🎓 CoursesMarkets & internationalIntermediate⏱ 60 min
🇮🇳
Accepting payments in India. 6 chapters and a final quiz.
The operating manual for the world's largest instant payments market. Choose an aggregator the RBI has actually authorized, wire UPI in intent mode rather than collect, and build a cost model for a market where the law sets the merchant fee at zero. Then accept cards under mandatory tokenization, set up e-NACH or UPI AutoPay mandates that don't break, and pass the compliance review on data localization.
🇮🇳
Telling a gateway, an aggregator, and a PSP bank apart, and checking that a provider holds the RBI authorization that matches your flow (PA-O, PA-P, PA-CB)
Wiring UPI collection by choosing between intent, collect, and QR, and understanding why collect is being shut down
Building an Indian cost-of-acceptance model on an MDR that is zero up to ₹2,000 and 0.40% above that from October 15, 2026, and putting your margin somewhere other than a percentage
Accepting cards under mandatory tokenization and preparing for authentication on cross-border card-not-present transactions
Chapter 1. Choosing who collects for you: PG, PA, or PSP bank.
The first decision is the only one you cannot cheaply reverse: who touches the money before you do. In India, the collection chain runs merchant → payment aggregator (PA) or acquiring bank → PSP bank → NPCI → payer's bank. No merchant, Indian or foreign, connects to NPCI directly. Access to the rail is reserved for banks. So you choose an intermediary, and that choice commits your cash flow, your license, and your ability to operate.
Gateway or aggregator: the question to ask at the first meeting
Technology and collection on the merchant's behalf
The funds
Never pass through it; they go from the payer's bank to the merchant's account
Pass through an escrow account before payout
RBI authorization
Not required for a purely technical service
Mandatory, under the Payment and Settlement Systems Act, 2007
What the merchant needs
Its own acquiring contract with an Indian bank
Nothing beyond the PA contract; the aggregator holds the banking relationship
The risk to watch
You handle bank onboarding and wait for your MID
Your money sits with a third party: its license and its escrow are your risk
The dividing line of the Indian market: do the funds pass through the provider or not?
The Reserve Bank of India (Regulation of Payment Aggregators) Directions, 2025, published on September 15, 2025, completely overhauled the aggregator regime and split the business into three separate authorizations. PA-O covers online aggregation and PA-P covers in-person aggregation, which brings in-store acquiring by non-banks into scope. PA-CB covers cross-border payment aggregation, under a framework dating from an RBI circular of October 31, 2023. A provider can hold one without the others. “We're RBI licensed” is not an acceptable answer.
Net worth: ₹15 crore when the application is filed, rising to ₹25 crore by the end of the third financial year after authorization (RBI, Regulation of Payment Aggregators Directions, 2025).
Legal form: a non-bank aggregator must be a company incorporated in India under the Companies Act, 2013. There is no PA license for a foreign entity, and that is the pivot point of any market entry strategy.
Ring-fencing: merchant funds pass through an *escrow account with a Scheduled Commercial Bank*** in India, kept separate from the aggregator's own funds.
Settlement to the merchant: the 2025 Directions require T+1 settlement. Write that benchmark into the contract and check it against actual statements.
Cross-border: the PA-CB regime caps a single transaction at ₹25 lakh (RBI circular of October 31, 2023) and requires dedicated collection accounts, separate from the domestic escrow.
Transition deadline: applications had to be filed by December 31, 2025, and aggregators without one had to stop operating by February 28, 2026 (RBI, 2025 Directions). A provider that missed that window is no longer operating legally.
Decision tree: which collection setup fits your case?
Do you have an Indian entity?
