Account Security Policy
This policy explains how CapHanu Enterprise protects customer, seller, affiliate, B2B, wallet, CapCoin, order, payment, digital download, and support accounts through login security, OTP verification, password rules, session protection, device monitoring, fraud prevention, account recovery, unauthorized access reporting, and user safety responsibilities.
📌 Overview & Purpose
CapHanu Enterprise takes account security seriously because user accounts may contain personal information, addresses, orders, invoices, wallet balance, CapCoins, saved preferences, digital product access, support tickets, seller data, affiliate rewards, B2B quotations, and payment-related records. This Account Security Policy explains platform safeguards and user responsibilities for safe account use.
This policy applies to customers, sellers, admins where applicable, affiliates, referral users, B2B buyers, support users, digital product buyers, marketplace partners, and anyone using CapHanu Enterprise login, OTP, account dashboard, checkout, wallet, review, support, or seller/affiliate features.
🧭 Account Security Scope
Account security includes all processes and safeguards used to prevent unauthorized access, account takeover, fake orders, payment misuse, wallet misuse, CapCoin abuse, referral/affiliate abuse, fake returns, COD misuse, privacy breach, and unauthorized digital downloads.
📲 Login, OTP & Verification Rules
CapHanu Enterprise may use mobile OTP, email OTP, password login, reset links, login alerts, device verification, rate limiting, CAPTCHA-like checks, or other security methods to verify account ownership and reduce unauthorized access.
- OTP is confidential and must be used only by the account holder for the intended action.
- OTP may expire after a short time and may have limited attempts.
- Repeated OTP requests or failed attempts may temporarily block login, reset, checkout, or account actions.
- CapHanu Enterprise may require OTP for login, registration, password reset, mobile/email change, COD verification, refund verification, wallet action, or suspicious activity review.
- Do not share OTP with courier, seller, support caller, friend, family member, affiliate, or anyone claiming to help with refund/order.
- If you receive OTP without requesting it, do not share it and report suspicious activity to support.
🔑 Password, Reset & Recovery Rules
Passwords protect access to your account. Users must create strong passwords and keep them confidential. CapHanu Enterprise may apply password policy, reset verification, session logout, and account recovery checks to protect users.
| Security Area | Recommended / Required Practice | Why Important |
|---|---|---|
| Strong Password | Use a long, unique password with letters, numbers, and symbols. | Reduces guessing and credential stuffing risk. |
| No Reuse | Do not reuse the same password from email, bank, social media, or other shopping sites. | Data leaks from other sites can compromise reused passwords. |
| Password Reset | Use official reset page/link only and verify email/mobile carefully. | Prevents phishing and fake reset scams. |
| Recovery Link | Do not forward reset link or recovery link to anyone. | Reset links can allow account takeover. |
| Shared Devices | Do not save passwords on public/shared computers. | Prevents account access by unknown users. |
| Suspicious Activity | Change password and logout from devices if you suspect compromise. | Reduces further misuse. |
CapHanu Enterprise may force password reset, invalidate sessions, restrict login, or require additional verification if account risk is detected.
💻 Session, Remember Login & Device Security
Sessions allow users to stay logged in while using the website. “Remember me” or similar features may keep users logged in longer on trusted devices. Users should use these features carefully.
- Logout after using public, shared, office, cyber café, friend, or family device.
- Do not use “remember me” on devices you do not fully control.
- CapHanu Enterprise may automatically expire inactive sessions or suspicious sessions.
- Changing password, reporting compromise, or security review may logout existing sessions.
- Device, browser, IP, location, and activity signals may be used to detect suspicious login or misuse.
- Users are responsible for securing their device with screen lock, updated browser, antivirus/security updates, and safe network use.
👛 Wallet, CapCoin, Payment & Order Security
Account security is closely connected with payment, wallet, CapCoin, coupons, gift cards, refunds, COD, referral, and affiliate benefits. Unauthorized account access may lead to misuse of these features.
- Wallet balance, CapCoins, coupons, gift cards, and promotional credits may be protected by login and additional checks.
- Refund requests, bank detail changes, UPI detail submission, and wallet actions may require verification.
- CapHanu Enterprise may block or hold wallet/CapCoin use if suspicious activity is detected.
- Unauthorized payment claims may require order, transaction, device, and account review.
- Never share payment credentials, card details, UPI PIN, OTP, or bank passwords with anyone claiming to process refund.
- Report unauthorized orders, wallet debit, CapCoin misuse, or suspicious refund change immediately.
