RanaPay

RANAPAY INDIA PRIVATE LIMITED

PPI & GIFT CARD REGULATORY COMPLIANCE POLICY

POLICY NO. 01 | VERSION 1.0

EFFECTIVE DATE: 29 SEPTEMBER 2026

Document ControlDetails
Company NameRANAPAY INDIA PRIVATE LIMITED
CINU72900UP2021PTC140275
Registered OfficeD30, Vibhuti Khand, Gomti Nagar, Lucknow, Uttar Pradesh – 226010
Websiteranapay.in
BusinessGift Cards, Gift Vouchers & Virtual Gift Products through applicable authorised/regulated partners
Policy OwnerCompliance / Management
Review FrequencyAt least annually and upon material legal, regulatory, product, technology or partner change
ClassificationConfidential – Controlled Compliance Document

1. Purpose

This Policy establishes the regulatory compliance framework of RANAPAY INDIA PRIVATE LIMITED ("RanaPay") for its gift card, gift voucher, virtual gift product and related payment or technology-enabled activities. It is designed for RanaPay's role as a business/technology/facilitation entity working with applicable authorised PPI issuers, banks, payment providers, merchants, brands and other partners, rather than assuming that RanaPay itself holds a PPI licence.

2. Scope

This Policy applies to relevant employees, management, contractors, technology teams, operations teams, compliance personnel and business functions involved in the design, distribution, support, processing, settlement, technology integration or administration of covered products.

  • Gift cards and gift vouchers
  • Virtual gift products
  • Payment-related integrations
  • PPI/bank/payment-provider arrangements
  • Merchant and brand relationships
  • Customer-facing product operations
  • Technology and API integrations
  • Settlement and reconciliation activities

3. Business & Regulatory Role

RanaPay shall maintain a documented description of its role for each product or service. The role assessment shall identify which activities are performed by RanaPay and which activities are performed by the authorised PPI issuer, bank, payment provider, merchant or other regulated entity.

Where a product involves regulated PPI or payment activity, RanaPay shall operate within the scope of its contractual and legal role and shall not assume or represent itself as the regulated issuer unless separately authorised to do so.

4. Licence / Authorisation Representation

RanaPay shall not state, display or imply that it holds an RBI PPI licence, payment-system authorisation or other regulatory approval unless such approval has actually been granted to RanaPay.

  • Marketing material shall use accurate regulatory descriptions.
  • Website content shall not create a misleading impression of licensing.
  • Customer communications shall accurately identify the relevant issuer/partner where required.
  • Partner licences/authorisations shall be verified before relying on them.

5. Regulated Partner Model

Where RanaPay uses an authorised PPI issuer, bank, payment provider or other regulated partner, the relationship shall be supported by appropriate agreements defining responsibilities, service scope, settlement, customer support, compliance obligations, security, data handling and escalation.

  • Identify the regulated activity.
  • Identify the regulated entity responsible for that activity.
  • Document RanaPay's role.
  • Verify the partner's relevant authorisation where applicable.
  • Execute appropriate contractual arrangements.
  • Review the arrangement periodically.

6. Regulatory Applicability Assessment

Before launching a new product, material feature or new payment arrangement, the responsible business and compliance functions shall assess the applicable regulatory and contractual requirements.

  • Product structure review
  • PPI/payment role assessment
  • Customer journey review
  • KYC/AML applicability
  • Data/privacy requirements
  • Fraud and transaction-monitoring requirements
  • Refund/complaint obligations
  • Settlement and reconciliation requirements
  • Regulatory reporting responsibilities

7. PPI & Gift Card Product Governance

Each covered product shall have a documented product owner and approved operating model. Where a PPI issuer is responsible for issuance or stored-value functionality, the product documentation shall clearly distinguish the issuer's role from RanaPay's role.

  • Product description
  • Issuer/partner details where applicable
  • Activation process
  • Validity/expiry
  • Redemption process
  • Transaction limits where applicable
  • Refund/cancellation rules
  • Fraud controls
  • Customer support process

8. Partner Due Diligence

Before onboarding a material regulated or critical partner, RanaPay shall conduct risk-based due diligence.

  • Corporate identity
  • Regulatory status/authorisation where applicable
  • Ownership/management information where appropriate
  • Service scope
  • Contractual terms
  • Information-security controls
  • Data-protection controls
  • Settlement process
  • Incident-management process
  • Business continuity
  • Escalation contacts

9. Customer Protection

RanaPay shall maintain appropriate customer-protection controls consistent with its role and applicable contractual/legal requirements.

  • Clear product information
  • Transparent applicable terms
  • Customer support
  • Complaint registration
  • Refund/dispute handling
  • Unauthorised transaction escalation
  • Protection of customer information
  • Appropriate fraud controls

10. KYC / AML / CFT Coordination

Where KYC, AML/CFT or customer due-diligence obligations apply to RanaPay's role, RanaPay shall implement the applicable controls. Where such obligations are performed by a regulated partner, the responsibility shall be documented and RanaPay shall provide information and cooperation required under the applicable arrangement.