No → the domestic route is closed to you
Without a company incorporated in India, you can get neither a domestic acquiring contract nor a PA license. That leaves a third party's PA-CB and cross-border collection providers
➜
Indian entity, online sales
Contract with an authorized PA-O
The fastest route: the aggregator handles the banking relationship, the escrow, and the payout. Check the exact license category and its date
➜
Indian entity, in-store sales
Contract with an authorized PA-P, or an acquiring bank
The 2025 Directions created the PA-P category. A terminal provider without PA-P can no longer collect on your behalf
➜
Collecting from abroad into India, or the reverse
PA-CB, ₹25 lakh per-transaction cap
Dedicated collection accounts, and foreign exchange rules apply. This is not an acquiring contract: pricing and FX constraints belong to a different business
➜
High volume and an in-house payments team
Direct acquiring contract + technical gateway
You handle bank onboarding and MIDs, take back control of routing, and eliminate escrow risk. Setup takes much longer
⚠️
Never confuse the brand with the license
The RBI canceled the banking license of Paytm Payments Bank Limited by an order dated April 24, 2026, under Section 22(4) of the Banking Regulation Act, 1949. The Delhi High Court ordered its liquidation on July 8 and 22, 2026. The Paytm brand, run by One97 Communications Limited, survived by moving to a multibank model. In any Indian due diligence, ask for the exact name of the entity holding the authorization, its category and date, and the list of its backup PSP banks. A provider that depends on a single bank is a continuity risk, not a simplification.
The players you will really meet in an Indian RFPRARazorpayPAPayU IndiaCACashfreePIPine LabsPaytmPhonePe
🎯 Quick question
A European SaaS company with no Indian subsidiary wants to collect payments from its subscribers in India. What can it get?
Chapter 2. UPI in production: intent, collect, VPA, and QR.
“Integrating UPI” means you have picked a mode. There are two, and they differ in user experience, success rate, and fraud profile. In intent mode, the merchant pushes: it builds a upi://pay link that the phone opens, prefilled, in the customer's UPI app. The customer just enters their UPI PIN. In collect mode, the merchant pulls: it sends a payment request to the payer's ID. The payer gets a notification and has to find it, open it, and approve it before it expires. Intent removes two steps and the dependency on a notification, which makes it the default mode for any serious merchant integration.
The UPI intent link, as your back office should build it
upi://pay
?pa=marchand@banque # payee address: the payee's VPA (required)
&pn=Nom%20Du%20Marchand # payee name: shown in the payer's app
&mc=5814 # merchant category code, assigned by the acquirer
&tr=CMD-2026-000178 # transaction reference: YOUR order ID
&tn=Commande%20178 # transaction note, visible to the customer
&am=1499.00 # amount, in rupees, two decimal places
&cu=INR # currency: INR only
Parameter source: NPCI, UPI Linking Specification.
GOLDEN RULE OF RECONCILIATION
tr = your reference: you choose it, and it comes back in the callback
txn = the UPI ID, generated by the rail: you only learn it afterward
NEVER reconcile on amount + timestamp: on a rail that
handles 23.66 billion transactions a month, collisions are certain.
Mode
Who initiates
Customer journey
When to use it
Intent (upi://pay link)
The merchant, by pushing a link
Automatic switch to the UPI app, amount prefilled, PIN entry
Online payment on mobile, the dominant case. Default mode
Dynamic QR
The merchant, by displaying a single-use QR code
The customer scans from their app: the QR code already carries the amount and reference
The customer scans and enters the amount themselves
Small shops. Zero acceptance cost, but manual reconciliation: there is no order reference
Collect (ReqPay in collect mode)
The merchant, by pulling from the payer's VPA
A notification to find in the app, open, and approve before it expires
Edge cases: follow-up requests to a known VPA, deferred collection. Avoid at checkout
Choosing a UPI collection mode by sales channel
⚠️
Collect is closing down, for good reason
NPCI ended person-to-person collect requests effective October 1, 2025. Before that, P2P collect was capped at about ₹2,000, with higher amounts open only to verified merchants. The reason was the most common fraud in the market: a scammer sends a collect request disguised as money the victim is about to receive. The victim enters their UPI PIN, and their account is debited. Teach your support teams one absolute rule. Entering your UPI PIN never receives money. It only sends it. Any merchant help page that suggests otherwise is creating disputes.