🔄 Account Recovery, Mobile/Email Change & Ownership Verification
Account recovery helps genuine users regain access, but it also creates risk if someone tries to impersonate the account holder. CapHanu Enterprise may require verification before account recovery or sensitive changes.
- Recovery may require registered mobile/email OTP, order details, identity/account proof, recent activity verification, or support review.
- Changing mobile number, email, refund details, bank/UPI details, or delivery address may require additional verification.
- If registered mobile/email is lost, support may ask for order ID, invoice, account proof, payment proof, or other verification.
- CapHanu Enterprise may refuse recovery if ownership cannot be verified.
- Account recovery may temporarily restrict wallet, refund, payout, digital download, or seller/affiliate actions until risk review is complete.
- Submitting fake proof, forged documents, or false ownership claim may lead to account restriction and legal action.
🛡️ Fraud Protection, Abuse Control & Risk Review
CapHanu Enterprise may use automated and manual risk controls to protect users, sellers, payments, wallet, CapCoins, orders, coupons, referrals, affiliates, digital downloads, and the marketplace from misuse.
| Risk Area | Possible Signal | Possible Action |
|---|---|---|
| Suspicious Login | Unusual device, repeated failed attempts, unusual location/IP, OTP abuse. | Extra verification, temporary lock, forced logout, password reset. |
| Payment Risk | Chargeback, failed payments, mismatched details, suspicious high-value orders. | Order hold, verification, cancellation, refund review. |
| COD Misuse | Repeated refusal, wrong address, fake orders, unreachable phone. | COD restriction, prepaid-only mode, account review. |
| Wallet / CapCoin Abuse | Duplicate accounts, reward farming, fake referrals, offer misuse. | Benefit reversal, wallet hold, reward cancellation. |
| Seller / Affiliate Abuse | Fake orders, self-orders, invalid traffic, payout manipulation. | Payout hold, commission reversal, account restriction. |
| Digital Access Abuse | Excess downloads, link sharing, account sharing, suspicious access. | Download hold, license revocation, account review. |
Risk review may use order history, payment records, device signals, login attempts, support logs, address patterns, return/RTO history, wallet ledger, referral/affiliate data, and security logs.
🎣 Phishing, Fake Support & Scam Protection
Fraudsters may create fake websites, fake customer care numbers, fake WhatsApp support, fake refund links, fake courier links, fake UPI requests, or fake social media pages to steal OTP, payment details, or account access.
- Use only official CapHanu Enterprise website and official support channels.
- Check website URL carefully before entering login or payment details.
- Do not click suspicious links claiming refund, prize, KYC, delivery update, free gift, or urgent account block.
- Do not install screen-sharing apps or remote access apps on request of unknown caller.
- Do not scan QR code to receive money. QR scan is generally used to pay, not receive refund.
- Report fake pages, fake support numbers, suspicious messages, or phishing links immediately.
🏪 Seller, Affiliate, B2B & Partner Account Security
Seller, affiliate, B2B, and partner accounts may include payout details, commission reports, wholesale quotations, customer order records, product listings, business documents, and sensitive operational data. These accounts require extra care.
- Use separate authorized user access where available; do not share one login among many people.
- Keep payout bank/UPI details secure and verify any change request carefully.
- Do not share seller/affiliate dashboard access with unauthorized staff, agencies, or vendors.
- Immediately remove access of former employees, contractors, or partners.
- CapHanu Enterprise may hold payout or commission if account takeover, fraud, fake traffic, or unauthorized bank change is suspected.
- Business users are responsible for internal authorization and safe handling of account credentials.
💾 Digital Product & Download Security
Digital product buyers should protect access links, license keys, dashboard downloads, private files, and account credentials. Unauthorized sharing or weak account security may lead to misuse of digital access.
- Do not share download links, license keys, ZIP passwords, or account access with others unless license allows it.
- Download links may be tokenized, limited, logged, or expired for security.
- CapHanu Enterprise may block suspicious download activity or unauthorized access patterns.
- If your account is compromised, digital product access may be temporarily restricted until verification.
- Refunded, disputed, or chargeback-linked digital orders may lose access.
✅ User Security Responsibility
CapHanu Enterprise provides security controls, but users must also follow safe practices. Many account issues happen because users share OTP, password, payment details, or use unsafe devices.
- Keep your mobile number, email, and account details updated.
- Use a strong unique password and change it if you suspect compromise.
- Do not share OTP, password, recovery link, login link, wallet details, or payment credentials.
- Logout from shared devices and avoid saving passwords on public devices.
