Login, OTP, Session & Fraud Protection Rules

Account Security Policy

This policy explains how CapHanu Enterprise protects customer, seller, affiliate, B2B, wallet, CapCoin, order, payment, digital download, and support accounts through login security, OTP verification, password rules, session protection, device monitoring, fraud prevention, account recovery, unauthorized access reporting, and user safety responsibilities.

Effective: 01 January 2026 Updated: 28 May 2026

📌 Overview & Purpose

CapHanu Enterprise takes account security seriously because user accounts may contain personal information, addresses, orders, invoices, wallet balance, CapCoins, saved preferences, digital product access, support tickets, seller data, affiliate rewards, B2B quotations, and payment-related records. This Account Security Policy explains platform safeguards and user responsibilities for safe account use.

This policy applies to customers, sellers, admins where applicable, affiliates, referral users, B2B buyers, support users, digital product buyers, marketplace partners, and anyone using CapHanu Enterprise login, OTP, account dashboard, checkout, wallet, review, support, or seller/affiliate features.

Main rule: Never share OTP, password, UPI PIN, card PIN, CVV, full card number, bank password, recovery link, or login session with anyone. CapHanu Enterprise will never ask for these sensitive credentials through phone, WhatsApp, email, or unofficial link.

🧭 Account Security Scope

Account security includes all processes and safeguards used to prevent unauthorized access, account takeover, fake orders, payment misuse, wallet misuse, CapCoin abuse, referral/affiliate abuse, fake returns, COD misuse, privacy breach, and unauthorized digital downloads.

Login Security Password, OTP, mobile/email verification, remember login, account recovery, and suspicious login checks.
Session Security Secure sessions, logout, device checks, inactivity timeout, and session misuse prevention.
Transaction Safety Payment verification, wallet/CapCoin protection, COD risk review, refund and order security.
Fraud Protection Abuse prevention, fake account control, suspicious activity review, rate limiting, and audit logs.

📲 Login, OTP & Verification Rules

CapHanu Enterprise may use mobile OTP, email OTP, password login, reset links, login alerts, device verification, rate limiting, CAPTCHA-like checks, or other security methods to verify account ownership and reduce unauthorized access.

  • OTP is confidential and must be used only by the account holder for the intended action.
  • OTP may expire after a short time and may have limited attempts.
  • Repeated OTP requests or failed attempts may temporarily block login, reset, checkout, or account actions.
  • CapHanu Enterprise may require OTP for login, registration, password reset, mobile/email change, COD verification, refund verification, wallet action, or suspicious activity review.
  • Do not share OTP with courier, seller, support caller, friend, family member, affiliate, or anyone claiming to help with refund/order.
  • If you receive OTP without requesting it, do not share it and report suspicious activity to support.
OTP sharing is one of the biggest account takeover risks. Anyone who has your OTP may misuse your account, wallet, order, address, refund, or digital download access.

🔑 Password, Reset & Recovery Rules

Passwords protect access to your account. Users must create strong passwords and keep them confidential. CapHanu Enterprise may apply password policy, reset verification, session logout, and account recovery checks to protect users.

Security Area Recommended / Required Practice Why Important
Strong Password Use a long, unique password with letters, numbers, and symbols. Reduces guessing and credential stuffing risk.
No Reuse Do not reuse the same password from email, bank, social media, or other shopping sites. Data leaks from other sites can compromise reused passwords.
Password Reset Use official reset page/link only and verify email/mobile carefully. Prevents phishing and fake reset scams.
Recovery Link Do not forward reset link or recovery link to anyone. Reset links can allow account takeover.
Shared Devices Do not save passwords on public/shared computers. Prevents account access by unknown users.
Suspicious Activity Change password and logout from devices if you suspect compromise. Reduces further misuse.

CapHanu Enterprise may force password reset, invalidate sessions, restrict login, or require additional verification if account risk is detected.

💻 Session, Remember Login & Device Security

Sessions allow users to stay logged in while using the website. “Remember me” or similar features may keep users logged in longer on trusted devices. Users should use these features carefully.

  • Logout after using public, shared, office, cyber café, friend, or family device.
  • Do not use “remember me” on devices you do not fully control.
  • CapHanu Enterprise may automatically expire inactive sessions or suspicious sessions.
  • Changing password, reporting compromise, or security review may logout existing sessions.
  • Device, browser, IP, location, and activity signals may be used to detect suspicious login or misuse.
  • Users are responsible for securing their device with screen lock, updated browser, antivirus/security updates, and safe network use.

👛 Wallet, CapCoin, Payment & Order Security

Account security is closely connected with payment, wallet, CapCoin, coupons, gift cards, refunds, COD, referral, and affiliate benefits. Unauthorized account access may lead to misuse of these features.