A VPA is not an IBAN
A VPA (Virtual Payment Address), in the form name@bank, is an alias, not an account. It can be revoked or moved from one bank to another, and one customer can hold several. Never use it as the primary key in your customer database.
Validate a VPA before you use it: the address validation call returns the holder's name as their bank has it on file. Show that name to the customer and have them confirm it. It is your best protection against a typo, which cannot be undone on an instant rail.
VPAs are case-insensitive for resolution, but your storage has to normalize them: Ravi@okhdfcbank and ravi@okhdfcbank point to the same account and must map to a single record.
A newly created UPI ID, or a newly linked account, is capped at ₹5,000 for the first 24 hours. A new customer whose first order exceeds that amount will fail, and your integration is not to blame.
Limits are category-specific, not universal: ₹1 lakh a day for P2P, and up to ₹5 lakh per transaction and ₹10 lakh per 24 hours for certain verified merchant categories since September 15, 2025 (NPCI circular of August 28, 2025). Your MCC sets your limit, so get it confirmed in the contract, not in production.
ℹ️
P2PM or P2M: the category your acquirer assigns you sticks
In 2019, NPCI introduced a P2PM category for very small merchants, available up to about ₹50,000 of incoming UPI credits a month, with no merchant fee. Once a merchant collects more than about ₹1 lakh a month for three consecutive months, it must move to P2M, with a proper merchant category code. The operational impact is underestimated. A seller that outgrows a P2PM ID sees its payments start to fail, with no clear error message. If you run a marketplace in India, monitoring your sellers against that threshold is part of your operations, not your aggregator's.
23.66B
UPI transactions in July 2026 alone
NPCI, UPI product statistics, July 2026
85,5 %
UPI's share of payment volume in India, and 9.5% of value
RBI, Payment Systems Report 2026 (2025 data)
₹1 313
average UPI ticket: size your unit costs on this, not on a European average order
RBI, Payment Systems Report 2026
50 a day
balance checks allowed per app since August 1, 2025: don't build your monitoring on balance queries
NPCI, technical and operational restrictions effective August 1, 2025
73.13 crore
UPI QR codes deployed: acceptance in India is designed around QR codes, not terminals
RBI, Payment Systems Report 2026
🎯 Quick question
You are rebuilding the mobile checkout of an Indian e-commerce merchant. Which UPI mode do you wire by default, and why?
Chapter 3. Zero MDR: building a cost model when there is no fee.
A head of payments who arrives in India with a spreadsheet of ad valorem fees should close it. Since January 1, 2020, under Section 269SU of the Income-tax Act 1961, the merchant fee has been zero by law on RuPay debit cards and BHIM-UPI. This is not a low market rate open to renegotiation: the law bans charging at all. In a market where UPI carries 85.5% of volume, your marginal cost of acceptance on most transactions is zero. So is your provider's revenue.
⚠️
Merchant payments stop being entirely free on October 15, 2026
On September 15, 2026, NPCI set a fee of 0.40% on person-to-merchant payments above ₹2,000, capped at ₹300. Person-to-person payments, payments under ₹2,000, and merchants collecting up to ₹1 lakh a month remain exempt. The fee cannot be passed on to the customer: treat it as a cost of acceptance, not as a price shown at checkout.
