REMPINDIA MULTITRADE PRIVATE LIMITED
POLICY NO. 01 | VERSION 1.0
EFFECTIVE DATE: 29 SEPTEMBER 2026
| Document Control | Details |
|---|---|
| Company | REMPINDIA MULTITRADE PRIVATE LIMITED |
| CIN | U45202UP2021PTC143528 |
| Registered Office | C/O Rajesh Singh S/o Shree Shankar Singh, Karanpur Chauraha, Shamsabad Road, Sirathu, Kaushambi, Uttar Pradesh – 212217 |
| Website / Brand | giftvoucher.co.in |
| Business Model | Gift Card / Gift Voucher business operated through an authorised PPI / bank / payment partner; the Company shall not represent itself as a PPI issuer unless separately authorised. |
| Policy Owner | Management / Compliance |
| Review Frequency | At least annually and upon material regulatory, business or partner change |
| Classification | Confidential – Regulatory Compliance Policy |
This Policy establishes the regulatory-compliance framework for REMPINDIA MULTITRADE PRIVATE LIMITED's gift-card and gift-voucher business operated through authorised PPI, bank, payment or other regulated partners. It is intended to ensure that the Company's activities remain within the role, responsibilities and permissions applicable to the Company and its partners.
REMPINDIA MULTITRADE PRIVATE LIMITED shall not describe itself as a PPI issuer, issuer of regulated stored-value instruments, bank or other regulated entity unless it holds the applicable authorisation. Where a gift card or voucher is issued, processed, funded, settled or otherwise regulated through an authorised partner, the Company's activities shall be performed in accordance with the partner agreement, applicable law and the partner's approved operating framework.
This Policy applies to gift cards, gift vouchers, digital voucher products, websites, applications, APIs, merchant relationships, payment flows, PPI/bank/payment integrations, customer support, marketing material, settlement processes and employees or vendors involved in the relevant services.
Compliance shall maintain a regulatory obligation register identifying requirements applicable to the Company's role and each partner-led product flow. The mapping should identify the responsible entity, source requirement, operational control, evidence and owner.
Where an authorised PPI issuer or other regulated partner performs regulated issuance or payment functions, the Company shall operate only within the agreed scope. Responsibilities for KYC, AML/CFT, transaction monitoring, issuance, redemption, settlement, refunds, grievances, unauthorised transactions, reporting and customer communications shall be documented between the parties.
Customer-facing information shall be accurate and not misleading. The Company shall provide appropriate information regarding purchase, activation, redemption, validity, restrictions, refunds, cancellation, disputes and support, consistent with the product and partner arrangements.
Where KYC, customer due diligence or AML/CFT obligations apply to the relevant activity, the Company shall follow the applicable partner process and its KYC & Customer Due Diligence Policy and AML/CFT Policy. The Company shall not bypass or weaken controls imposed by an authorised regulated partner.
The Company shall maintain risk-based fraud controls appropriate to its role, including monitoring of unusual voucher activity, repeated failed transactions, suspicious purchase patterns, account compromise, misuse, abnormal redemption and other relevant indicators.
Payment collection, settlement and reconciliation shall be conducted through approved channels and according to documented partner arrangements. Relevant controls are detailed in the Payment, Settlement & Reconciliation Policy.
Systems, APIs, customer information and transaction data shall be protected through appropriate security controls. Material cyber incidents shall be escalated under the Cyber Incident Response & Cyber Fraud Policy.
Personal and confidential information shall be collected, used, shared, retained and disposed of in accordance with applicable privacy requirements, partner arrangements and the Data Protection, Privacy & Retention Policy.
A documented grievance process shall be maintained. Where the authorised partner has primary responsibility for a regulated complaint, the Company shall promptly route and support the complaint according to the agreed process.
Reports of unauthorised transactions, account compromise or voucher misuse shall be recorded, investigated and coordinated with the relevant PPI, bank, payment or technology partner as applicable.
Vendors and service providers that affect regulated or customer-facing functions shall be subject to appropriate due diligence, contractual controls, information-security requirements and monitoring.
The Company shall maintain appropriate records and provide information required by authorised partners, regulators or competent authorities where applicable to its role. Regulatory reporting responsibility shall be clearly allocated in partner agreements.
Regulatory approvals, product assessments, partner agreements, customer terms, reports, incidents, complaints, transaction records and other relevant evidence shall be retained according to applicable legal, regulatory, contractual and business requirements.
Compliance shall monitor material changes in applicable laws, regulatory directions and partner requirements. Material changes shall be assessed for impact on products, contracts, customer journeys, technology and policies.
Material compliance, fraud, cyber, privacy, settlement or customer-protection incidents shall be escalated to management and relevant partners promptly. Reporting to authorities shall be handled where legally required or appropriate.
Relevant employees and contractors shall receive appropriate training or guidance on regulatory responsibilities, customer protection, fraud prevention, information security, privacy, reporting and escalation.
The Company may conduct periodic compliance reviews, partner reviews, control testing and audits appropriate to the business and risk profile. Material findings shall be documented and remediated.
Exceptions to this Policy shall be documented, risk-assessed and approved by authorised management. No exception may override mandatory legal, regulatory or contractual requirements.
| Function | Responsibility | Escalation |
|---|---|---|
| Management | Policy approval, regulatory risk oversight and material decisions | Director / Management |
| Compliance / Legal | Regulatory mapping, partner obligations and regulatory liaison | Compliance Head |
| Operations | Implementation of approved product and partner processes | Operations Head |
| Technology / Security | Technology, API, access and cyber controls | Technology/Security Head |
| Risk / Fraud | Fraud risk and transaction monitoring | Risk/Fraud Head |
| Finance | Settlement, reconciliation and financial records | Finance Head |
| Customer Support | Grievance and customer communication | Support Head |
| Partner Owner | PPI/bank/payment partner coordination | Partner Owner |
This Policy shall be reviewed at least annually and whenever there is a material change in the Company's business model, product, PPI/bank/payment partner, technology, applicable law or regulatory requirements.
| Role | Name / Designation | Signature / Date |
|---|---|---|
| Prepared By | Compliance / Operations | |
| Reviewed By | Legal / Risk / Technology | |
| Approved By | Director / Authorised Signatory |