Haripay

Haripay INDIA PRIVATE LIMITED

UNAUTHORISED TRANSACTION POLICY

POLICY NO. 10 | VERSION 1.0

EFFECTIVE DATE: 29 SEPTEMBER 2026

Document ControlDetails
CompanyHaripay INDIA PRIVATE LIMITED
CINU72900UP2021PTC140275
Registered OfficeD30, Vibhuti Khand, Gomti Nagar, Lucknow, Uttar Pradesh – 226010
WebsiteHaripay.in
Business ContextGift Cards, Gift Vouchers & Virtual Gift Products through applicable authorised/regulated partners
Policy OwnerCompliance / Operations / Fraud Risk
Review FrequencyAt least annually / event driven
ClassificationConfidential – Controlled Compliance Document

1. PURPOSE

This Policy establishes the framework for receiving, recording, investigating and resolving customer reports of transactions, purchases, activations or redemptions that the customer claims were not authorised by them.

2. ROLE & PARTNER PRINCIPLE

Haripay shall act according to its actual role and contractual arrangements. Where an authorised PPI issuer, bank, payment processor or other regulated partner controls the transaction, authentication, dispute or refund process, Haripay shall coordinate and provide relevant information rather than represent that it independently controls the regulated process.

3. OBJECTIVES

  • Provide a clear reporting channel.
  • Protect customers against unauthorised activity.
  • Contain ongoing risk where appropriate.
  • Investigate using available evidence.
  • Coordinate with relevant partners.
  • Process eligible refunds/reversals according to applicable rules.
  • Maintain complete case records.

4. SCOPE

This Policy applies to suspected unauthorised purchase, activation, redemption, account access, payment or other transaction activity relating to Haripay-supported gift cards, vouchers and virtual products.

5. WHAT MAY CONSTITUTE AN UNAUTHORISED TRANSACTION

  • Customer denies making the transaction
  • Customer reports compromised credentials
  • Unknown gift-card purchase
  • Unknown redemption
  • Account takeover indicators
  • Payment instrument misuse
  • Suspicious change in customer details followed by transaction

6. CUSTOMER REPORTING

Customers should report suspected unauthorised activity promptly through the officially published support/grievance channels. The report should include the transaction/reference number and relevant details where available.

7. CASE REGISTRATION

  1. Receive complaint.
  2. Create case/reference number.
  3. Record date and time.
  4. Capture available transaction details.
  5. Classify severity.
  6. Apply immediate protective measures where appropriate.
  7. Assign investigator.
  8. Track case to closure.

8. IMMEDIATE PROTECTIVE ACTIONS

  • Temporary transaction restriction
  • Account/session restriction where applicable
  • Credential reset or security verification
  • Blocking a compromised voucher/code where technically and contractually possible
  • Partner notification
  • Preservation of relevant evidence

Protective measures shall be proportionate and shall not unnecessarily restrict legitimate customer activity.

9. CUSTOMER VERIFICATION

Before disclosing sensitive transaction information or making account changes, reasonable verification shall be performed using approved procedures. Passwords, PINs or OTPs shall not be requested through insecure or unauthorised channels.

10. INVESTIGATION

The investigator shall review available transaction records, authentication information, timestamps, device/channel indicators where available, redemption information, customer communications, partner records and relevant system logs.

11. PARTNER COORDINATION

Where the transaction was processed by a PPI issuer, bank, payment provider, merchant or other partner, the case shall be escalated through the documented partner process. Relevant evidence shall be shared only as permitted by law and contract.

12. FRAUD LINKAGE

Suspected unauthorised transactions shall also be assessed under the Fraud Prevention & Transaction Monitoring Policy and Cyber Incident Response & Cyber Fraud Policy where applicable.

13. REFUND / REVERSAL

Where an unauthorised transaction is established or a refund/reversal is otherwise approved, processing shall follow the Refund, Cancellation & Chargeback Policy and the relevant partner/network rules.

14. CHARGEBACK / DISPUTE

Where a payment dispute or chargeback is initiated, the responsible payment/partner process shall be followed. Evidence and response deadlines shall be tracked.

15. CASE DECISION

After investigation, the case may be classified as confirmed unauthorised, suspected but inconclusive, authorised/valid, duplicate/technical issue, fraud-related or other appropriate category. The decision shall be documented with supporting evidence.

16. CUSTOMER COMMUNICATION

Customers shall be informed of material case outcomes and next steps, subject to security, confidentiality, partner and legal limitations.

17. ESCALATION

  • Material financial loss
  • Repeated or linked unauthorised transactions
  • Account takeover
  • Systemic compromise
  • Cybersecurity incident
  • High-value transaction
  • Partner dispute
  • Law-enforcement or regulatory request

18. EVIDENCE PRESERVATION

  • Transaction/reference data
  • Authentication records where available
  • System/API logs
  • Redemption records
  • Customer complaint
  • Partner communications
  • Relevant screenshots or documents
  • Investigation decisions

19. DATA PROTECTION

Case information shall be accessed on a need-to-know basis and protected according to applicable data-protection requirements and Haripay's Data Protection, Privacy & Retention Policy.

20. CUSTOMER AWARENESS

Customer-facing materials may include basic security guidance such as protecting OTPs, passwords, PINs and gift-card codes and reporting suspicious activity promptly.

21. CASE MANAGEMENT

Material cases shall have an assigned owner, status, action history, evidence, decision and closure date. Cases shall not be closed without recording the basis for closure.

22. REOPENING

A case may be reopened where new evidence is received, the customer provides material additional information, a partner changes its decision or a continuing risk is identified.

23. MONITORING & REPORTING

  • Number of unauthorised transaction cases
  • Financial value
  • Confirmed vs inconclusive cases
  • Response time
  • Refund/reversal outcomes
  • Repeat cases
  • Partner-related cases
  • Root causes
  • Control improvements

24. TRAINING

Relevant personnel shall be trained on customer verification, fraud indicators, secure communications, evidence handling, escalation and applicable partner procedures.

25. AUDIT & QUALITY REVIEW

Periodic reviews may test case registration, investigation quality, customer communication, evidence preservation, refund decisions and partner escalation.

26. POLICY EXCEPTIONS

Any exception shall be documented, risk-assessed and approved by an authorised function. Mandatory legal, regulatory or partner requirements shall not be overridden.

27. RESPONSIBILITY MATRIX

FunctionResponsibilityEscalation
Customer SupportReceive and register reports; customer communicationOperations / Fraud
Fraud/RiskInvestigation, classification and monitoringCompliance / Management
OperationsRestrictions, refunds and case executionOperations Head
ComplianceOversight and material escalationManagement
Technology/SecurityLogs, technical investigation and security containmentSecurity / Management
Partner ManagementPPI/bank/payment partner coordinationCompliance / Management
FinanceRefund/reversal accounting and reconciliationFinance Head

28. REVIEW & AMENDMENT

This Policy shall be reviewed at least annually and whenever there is a material change in fraud patterns, product design, technology, partner arrangements or applicable requirements.

29. APPROVAL

RoleName / DesignationSignature / Date
Prepared ByOperations / Fraud / Compliance
Reviewed ByLegal / Risk / Management
Approved ByDirector / Authorised Signatory

CONFIDENTIAL – CONTROLLED COMPLIANCE DOCUMENT

Haripay INDIA PRIVATE LIMITED