  • Wallet balance, CapCoins, coupons, gift cards, and promotional credits may be protected by login and additional checks.
  • Refund requests, bank detail changes, UPI detail submission, and wallet actions may require verification.
  • CapHanu Enterprise may block or hold wallet/CapCoin use if suspicious activity is detected.
  • Unauthorized payment claims may require order, transaction, device, and account review.
  • Never share payment credentials, card details, UPI PIN, OTP, or bank passwords with anyone claiming to process refund.
  • Report unauthorized orders, wallet debit, CapCoin misuse, or suspicious refund change immediately.
Refund scams often ask for OTP or UPI PIN. A genuine refund does not require you to share UPI PIN, card PIN, OTP, CVV, or bank password.

🔄 Account Recovery, Mobile/Email Change & Ownership Verification

Account recovery helps genuine users regain access, but it also creates risk if someone tries to impersonate the account holder. CapHanu Enterprise may require verification before account recovery or sensitive changes.

  • Recovery may require registered mobile/email OTP, order details, identity/account proof, recent activity verification, or support review.
  • Changing mobile number, email, refund details, bank/UPI details, or delivery address may require additional verification.
  • If registered mobile/email is lost, support may ask for order ID, invoice, account proof, payment proof, or other verification.
  • CapHanu Enterprise may refuse recovery if ownership cannot be verified.
  • Account recovery may temporarily restrict wallet, refund, payout, digital download, or seller/affiliate actions until risk review is complete.
  • Submitting fake proof, forged documents, or false ownership claim may lead to account restriction and legal action.

🛡️ Fraud Protection, Abuse Control & Risk Review

CapHanu Enterprise may use automated and manual risk controls to protect users, sellers, payments, wallet, CapCoins, orders, coupons, referrals, affiliates, digital downloads, and the marketplace from misuse.

Risk Area Possible Signal Possible Action
Suspicious Login Unusual device, repeated failed attempts, unusual location/IP, OTP abuse. Extra verification, temporary lock, forced logout, password reset.
Payment Risk Chargeback, failed payments, mismatched details, suspicious high-value orders. Order hold, verification, cancellation, refund review.
COD Misuse Repeated refusal, wrong address, fake orders, unreachable phone. COD restriction, prepaid-only mode, account review.
Wallet / CapCoin Abuse Duplicate accounts, reward farming, fake referrals, offer misuse. Benefit reversal, wallet hold, reward cancellation.
Seller / Affiliate Abuse Fake orders, self-orders, invalid traffic, payout manipulation. Payout hold, commission reversal, account restriction.
Digital Access Abuse Excess downloads, link sharing, account sharing, suspicious access. Download hold, license revocation, account review.

Risk review may use order history, payment records, device signals, login attempts, support logs, address patterns, return/RTO history, wallet ledger, referral/affiliate data, and security logs.

🎣 Phishing, Fake Support & Scam Protection

Fraudsters may create fake websites, fake customer care numbers, fake WhatsApp support, fake refund links, fake courier links, fake UPI requests, or fake social media pages to steal OTP, payment details, or account access.

  • Use only official CapHanu Enterprise website and official support channels.
  • Check website URL carefully before entering login or payment details.
  • Do not click suspicious links claiming refund, prize, KYC, delivery update, free gift, or urgent account block.
  • Do not install screen-sharing apps or remote access apps on request of unknown caller.
  • Do not scan QR code to receive money. QR scan is generally used to pay, not receive refund.
  • Report fake pages, fake support numbers, suspicious messages, or phishing links immediately.
CapHanu Enterprise will never ask you to install remote access apps, share screen, reveal OTP, reveal UPI PIN, or send money to receive refund.

🏪 Seller, Affiliate, B2B & Partner Account Security

Seller, affiliate, B2B, and partner accounts may include payout details, commission reports, wholesale quotations, customer order records, product listings, business documents, and sensitive operational data. These accounts require extra care.

  • Use separate authorized user access where available; do not share one login among many people.
  • Keep payout bank/UPI details secure and verify any change request carefully.
  • Do not share seller/affiliate dashboard access with unauthorized staff, agencies, or vendors.
  • Immediately remove access of former employees, contractors, or partners.
  • CapHanu Enterprise may hold payout or commission if account takeover, fraud, fake traffic, or unauthorized bank change is suspected.
  • Business users are responsible for internal authorization and safe handling of account credentials.

💾 Digital Product & Download Security

Digital product buyers should protect access links, license keys, dashboard downloads, private files, and account credentials. Unauthorized sharing or weak account security may lead to misuse of digital access.

  • Do not share download links, license keys, ZIP passwords, or account access with others unless license allows it.
  • Download links may be tokenized, limited, logged, or expired for security.
  • CapHanu Enterprise may block suspicious download activity or unauthorized access patterns.
  • If your account is compromised, digital product access may be temporarily restricted until verification.
  • Refunded, disputed, or chargeback-linked digital orders may lose access.

✅ User Security Responsibility

CapHanu Enterprise provides security controls, but users must also follow safe practices. Many account issues happen because users share OTP, password, payment details, or use unsafe devices.