Where fees remain, and where they are gone
Instrument
Merchant cost
What it means for your model
Account-to-account UPI
Zero up to ₹2,000, then 0.40% above that from October 15, 2026 (NPCI)
The threshold becomes a model input: track the share of your payments above ₹2,000, because that is where the fee kicks in
RuPay debit card
Zero, with interchange abolished by law
RuPay debit issuing no longer has a business model for issuers: don't count on issuer incentives
Visa/Mastercard debit cards
Negotiated MDR, standard regime
The only debit segment where negotiation makes sense, and it is shrinking fast
Wallet (PPI) used on UPI
Interchange of 1.1% above ₹2,000, zero below (NPCI circular, since April 1, 2023)
A threshold means an edge effect: track how your ticket sizes cluster around ₹2,000
RuPay credit card linked to UPI
Interchange applies above ₹2,000, per the NPCI schedule
You accept credit on a QR code, with no terminal, but you pay a fee again
Visa/Mastercard credit cards
Negotiated MDR
The real cost center for cards. This is where your negotiation happens
Cost-of-acceptance grid to fill in before any pricing negotiation
Cost-of-acceptance model: fill it in with YOUR mix, not this one
Cout_acceptation = Sum over each instrument i of:
Volume_i x Ticket_moyen_i x Taux_i + Frais_fixes_i
Known, enforceable rates (sources in the table above):
UPI account to account ............. 0.00% (Income-tax Act, s.269SU)
RuPay debit card ................... 0.00% (Income-tax Act, s.269SU)
UPI merchant > ₹2,000 .............. 0.40% (NPCI, from 2026-10-15)
PPI wallet on UPI, > ₹2,000 ........ 1.10% (NPCI, since 2023-04-01)
PPI wallet on UPI, <= ₹2,000 ....... 0.00% (NPCI, since 2023-04-01)
Visa / Mastercard cards ............ r_negocie <-- TO BE OBTAINED, unregulated
RuPay credit card on UPI ........... NPCI schedule, above ₹2,000
WORKING ASSUMPTION (replace with your actual mix, measured over 90 days):
anchor: UPI = 85.5% of national VOLUME, 9.5% of VALUE
(RBI, Payment Systems Report 2026)
=> in India, volume is free and the value is elsewhere.
A revenue model based on a percentage of the amount collected
has almost nothing to apply to. This is not a negotiation
problem. It is a model problem.
WHAT TO MEASURE INSTEAD:
cost per successful transaction = (fixed fees + subscriptions) / # successful tx
cost of a failure = retry + support + lost order
cost of the payout = payout fees + days of cash tied up (T+1)
🔑
If the margin isn't in the percentage, it's in five other places
Since the rail cannot be charged for, revenue moves elsewhere. It moves to hardware subscriptions (Android terminals, a Soundbox that announces each payment out loud) and to value-added services: reconciliation, refund management, fraud prevention, and bulk payouts. It also moves to merchant lending based on observed payment flows and to card and wallet acceptance, where fees still exist. Then there are cross-border flows, where FX conversion can be charged. An Indian business plan built on a take rate imported from a card market is wrong from the first line, and it will stay wrong even after renegotiation.
Jan. 1, 2020
zero MDR on RuPay debit and BHIM-UPI takes effect
Income-tax Act 1961, Section 269SU
1,1 %
interchange on merchant payments made with a wallet (PPI) over UPI, above ₹2,000
NPCI circular, in effect since April 1, 2023
99,8 %
digital share of total Indian payment volume (97.8% by value)
RBI, Payment Systems Report 2026
T+1
settlement time to the merchant imposed on aggregators: your variable is cash flow, not the fee
RBI, Regulation of Payment Aggregators Directions, 2025
One contractual risk needs handling now. The zero MDR is a policy choice, not a law of nature. Since 2025, the Payments Council of India has been lobbying to restore a 0.3% fee on UPI for large merchants only, with a turnover threshold of ₹40 lakh under discussion. In March and April 2026, Parliament's Standing Committee on Finance recommended reinstating an MDR for large merchants. No decision has been made so far. Treat this as a contract risk. Negotiate now the clause that will apply if an MDR comes back (cap, notice period, right to terminate), rather than discovering it in a one-sided amendment.
🎯 Quick question
Your finance team wants to cut the cost of acceptance in India, which is mostly UPI, by 20%. What do you say?
Chapter 4. Cards: RuPay, network choice, and mandatory tokenization.
Cards have not disappeared in India, but the market has split in two. Debit is collapsing because UPI does what debit cards did, for free and better. Volume fell from 408 crore to 133 crore transactions between 2021 and 2025, an average decline of 24.4% a year (RBI, Payment Systems Report 2026). Credit, meanwhile, grew 27% a year over the same period. The operational takeaway is clear. In India, the card is a credit instrument. Designing an acceptance flow around debit means optimizing a channel that is dying out.
