Cyber Crime, Fraud & Information Security Policy
Chargeback, Dispute & Unauthorized Transaction Policy, Cyber Crime / Cyber Fraud Management Policy, and Information Security & Cyber Security Policy.
Entity & Operator Identification
Legal Name: SAFALPAY INDIA PRIVATE LIMITED
Brand: StudioMitra
CIN: U72900UP2021PTC152896
GSTIN: 09ABGCS9381Q2Z6
Website: www.studiomitra.in
Support Email: info.studiomitra@gmail.com
Cyber & Compliance: compliance@safalpay.com
Helpline: +91 9918784000
Principal Place of Business: D-30, Vibhuti Khand, Gomti Nagar, Lucknow, Uttar Pradesh – 226010, India
Chargeback, Dispute & Cyber Fraud Management Policy
Operating framework for chargebacks, representments, unauthorized transactions, and CERT-In aligned incident management (Clauses 1 to 50).
1. Purpose
This Policy establishes the framework followed by StudioMitra, a brand operated by SAFALPAY INDIA PRIVATE LIMITED, for receiving, reviewing, investigating and resolving chargebacks, payment disputes, unauthorized transactions, suspected fraud, cyber-enabled fraud and cyber security incidents connected with the StudioMitra Website, software and related services.
The Policy is intended to protect customers, photography studios, photographers, business users, employees, service providers and the Company against financial loss, misuse of accounts, payment fraud, unauthorized access, data compromise and other cyber-related risks.
2. Scope
This Policy applies to the StudioMitra website, photography studio management software/SaaS services, booking management, customer management, appointment and event management, invoicing, payment-status functionality, galleries/media functionality, user accounts, integrations and related support services.
It applies to customers, photography studios, photographers, business users, authorized representatives, employees, contractors and relevant third-party service providers to the extent applicable.
StudioMitra's existing Terms & Conditions describe the Website and services, including booking/business-management functionality, payment-related facilities, fraud/security controls, prohibited activities and grievance handling.
3. Company Details
Legal Name: SAFALPAY INDIA PRIVATE LIMITED
Brand: StudioMitra
CIN: U72900UP2021PTC152896
GSTIN: 09ABGCS9381Q2Z6
Principal Place of Business: D-30, Vibhuti Khand, Gomti Nagar, Lucknow, Uttar Pradesh – 226010, India
Website: www.studiomitra.in
General Support: info.studiomitra@gmail.com
Website Registered Email: info.safalpay@gmail.com
Compliance Email: compliance@safalpay.com
Phone: +91 9918784000
4. Definitions
- “Chargeback” means a payment reversal or dispute initiated through a card issuer, payment network, bank, payment service provider or other applicable financial institution.
- “Dispute” means a complaint or claim relating to a transaction, service, billing, payment status, refund, cancellation or other transaction-related matter.
- “Unauthorized Transaction” means a transaction that the account holder or authorized user states was not initiated or authorized by them.
- “Cyber Incident” means an event that may compromise the confidentiality, integrity or availability of information systems, applications, accounts or data.
- “Cyber Fraud” means fraud conducted through digital, electronic, online, social-engineering or cyber-enabled methods.
- “User” includes a customer, photography studio, photographer, business user or other authorized person using StudioMitra services.
- “Transaction Reference” includes order ID, transaction ID, UTR, RRN, payment reference, mandate reference or other identifier available for a transaction.
5. Policy Objectives
- Provide a structured process for transaction disputes and chargebacks.
- Protect users against unauthorized transactions and fraudulent activity.
- Detect, investigate and respond to cyber fraud and security incidents.
- Preserve relevant transaction and security evidence.
- Coordinate with banks, payment gateways, payment service providers and other authorized parties.
- Support lawful requests from law-enforcement, regulatory and cyber-security authorities.
- Minimize financial, operational, reputational and data-security impact.
- Improve controls through post-incident review and corrective action.
6. Nature of StudioMitra Services
StudioMitra provides software and digital tools for photography studios and related businesses, including booking management, customer management, appointment scheduling, event management, invoicing/billing, payment-status tracking and photography gallery/media management. The Privacy Policy records that customer/booking information may include names, contact details, booking dates, appointment details, event dates, venues, invoices, payment status and photographs/videos.
