Legalv1.0.0

Terms of Use of ZulePay Offline Payments (Offline Pocket, Digital Cheques and ISUTs)

Effective date: 9 September 2026 · Last updated: 9 September 2026 · Published by USR Enterprises Private Limited

Terms of Use of ZulePay Offline Payments (Offline Pocket, Digital Cheques and ISUTs)

Last updated: 9 September 2026 · Version: 1.0.0 · Effective date: 9 September 2026

1. About this document

These terms ("Offline Payments Terms") govern ZulePay's offline payment feature — the ability to pay without internet connectivity using your Offline Pocket, Digital Cheques and Immutable Single-Use Tokens ("ISUTs"). They apply in addition to the General Terms and Conditions, the Wallet Terms, the Privacy Policy and the Cancellation & Refund Policy. Capitalised terms have the meanings in the General Terms.

2. Overview

Offline payments let a customer pay a merchant or another customer when either or both devices are offline. Funds are first carved into your Offline Pocket; when you prepare a payment, a Digital Cheque is cut from the Pocket and an ISUT is minted on your device and handed to the payee over a nearby channel. The payee's device verifies the ISUT cryptographically and redeems it when back online. The cryptographic design ensures a token can be spent only once, only by the intended payee, and only within its validity window.

3. The Offline Pocket

  1. You may provision an Offline Pocket by allocating funds from your Main Wallet, subject to your KYC tier and the regulatory cap — currently ₹2,000 outstanding at any time.
  2. The Offline Pocket can be de-provisioned at any time from the app while you are online, returning funds to your Main Wallet.
  3. While your device is offline, the split between Main Wallet and Offline Pocket on your device is authoritative for spending decisions; after sync, the platform ledger is definitive.
  4. If you change or lose your device, follow the in-app device migration flow. Offline balances do not automatically transfer between devices except through that flow.

4. Digital Cheques and ISUT generation

  1. When you prepare an offline payment, the app carves out a Digital Cheque from your Offline Pocket and mints an ISUT — an end-to-end encrypted, single-use token locked to the recipient's public key.
  2. On generation, the corresponding spending power is destroyed on your device ("destroy-on-generate"), so the same funds cannot be spent twice while the ISUT is live.
  3. Per-cheque minimum and maximum amounts are as displayed in the app at the time of preparation.
  4. A generated ISUT cannot be cancelled by you; if it expires unredeemed, funds return automatically under Section 6.

5. Transfer

  1. ISUTs are transferred to the payee over Bluetooth / nearby channels or by QR code, without internet. Transfer works customer-to-merchant and customer-to-customer.
  2. You are responsible for transferring the ISUT to the intended payee. Once a payee's device has accepted the ISUT, the payment is final like any other payment.
  3. Both devices should confirm the payment amount shown before transfer.

6. Validity and expiry

  1. Each ISUT is valid for 30 minutes from generation (the "validity window"), as shown on the payment screen.
  2. If the payee does not redeem (sync) the ISUT within the validity window, it expires automatically and the amount is returned to you — credited back to your Offline Pocket / Main Wallet once your device is online — as described in the Cancellation & Refund Policy.
  3. An expired ISUT has no value; any later attempt to redeem it will be rejected.

7. Redemption and sync

  1. The payee's device verifies the token cryptographically and queues it. Settlement completes when the payee's device syncs with the platform.
  2. Until sync, the platform may have no visibility of the payment. Balances, history and statements shown elsewhere (including on other devices or the merchant dashboard) may not reflect offline activity until then.
  3. Merchants must sync within the timelines in the Merchant Solutions Terms; delays may affect settlement timing.

8. Device keys and security

  1. Offline payments are secured by device-bound cryptographic keys (ECDSA P-256) generated in your device's secure hardware. Private keys never leave your device and cannot be exported.
  2. You must keep your device secure, protect your device unlock credentials, and report loss or suspected compromise immediately (support@zulepay.com / +91 95381 07745).
  3. If you change or lose your device, use the in-app device migration flow; provisioning a new device invalidates the previous device's offline payment keys where technically feasible.
  4. Offline payments may be disabled on devices we detect as rooted, jailbroken or otherwise compromised.

9. Blacklisted keys

We maintain a blacklist of compromised device keys. We may blacklist a device key on reasonable suspicion of compromise, fraud or misuse, and refuse to honour ISUTs from blacklisted keys. Legitimate holders of blacklisted devices should contact support to verify identity and recover their balance through the standard flows.

10. Risks and liability

  1. Device loss before transfer. If you lose your device with an Offline Pocket balance, contact support immediately. Because keys cannot leave the device, recovery follows the device-migration / identity-verification flow and may take longer than online refunds.
  2. Counterparty risk. Offline verification checks the token's cryptography, not the counterparty's identity. Verify who you are paying.
  3. Visibility gap. Between generation and sync, the platform cannot see the payment; customer support may have limited information during this window.
  4. Reporting. Unauthorised transactions are handled under Section 25 of the General Terms and the RBI's customer-protection framework — report within 3 working days of the communication from us for zero liability.
  5. Nothing in this section limits rights that cannot be excluded by law.

11. Prohibited conduct

Any attempt to reuse, relay, alter, forge or otherwise tamper with an ISUT or the offline protocol — including using emulators, automation or modified devices to manipulate the app — is a serious breach of these Terms (see Section 19 of the General Terms), may constitute a criminal offence, and entitles us to freeze the account, reverse related entries and report to law enforcement.

12. Contact us

USR Enterprises Private Limited CIN: U62011KA2026PTC224718 VO-843, WeWork 10th Floor, RMZ Latitude, No. 69/458/69, Hebbal Kempapura, Bengaluru – 560024, Karnataka, India Email: support@zulepay.com · Phone: +91 95381 07745