1,005.2M
debit cards in circulation in June 2025, vs. 111.2 million credit cards
RBI, Payment System Report, June 2025
−24.4% a year
average annual decline in debit card payment volume, 2021 to 2025
RBI, Payment Systems Report 2026
+27% a year
annual growth in credit card volume over the same period
RBI, Payment Systems Report 2026
760M+
RuPay cards issued, all products combined
NPCI, 2024
What India's card regime won't let you do
Two habits imported from mature card markets fall flat in India. The first is least-cost routing. Since the RBI circular on network choice took effect on September 6, 2024, issuers can no longer sign exclusivity deals with a network. They must let customers choose their network at issuance and at renewal. The customer picks one network, not two applications on the same card, so there is no dynamic routing at the point of sale for acquirers to exploit. The second is the global card vault, which is illegal, and which the rest of this chapter covers.
The market's real differentiator lies elsewhere: RuPay Credit Card on UPI. A RuPay credit card is linked to a UPI ID and pays by scanning a merchant QR code, with the UPI PIN as authentication. You therefore accept credit on a QR code, with no terminal, along with the fee that comes with it above ₹2,000. The scope is limited. Cash withdrawals at merchants, P2P, and card-to-card payments are excluded, and standard UPI limits apply. There is no Visa or Mastercard equivalent on this rail. If your average ticket justifies credit, this card is the only way in through QR.
Tokenization: you no longer store anything
Since October 1, 2022, merchants and their aggregators may no longer store the card number, CVV, or expiration date. Only the issuer and the network hold that data; you work with a token.
Creating a token requires the cardholder's explicit consent, validated by an additional factor of authentication with the issuer (AFA). You cannot quietly tokenize an existing card base: every customer has to make a new authenticated payment.
Guest checkout allows time-limited retention: up to T+4, or the settlement date if that comes first. That is not storage. It is a temporary reprieve.
Since December 2023, the RBI has allowed tokenization at the issuer level (CoFT through card issuing banks): cardholders can create tokens in their bank's interface for the merchants they choose. You inherit tokens you never requested, and your back office must be able to accept them.
What this means for migrations: an Indian token is specific to the merchant-network-issuer combination. Switching providers without a portability clause forces you to re-authenticate your entire customer base. Negotiate portability in the contract when you sign up, never when you leave.
⚠️
April 1, 2026, then October 1, 2026: the date foreign merchants forget
The Authentication Mechanisms for Digital Payment Transactions Directions, 2025, published on September 25, 2025, require two authentication factors, at least one of them dynamic, on every digital payment transaction. They took effect on April 1, 2026 for domestic transactions, and the text explicitly opens the door to methods beyond SMS OTP: device-bound passkeys, biometrics, and risk-based authentication. The second part is often missed. By October 1, 2026, issuers must have a mechanism to validate cross-border card-not-present transactions initiated by a foreign merchant or acquirer. In other words, a merchant outside India that charges an Indian card will no longer be exempt from authentication. If your international checkout has never had to handle a challenge on an Indian card, test it now.
🎯 Quick question
You are switching from one Indian aggregator to another. What happens to your stored cards?
Chapter 5. Subscriptions: e-NACH, UPI AutoPay, and the 2026 e-mandate framework.
Two rails carry recurring direct debits in India, and you choose based on ticket size, not technical preference. NACH, run by NPCI, is the bulk clearing rail. Its paperless version, e-NACH, registers a mandate online through Aadhaar (India's national digital ID), net banking, or a debit card. UPI AutoPay is a mandate linked to the payer's UPI ID and executed by the switch. The first collects loan installments, insurance premiums, and systematic investment plans. The second collects consumer subscriptions.
