. TRAINING

Relevant operations, support, fraud, technology and partner-management personnel shall receive appropriate training on voucher lifecycle controls and customer protection.

33. MONITORING & REVIEW

Management shall periodically review operational metrics, fraud trends, reconciliation exceptions, complaints, partner performance and control weaknesses.

34. NON-COMPLIANCE

Operational breaches or control failures shall be investigated and corrective action shall be taken according to severity and applicable internal procedures.

35. EXCEPTIONS

Exceptions shall be documented, risk-assessed and approved by authorised personnel. Applicable legal, regulatory, contractual and product terms shall not be bypassed.

36. RESPONSIBILITY MATRIX

FunctionResponsibilityEscalation
OperationsLifecycle processing, exceptions and operational controlsOperations Head
Partner ManagementIssuer/merchant/partner coordinationManagement
TechnologySystems, APIs, availability and technical controlsTechnology Head
Fraud/RiskFraud monitoring, suspicious activity and controlsRisk/Fraud Head
CompliancePolicy oversight and applicable requirement assessmentCompliance Head
FinanceSettlement and reconciliationFinance Head
Customer SupportCustomer verification, complaints and approved assistanceOperations / Compliance

37. REVIEW & AMENDMENT

This Policy shall be reviewed at least annually and whenever there is a material change in product structure, partner arrangements, technology, redemption process or applicable requirements.

38. APPROVAL

RoleName / DesignationSignature / Date
Prepared ByOperations / Compliance / Technology / Partner Management
Reviewed ByRisk / Legal / Management
Approved ByDirector / Authorised Signatory

CONFIDENTIAL – CONTROLLED OPERATIONS DOCUMENT

RANAPAY INDIA PRIVATE LIMITED