RanaPay shall not claim to have performed a regulated KYC/AML function where that function is contractually and legally performed by another authorised entity.

11. Fraud & Transaction Monitoring

RanaPay shall maintain risk-based controls appropriate to its role for identifying suspicious, abnormal, fraudulent or unauthorised activity.

  • Transaction anomaly identification
  • Voucher abuse monitoring
  • Duplicate or unusual activity review
  • Fraud escalation
  • Account/security controls
  • Partner coordination
  • Evidence preservation

12. Payment, Settlement & Reconciliation

Payment and settlement activities shall be performed through approved arrangements. RanaPay shall maintain appropriate transaction records and reconciliation controls for activities within its responsibility.

  • Transaction matching
  • Settlement verification
  • Failed/reversed transaction review
  • Refund reconciliation
  • Exception management
  • Partner settlement communication

13. Information Security

RanaPay shall protect business, customer, transaction, payment, partner and security information using appropriate technical and organisational controls.

  • Role-based access
  • Authentication controls
  • Secure API integrations
  • Logging and monitoring
  • Data protection
  • Backup and recovery
  • Security awareness
  • Incident escalation

14. Regulatory Change Management

The Compliance/Management function shall monitor material changes relevant to RanaPay's products and operating model and shall coordinate appropriate policy, product, contract, customer-communication and control updates.

  • Identify change.
  • Assess business impact.
  • Assess regulatory impact.
  • Assign responsible owner.
  • Implement required changes.
  • Record completion/evidence.

15. Regulatory Reporting & Cooperation

Where a regulatory reporting or information obligation applies directly to RanaPay, reports shall be prepared from reliable records, reviewed by an authorised person and submitted through the applicable channel within the required timeframe.

Where the reporting obligation belongs to a regulated partner, RanaPay shall provide accurate information and cooperation as required under the applicable agreement and law.

16. Regulatory Communications

  • Regulatory notices
  • Partner compliance requests
  • Government/law-enforcement requests
  • Audit requests
  • Information requests
  • Material compliance escalations

Material regulatory communications shall be routed to the designated Compliance/Management function and maintained in the regulatory communication register.

17. Record Keeping

  • Partner due-diligence records
  • Authorisation evidence where applicable
  • Contracts and amendments
  • Product approvals
  • Compliance assessments
  • Transaction and settlement records
  • Customer complaints
  • Fraud/incident records
  • Regulatory communications
  • Training and review records

Records shall be retained in accordance with applicable law, contractual obligations and RanaPay's Data Protection, Privacy & Retention Policy.

18. Audit & Compliance Monitoring

RanaPay may conduct periodic compliance reviews covering product governance, partner arrangements, regulatory representations, customer protection, transaction controls, records and other material compliance areas.

Material findings shall be documented, assigned to responsible owners and tracked until closure.

19. Escalation & Material Breaches

Material compliance concerns shall be escalated promptly to Compliance/Management. Examples include suspected regulatory breaches, unauthorised activity, material fraud, significant cyber incidents, serious customer impact or material partner compliance failures.

  • Issue identification
  • Immediate containment where appropriate
  • Management escalation
  • Partner escalation where applicable
  • Evidence preservation
  • Corrective action
  • Closure documentation

20. Training & Awareness

Relevant personnel shall receive training appropriate to their responsibilities covering regulatory role, product compliance, customer protection, fraud awareness, information security, partner requirements and incident escalation.

21. Policy Exceptions

Exceptions shall be documented, risk-assessed and approved by the authorised function. No internal exception shall be used to bypass a mandatory legal or regulatory requirement.

22. Review & Amendment

This Policy shall be reviewed at least annually and whenever there is a material change in law, business model, product structure, regulated partner, technology, customer journey or regulatory interpretation.

23. Responsibility Matrix

FunctionPrimary ResponsibilityEscalation
ManagementOverall governance, approval and risk oversightBoard/Authorised Management
ComplianceRegulatory assessment, monitoring and reportingManagement
OperationsProduct/process implementation and recordsCompliance / Management
Technology / SecurityAPI, system and information-security controlsManagement / Security
FinancePayment, settlement and reconciliation controlsManagement / Compliance
Customer SupportCustomer complaints, support and escalationOperations / Compliance
Partner ManagementPartner due diligence, contracts and monitoringManagement / Compliance

24. Approval

RoleName / DesignationSignature / Date
Prepared ByCompliance / Operations
Reviewed ByLegal / Risk / Management
Approved ByDirector / Authorised Signatory

CONFIDENTIAL – RANAPAY INDIA PRIVATE LIMITED