Decision criterion
e-NACH (NACH rail)
UPI AutoPay (UPI rail)
Addressing
Payer's bank account (account number + IFSC code)
Payer’s UPI ID (VPA)
Enrollment conversion
Longer flow: Aadhaar, net banking, or debit card
A few seconds in the UPI app; the conversion gap is the main criterion
Execution
Batch clearing, net settlement
Debit on the instant rail, failure known immediately
Best-fit ticket size
Large amounts: loan installments, insurance premiums, investment plans
Small recurring amounts: subscriptions, digital services
Handling failures
Reject handled in the NACH cycle, retry must be rescheduled
Immediate reject, second attempt possible the same day
Operational constraint
Batch schedule set by the rail
Mandate execution limited to off-peak windows since August 1, 2025 (NPCI)
Decision grid: which rail for which subscription
The seven rules of the Digital Payments – E-mandate Framework, 2026
The first transaction on a mandate always requires strong authentication. No exceptions, whatever the rail.
After that, strong authentication is not required up to ₹15,000 per transaction. Above that amount, it becomes mandatory again at the time of debit, so the customer must be present.
The threshold rises to ₹1 lakh for three categories only: insurance premiums, mutual fund subscriptions, and credit card bill payments.
Mandatory pre-debit notification at least 24 hours before each debit, stating the payee’s name, the amount, the date and time of the debit, the mandate reference, and the purpose.
The right to decline individual transactions, and mandate revocation validated with AFA.
No charges to the customer for using the e-mandate service, and a post-debit notification listing the ways to file a complaint.
A dispute and complaint handling process must be set up by the collecting entity. You cannot delegate it to your aggregator.
🔑
Your dunning schedule starts at D-2, not on the debit date
The 24-hour pre-debit notification, with its right to decline, moves the moment of truth. Dunning systems imported from Europe or the US key off the return codes received after the debit. In India, a significant share of failures are declines triggered in advance by the notification itself. That has three practical consequences. The notification is a product design element, not a legal template. Your retention sequence must fire before the debit. Your metrics must separate a decline (the customer said no the day before) from a failure (the bank rejected the debit), because conflating the two means chasing customers who have just canceled.
⚠️
You no longer choose when your batch runs
Since August 1, 2025, NPCI has limited UPI AutoPay mandate execution to off-peak windows, after several rail outages caused by spikes in API calls. The same package of measures caps balance checks at 50 per day per app. That has two effects for a subscription business. Your monthly billing run can no longer fire at whatever time suits you. And a monitoring setup that checks the payer's balance before debiting will hit the cap. Drive your operations from the rail's execution notifications, not from polling.
🔕
The day-before decline
The customer read the pre-debit notification and declined the debit. That is not a banking failure. Chasing them with a technical error message is the surest way to turn hesitation into a cancellation.
⛔
Crossing ₹15,000
A price increase or a plan change can push the payment above the threshold. Strong authentication then becomes mandatory again at the time of debit, so the customer must be available. Test this scenario before you change your prices.
🔗
The vanished VPA
A UPI AutoPay mandate is tied to a revocable ID. When the customer changes banks or apps, the VPA goes away, and the mandate dies with it. Build a re-enrollment flow, and don't store the VPA as the customer's identity.
🎯 Quick question
A software company raises its monthly subscription for Indian customers from ₹12,000 to ₹18,000. What should it expect?
Chapter 6. Data, disputes, and go-live: what will get you rejected.
Indian projects rarely fail on technology. They fail on three compliance points that no outsourcing contract can fix. The first question is where the payment data is stored. The second is who answers the customer when a debit goes through and the goods never arrive. The third is how quickly the money comes back. This chapter is the review to pass before you open up traffic.
April 6, 2018
Payment data localization
RBI circular DPSS.CO.OD No. 2785/06.08.005/2017-2018: all payment system data must be stored only in India, so supervisors have unrestricted access. For a cross-border transaction, a copy of the domestic leg may be kept abroad.
September 20, 2019
Refund deadlines and customer compensation
RBI circular DPSS.CO.PD No. 629/02.01.014/2019-20: harmonized turnaround times for failed transactions, with ₹100 per day of delay owed to the customer once the deadline passes.
October 1, 2022
End of card data storage
Merchants and aggregators may no longer store the PAN, CVV, or expiration date.
February 15, 2025
UPI dispute automation
New NPCI rules: the payee's bank automatically accepts or rejects a dispute based on TCC or RET codes, starting in the next settlement cycle.