Where a payment is processed through a third-party payment gateway, bank, UPI provider, card network or payment service provider, that provider may independently process payment information. StudioMitra's existing Terms also state that it may not directly process or store all payment credentials.
7. Chargeback Policy
A chargeback may be initiated by a customer through the relevant card issuer, bank, payment network or payment service provider under the applicable rules. StudioMitra may review and respond to a chargeback where the transaction or service relates to StudioMitra.
A chargeback does not automatically establish that the customer is entitled to a refund. The outcome is determined under the applicable payment-network, bank or payment-provider rules, available evidence and applicable law.
8. Common Chargeback / Dispute Reasons
- Transaction not recognized by the account holder.
- Duplicate transaction or duplicate billing.
- Payment made but service/order not received.
- Service cancelled but refund not received.
- Incorrect amount or billing error.
- Payment shown as failed but account was debited.
- AutoPay or recurring debit dispute, where applicable.
- Claim that the transaction was unauthorized.
- Claim that the service was materially different from the agreed service.
- Other transaction-related claims recognized by the applicable payment provider.
9. User Responsibilities Before Raising a Dispute
Users should first review their account, invoice, booking information, transaction history and payment confirmation. Where appropriate, users should contact StudioMitra so that the issue can be investigated before initiating a formal chargeback.
The User should provide accurate information and must not submit a false, misleading or duplicate dispute.
10. Information Required for a Dispute
- Customer / account holder name;
- Registered mobile number and email address;
- Order ID / transaction ID;
- UTR / RRN / payment reference, where available;
- Transaction date and exact amount;
- Payment method and relevant provider;
- Booking, invoice or service reference;
- Description of the issue; and
- Screenshots, receipts, invoices or other supporting evidence.
11. Dispute Intake and Acknowledgement
A dispute received through an official StudioMitra support or compliance channel should be logged with a unique internal reference. The Company will acknowledge receipt and route the matter to the appropriate internal team.
12. Dispute Investigation
StudioMitra reviews account activity, booking records, invoice records, payment status, system logs, authentication records, and communication records to assess the legitimacy of the dispute.
13. Chargeback Representment / Response
Where a chargeback is received through a payment provider and StudioMitra is entitled or required to respond, the Company may submit verifiable evidence including timestamped delivery logs, download records, IP access logs, and digital contract signatures.
14. Refund vs Chargeback
A refund is returned through the standard merchant refund process governed by our Refund Policy. A chargeback is a banking dispute. Duplicate recoveries across channels are prohibited.
16. Account Compromise
If login credentials are suspected of being compromised, immediately reset passwords, enable multi-factor authentication, and contact StudioMitra to terminate active sessions.
17. Cyber Fraud Prevention Best Practices
- Use strong and unique passwords and change compromised credentials promptly.
- Use multi-factor authentication where available.
- Apply role-based access for studio team members.
- Never share OTPs, passwords, PINs, CVV, or API keys.
- Never install remote-access software requested by unknown callers.
18. Cyber Fraud / Cyber Crime Incident Types
Covered security threats include:
19. Cyber Incident Reporting by Users
Report suspected incidents immediately to compliance@safalpay.com or phone +91 9918784000.
20. Internal Incident Response & Statutory Compliance (Clauses 20–30)
StudioMitra enforces a 9-stage incident response framework covering identification, triage, containment, evidence preservation, investigation, eradication, recovery, reporting, and post-incident review.
- CERT-In Compliance: Mandatory incident reporting within six hours and 180-day secure ICT logging.
- Law Enforcement: Proactive reporting of cyber financial fraud and identity theft to competent cyber cells.
- Media Protection: Special protocols for unauthorized photography access or gallery alteration.
31. AutoPay, Account Controls & Business Continuity (Clauses 31–40)
AutoPay mandate cancellations must be performed prior to scheduled debits. The Company reserves the right to restrict compromised accounts, enforce internal least-privilege controls, conduct employee awareness drills, and execute post-incident remediation audits.
