RANAPAY INDIA PRIVATE LIMITED
UNAUTHORISED TRANSACTION POLICY
POLICY NO. 10 | VERSION 1.0
EFFECTIVE DATE: 29 SEPTEMBER 2026
| Document Control | Details |
|---|---|
| Company | RANAPAY INDIA PRIVATE LIMITED |
| CIN | U72900UP2021PTC140275 |
| Registered Office | D30, Vibhuti Khand, Gomti Nagar, Lucknow, Uttar Pradesh – 226010 |
| Website | ranapay.in |
| Business Context | Gift Cards, Gift Vouchers & Virtual Gift Products through applicable authorised/regulated partners |
| Policy Owner | Compliance / Operations / Fraud Risk |
| Review Frequency | At least annually / event driven |
| Classification | Confidential – Controlled Compliance Document |
1. PURPOSE
This Policy establishes the framework for receiving, recording, investigating and resolving customer reports of transactions, purchases, activations or redemptions that the customer claims were not authorised by them.
2. ROLE & PARTNER PRINCIPLE
RanaPay shall act according to its actual role and contractual arrangements. Where an authorised PPI issuer, bank, payment processor or other regulated partner controls the transaction, authentication, dispute or refund process, RanaPay shall coordinate and provide relevant information rather than represent that it independently controls the regulated process.
3. OBJECTIVES
- Provide a clear reporting channel.
- Protect customers against unauthorised activity.
- Contain ongoing risk where appropriate.
- Investigate using available evidence.
- Coordinate with relevant partners.
- Process eligible refunds/reversals according to applicable rules.
- Maintain complete case records.
4. SCOPE
This Policy applies to suspected unauthorised purchase, activation, redemption, account access, payment or other transaction activity relating to RanaPay-supported gift cards, vouchers and virtual products.
5. WHAT MAY CONSTITUTE AN UNAUTHORISED TRANSACTION
- Customer denies making the transaction
- Customer reports compromised credentials
- Unknown gift-card purchase
- Unknown redemption
- Account takeover indicators
- Payment instrument misuse
- Suspicious change in customer details followed by transaction
6. CUSTOMER REPORTING
Customers should report suspected unauthorised activity promptly through the officially published support/grievance channels. The report should include the transaction/reference number and relevant details where available.
7. CASE REGISTRATION
- Receive complaint.
- Create case/reference number.
- Record date and time.
- Capture available transaction details.
- Classify severity.
- Apply immediate protective measures where appropriate.
- Assign investigator.
- Track case to closure.
8. IMMEDIATE PROTECTIVE ACTIONS
- Temporary transaction restriction
- Account/session restriction where applicable
- Credential reset or security verification
- Blocking a compromised voucher/code where technically and contractually possible
- Partner notification
- Preservation of relevant evidence
Protective measures shall be proportionate and shall not unnecessarily restrict legitimate customer activity.
9. CUSTOMER VERIFICATION
Before disclosing sensitive transaction information or making account changes, reasonable verification shall be performed using approved procedures. Passwords, PINs or OTPs shall not be requested through insecure or unauthorised channels.
10. INVESTIGATION
The investigator shall review available transaction records, authentication information, timestamps, device/channel indicators where available, redemption information, customer communications, partner records and relevant system logs.
11. PARTNER COORDINATION
Where the transaction was processed by a PPI issuer, bank, payment provider, merchant or other partner, the case shall be escalated through the documented partner process. Relevant evidence shall be shared only as permitted by law and contract.
12. FRAUD LINKAGE
Suspected unauthorised transactions shall also be assessed under the Fraud Prevention & Transaction Monitoring Policy and Cyber Incident Response & Cyber Fraud Policy where applicable.
13. REFUND / REVERSAL
Where an unauthorised transaction is established or a refund/reversal is otherwise approved, processing shall follow the Refund, Cancellation & Chargeback Policy and the relevant partner/network rules.
14. CHARGEBACK / DISPUTE
Where a payment dispute or chargeback is initiated, the responsible payment/partner process shall be followed. Evidence and response deadlines shall be tracked.
15. CASE DECISION
After investigation, the case may be classified as confirmed unauthorised, suspected but inconclusive, authorised/valid, duplicate/technical issue, fraud-related or other appropriate category. The decision shall be documented with supporting evidence.
16. CUSTOMER COMMUNICATION
Customers shall be informed of material case outcomes and next steps, subject to security, confidentiality, partner and legal limitations.
17. ESCALATION
- Material financial loss
- Repeated or linked unauthorised transactions
- Account takeover
- Systemic compromise
- Cybersecurity incident
- High-value transaction
- Partner dispute
- Law-enforcement or regulatory request
18. EVIDENCE PRESERVATION
- Transaction/reference data
- Authentication records where available
- System/API logs
- Redemption records
- Customer complaint
- Partner communications
- Relevant screenshots or documents
- Investigation decisions
19. DATA PROTECTION
Case information shall be accessed on a need-to-know basis and protected according to applicable data-protection requirements and RanaPay's Data Protection, Privacy & Retention Policy.
20. CUSTOMER AWARENESS
Customer-facing materials may include basic security guidance such as protecting OTPs, passwords, PINs and gift-card codes and reporting suspicious activity promptly.
21. CASE MANAGEMENT
Material cases shall have an assigned owner, status, action history, evidence, decision and closure date. Cases shall not be closed without recording the basis for closure.
22. REOPENING
A case may be reopened where new evidence is received, the customer provides material additional information, a partner changes its decision or a continuing risk is identified.
23. MONITORING & REPORTING
- Number of unauthorised transaction cases
- Financial value
- Confirmed vs inconclusive cases
- Response time
- Refund/reversal outcomes
- Repeat cases
- Partner-related cases
- Root causes
- Control improvements
24. TRAINING
Relevant personnel shall be trained on customer verification, fraud indicators, secure communications, evidence handling, escalation and applicable partner procedures.
25. AUDIT & QUALITY REVIEW
Periodic reviews may test case registration, investigation quality, customer communication, evidence preservation, refund decisions and partner escalation.
26. POLICY EXCEPTIONS
Any exception shall be documented, risk-assessed and approved by an authorised function. Mandatory legal, regulatory or partner requirements shall not be overridden.
27. RESPONSIBILITY MATRIX
| Function | Responsibility | Escalation |
|---|---|---|
| Customer Support | Receive and register reports; customer communication | Operations / Fraud |
| Fraud/Risk | Investigation, classification and monitoring | Compliance / Management |
| Operations | Restrictions, refunds and case execution | Operations Head |
| Compliance | Oversight and material escalation | Management |
| Technology/Security | Logs, technical investigation and security containment | Security / Management |
| Partner Management | PPI/bank/payment partner coordination | Compliance / Management |
| Finance | Refund/reversal accounting and reconciliation | Finance Head |
28. REVIEW & AMENDMENT
This Policy shall be reviewed at least annually and whenever there is a material change in fraud patterns, product design, technology, partner arrangements or applicable requirements.
29. APPROVAL
| Role | Name / Designation | Signature / Date |
|---|---|---|
| Prepared By | Operations / Fraud / Compliance | |
| Reviewed By | Legal / Risk / Management | |
| Approved By | Director / Authorised Signatory |