September 15, 2025
Payment Aggregators Directions, 2025
PA-O, PA-P, PA-CB; net worth of ₹15 crore, then ₹25 crore; escrow; T+1 settlement to the merchant.
November 13, 2025
Digital Personal Data Protection Rules, 2025
Rules implementing the 2023 Act are notified, with an 18-month phased rollout ending May 13, 2027.
April 1, 2026
Two factors, one of them dynamic
The Authentication Mechanisms Directions, 2025 take effect for domestic transactions.
October 1, 2026
Cross-border card-not-present
Deadline for issuers to validate cross-border CNP transactions initiated by a foreign merchant or acquirer.
RBI localization (2018)
DPDP Act 2023 and 2025 Rules
What is protected
Payment system data: the full end-to-end transaction, message, identifiers, and authentication data
Digital personal data of every kind, including payment data
Logic
Storage in India only, with RBI supervisory access
Transfers allowed by default, except to countries the central government explicitly restricts: a blacklist approach
Enforced by
Reserve Bank of India
Data Protection Board of India
Penalty
Supervisory action, up to restrictions on business
Financial penalties of up to ₹250 crore for a security failure that led to a breach
Classic mistake
Thinking a contractual transfer clause is enough
Thinking the DPDP Act's flexibility on transfers relaxes the RBI rule, when it does not
Two data regimes that apply together and must never be confused
⚠️
Localization is not a clause, it is an architecture
The rule is neither an adequacy framework nor a set of standard clauses: it imposes an obligation to store data only in India, backed by direct supervisory powers. A provider that serves India from a shared regional platform in Singapore or Frankfurt is not compliant, however good its outsourcing contract. Raise this at the very first meeting. Ask where the processing and storage servers are really located, not where the provider is headquartered or where its support team sits.
When the customer disputes: what you don't have
UPI has no chargebacks in the card sense. A UPI payment is an account-to-account transfer: once executed, there is no chargeback right comparable to a card network's. Don't build your commercial policy on the opposite assumption, in either direction.
UPI disputes are decided by the system, not by you. Since February 15, 2025, the payee's bank automatically accepts or rejects a dispute based on the TCC or RET codes generated, starting in the next settlement cycle. Your job is to get proof of fulfillment to your aggregator, fast.
The customer has an enforceable refund deadline. The RBI circular of September 20, 2019 harmonizes turnaround times for failed transactions and requires ₹100 per day of delay to be paid to the customer. A slow refund is not just an unhappy customer: it is a cost.
The last resort is the ombudsman. The Reserve Bank – Integrated Ombudsman Scheme is the final step. Your written replies to customers are evidence in the case file, so write them accordingly.
Your complaints process is your responsibility. The 2026 e-mandate framework explicitly requires the collecting entity to have one. It is not a service your aggregator provides.
Check the exact category of the provider's authorization (PA-O, PA-P, PA-CB), its date, and the entity that holds it, then compare it with the list the RBI publishes.
Check the real location of the servers that process and store payment data.
Check the provider's PSP bank redundancy: a single bank is a continuity risk, not a simplification.
Check T+1 settlement against real statements, not the sales brochure.
Check the authentication flow: two factors, one of them dynamic, and a dynamic factor other than SMS OTP.
Check that the 24-hour pre-debit notification is actually implemented on your chosen mandate rail, with a right to decline.
Check card token portability and mandate export, as an entry clause, never an exit clause.
🔑
Key takeaways before you open up traffic
One rail dominates, one operator runs it, one regulator writes the rules, and the merchant fee is zero by law on most of the volume. So you are not optimizing a rate. You are optimizing a success rate, a payout time, and a cost of failure. Three enforceable obligations have no equivalent elsewhere: tokenization, two-factor authentication with one dynamic factor, and exclusive data localization. One deadline is aimed squarely at foreign merchants: October 1, 2026, for the validation of cross-border card-not-present transactions.
🎯 Quick question
A provider tells you it “covers India” from its regional platform in Singapore. How should you respond?