  • Keep your mobile number, email, and account details updated.
  • Use a strong unique password and change it if you suspect compromise.
  • Do not share OTP, password, recovery link, login link, wallet details, or payment credentials.
  • Logout from shared devices and avoid saving passwords on public devices.
  • Do not use suspicious browser extensions, cracked apps, malware, or unsafe networks for login/payment.
  • Check order history, wallet ledger, CapCoin activity, address book, refund details, and digital downloads regularly.
  • Report suspicious activity quickly so support can help reduce damage.

⚖️ CapHanu Enterprise Security Rights

To protect users, sellers, payments, wallet, data, and platform integrity, CapHanu Enterprise may take security actions where risk is detected.

  • Temporarily lock or restrict account access for suspicious activity.
  • Force password reset, OTP verification, logout from devices, or account re-verification.
  • Hold orders, refunds, wallet, CapCoins, affiliate commission, seller payout, or digital access during review.
  • Cancel suspicious orders, reverse benefits, restrict COD, block suspicious addresses/devices, or reject risky actions.
  • Request ownership proof or identity/account verification where needed.
  • Preserve security logs, audit records, IP/device signals, and transaction evidence for legal, fraud prevention, and dispute purposes.
  • Take legal action or cooperate with authorities where serious fraud, cyber abuse, payment fraud, or data misuse is suspected.

🚨 Unauthorized Access & Security Incident Reporting

Users should report account compromise or suspicious activity immediately. Fast reporting helps reduce further misuse and improves recovery chances.

Incident Type What To Do Helpful Details
Unknown Login / OTP Do not share OTP, change password, logout sessions, contact support. Time, mobile/email, screenshot, device info.
Unauthorized Order Report immediately and do not accept suspicious delivery. Order ID, address, payment mode, screenshots.
Wallet / CapCoin Misuse Report ledger entry and secure account. Transaction ID, amount, date/time, screenshots.
Payment Fraud Contact bank/payment provider and CapHanu support. Order ID, UPI/card reference, amount, time.
Fake Support / Phishing Do not click/pay/share OTP; report link/number. Phone number, link, WhatsApp/SMS/email screenshot.
Seller/Affiliate Payout Risk Freeze changes and contact support quickly. Account ID, changed bank detail, suspicious login, proof.

Users should also contact their bank, mobile operator, email provider, cybercrime portal, or appropriate authority where payment fraud, SIM swap, identity theft, or cybercrime is involved.

⚠️ Responsibility & Liability Limits

CapHanu Enterprise will make reasonable efforts to secure accounts and support genuine users. However, users remain responsible for losses caused by sharing OTP/password/payment details, using compromised devices, responding to fake links, giving remote access, failing to report promptly, or violating security instructions.

  • CapHanu Enterprise may not be responsible for unauthorized activity caused by user negligence, credential sharing, compromised email/mobile, malware, SIM swap, phishing, or third-party fraud outside our reasonable control.
  • Security review does not guarantee recovery of all losses, orders, wallet balance, rewards, or access.
  • Refund or reversal depends on verification, policy, payment partner rules, bank/cyber investigation, and evidence.
  • False unauthorized access claims, fake fraud reports, or manipulated evidence may lead to account action.

📚 Security Logs, Privacy & Data Handling

For account security, CapHanu Enterprise may collect and retain security-related records such as login time, session data, device/browser signals, IP logs, OTP attempts, password reset requests, order actions, wallet/CapCoin activity, support tickets, risk flags, and audit logs.

  • Security data may be used for fraud prevention, account protection, dispute resolution, compliance, and legal purposes.
  • Security records may be shared internally with authorized teams or externally with payment partners, courier partners, legal advisors, or authorities where required.
  • Users should read Privacy Policy and Cookie Policy for broader data handling details.
  • Some security records may be retained even after account closure where necessary for legal, tax, fraud, dispute, or audit purposes.

🔄 Policy Updates

CapHanu Enterprise may update this Account Security Policy due to new security features, fraud patterns, payment rules, wallet/CapCoin changes, seller/affiliate changes, digital product access rules, legal requirements, technology updates, or platform improvements.

Updated versions will be published on this page with the latest update date. Continued use of the platform after updates means the user acknowledges the revised Account Security Policy.

📩 Contact & Account Security Support

For account takeover, unauthorized order, suspicious OTP, password reset issue, wallet/CapCoin misuse, fake support scam, payment fraud, seller/affiliate account risk, digital access misuse, or account security clarification, contact official CapHanu Enterprise support channels immediately with complete details.

Email: support@caphanu.com
Mobile: +91 78745 67053
Website: https://caphanu.com/
Typical response: 24–48 business hours

Please do not share OTP, password, UPI PIN, card PIN, CVV, full card number, bank password, or unnecessary sensitive documents. Share only order ID, ticket ID, transaction reference, screenshots, suspicious link/number, and issue details through official support channels.