44. Part I Contact Desk & Governing Law (Clauses 41–50)
General Support: info.studiomitra@gmail.com
Compliance & Cyber Incidents: compliance@safalpay.com
Helpline: +91 9918784000
Governing Law: Republic of India
Information Security & Cyber Security Policy
Enterprise security controls, cloud defense, SSDLC, cryptography, access management, and infrastructure resilience (Clauses 1 to 57).
1. Purpose (Information Security)
This Information Security & Cyber Security Policy establishes the principles, controls, responsibilities and security practices adopted by SAFALPAY INDIA PRIVATE LIMITED under the brand name StudioMitra to protect information, systems, applications, accounts and digital services used to operate the StudioMitra Website and photography studio management software.
The objective is to protect confidentiality, integrity, and availability; reduce cyber attack risks; and establish a consistent security framework across users, vendors, and engineering teams.
2. Scope
Applies to the Website, SaaS platform, databases, APIs, cloud VPCs, administrative portals, endpoints, production and staging environments, and all personnel handling studio data or photography assets.
3. Company Information
Legal Name: SAFALPAY INDIA PRIVATE LIMITED
Brand: StudioMitra
CIN: U72900UP2021PTC152896
GSTIN: 09ABGCS9381Q2Z6
Address: D-30, Vibhuti Khand, Gomti Nagar, Lucknow, Uttar Pradesh – 226010, India
4. Information Security Objectives
- Protect confidential and personal information against unauthorized access or disclosure.
- Maintain integrity and accuracy of customer, booking, and accounting records.
- Ensure resilience and uptime of studio galleries and client proofing tools.
- Enforce rigorous defense against account takeover, malware, phishing, and API abuse.
5. Security Principles
Enforcing defense-in-depth principles:
- Confidentiality, Integrity & Availability (CIA Triad)
- Least Privilege & Need-to-Know
- Defense in Depth & Secure by Design
- Cryptographic Accountability & Attribution
6. Information Classification
7 & 8. Access Control & Authentication Security
Shared accounts are strictly prohibited. Multi-factor authentication is mandatory on all administrative consoles. Passwords must meet high entropy requirements and compromised tokens are revoked immediately.
9 & 10. Privileged Access & Data Security Controls
Administrative access to cloud consoles, databases, and secrets is isolated with separate credentials, continuous audit logging, and periodic access recertification. Sensitive data is never exported without verified operational authorization.
11 & 12. Personal Data & Photography Media Security
Photographers retain full ownership of customer images and must maintain lawful basis and model consents. StudioMitra enforces password and PIN access controls for client proofing galleries.
13, 14 & 15. Network, Application & API Security
Infrastructure is secured within multi-tier VPCs behind Web Application Firewalls. Code follows OWASP standards with parameterized SQL queries, CSRF defenses, and cryptographic API tokens with rate limiting.
16 & 17. Secure Software Development (SSDLC) & Vulnerability Management
Static application security testing (SAST) is integrated into CI/CD pipelines. Security vulnerabilities are categorized by severity and patched under strict SLA windows.
18 to 24. Endpoints, Phishing, Logging & Backups
- Full-disk encryption enforced on all engineering endpoints.
- Simulated phishing drills and email SPF/DKIM/DMARC authentication.
- CERT-In compliant 180-day ICT logging within Indian jurisdiction.
- Automated daily database snapshots with point-in-time recovery.
25 to 35. Cloud Security, Encryption & Incident Protocols
Data in transit uses TLS 1.3; data at rest uses AES-256 with KMS key rotation. Security incidents are escalated to compliance@safalpay.com and CERT-In within 6 hours where required.
36 to 48. Risk Management, Audits & Compliance (Clauses 36–48)
PCI-DSS Level 1 compliant card tokenization, routine penetration testing, third-party vendor assessments, and forensic preservation ensure compliance with the Information Technology Act 2000 and DPDP Act 2023.
57. Official Governance & Security Office Contact
SAFALPAY INDIA PRIVATE LIMITED
Brand: StudioMitra
D-30, Vibhuti Khand, Gomti Nagar, Lucknow, Uttar Pradesh – 226010, India
Website: www.studiomitra.in
General Email: info.studiomitra@gmail.com
Compliance / Cyber Incident Email: compliance@safalpay.com
Incident Helpline: +91 9918784000