- Do not use suspicious browser extensions, cracked apps, malware, or unsafe networks for login/payment.
- Check order history, wallet ledger, CapCoin activity, address book, refund details, and digital downloads regularly.
- Report suspicious activity quickly so support can help reduce damage.
⚖️ CapHanu Enterprise Security Rights
To protect users, sellers, payments, wallet, data, and platform integrity, CapHanu Enterprise may take security actions where risk is detected.
- Temporarily lock or restrict account access for suspicious activity.
- Force password reset, OTP verification, logout from devices, or account re-verification.
- Hold orders, refunds, wallet, CapCoins, affiliate commission, seller payout, or digital access during review.
- Cancel suspicious orders, reverse benefits, restrict COD, block suspicious addresses/devices, or reject risky actions.
- Request ownership proof or identity/account verification where needed.
- Preserve security logs, audit records, IP/device signals, and transaction evidence for legal, fraud prevention, and dispute purposes.
- Take legal action or cooperate with authorities where serious fraud, cyber abuse, payment fraud, or data misuse is suspected.
🚨 Unauthorized Access & Security Incident Reporting
Users should report account compromise or suspicious activity immediately. Fast reporting helps reduce further misuse and improves recovery chances.
| Incident Type | What To Do | Helpful Details |
|---|---|---|
| Unknown Login / OTP | Do not share OTP, change password, logout sessions, contact support. | Time, mobile/email, screenshot, device info. |
| Unauthorized Order | Report immediately and do not accept suspicious delivery. | Order ID, address, payment mode, screenshots. |
| Wallet / CapCoin Misuse | Report ledger entry and secure account. | Transaction ID, amount, date/time, screenshots. |
| Payment Fraud | Contact bank/payment provider and CapHanu support. | Order ID, UPI/card reference, amount, time. |
| Fake Support / Phishing | Do not click/pay/share OTP; report link/number. | Phone number, link, WhatsApp/SMS/email screenshot. |
| Seller/Affiliate Payout Risk | Freeze changes and contact support quickly. | Account ID, changed bank detail, suspicious login, proof. |
Users should also contact their bank, mobile operator, email provider, cybercrime portal, or appropriate authority where payment fraud, SIM swap, identity theft, or cybercrime is involved.
⚠️ Responsibility & Liability Limits
CapHanu Enterprise will make reasonable efforts to secure accounts and support genuine users. However, users remain responsible for losses caused by sharing OTP/password/payment details, using compromised devices, responding to fake links, giving remote access, failing to report promptly, or violating security instructions.
- CapHanu Enterprise may not be responsible for unauthorized activity caused by user negligence, credential sharing, compromised email/mobile, malware, SIM swap, phishing, or third-party fraud outside our reasonable control.
- Security review does not guarantee recovery of all losses, orders, wallet balance, rewards, or access.
- Refund or reversal depends on verification, policy, payment partner rules, bank/cyber investigation, and evidence.
- False unauthorized access claims, fake fraud reports, or manipulated evidence may lead to account action.
📚 Security Logs, Privacy & Data Handling
For account security, CapHanu Enterprise may collect and retain security-related records such as login time, session data, device/browser signals, IP logs, OTP attempts, password reset requests, order actions, wallet/CapCoin activity, support tickets, risk flags, and audit logs.
- Security data may be used for fraud prevention, account protection, dispute resolution, compliance, and legal purposes.
- Security records may be shared internally with authorized teams or externally with payment partners, courier partners, legal advisors, or authorities where required.
- Users should read Privacy Policy and Cookie Policy for broader data handling details.
- Some security records may be retained even after account closure where necessary for legal, tax, fraud, dispute, or audit purposes.
🔄 Policy Updates
CapHanu Enterprise may update this Account Security Policy due to new security features, fraud patterns, payment rules, wallet/CapCoin changes, seller/affiliate changes, digital product access rules, legal requirements, technology updates, or platform improvements.
Updated versions will be published on this page with the latest update date. Continued use of the platform after updates means the user acknowledges the revised Account Security Policy.
📩 Contact & Account Security Support
For account takeover, unauthorized order, suspicious OTP, password reset issue, wallet/CapCoin misuse, fake support scam, payment fraud, seller/affiliate account risk, digital access misuse, or account security clarification, contact official CapHanu Enterprise support channels immediately with complete details.
Please do not share OTP, password, UPI PIN, card PIN, CVV, full card number, bank password, or unnecessary sensitive documents. Share only order ID, ticket ID, transaction reference, screenshots, suspicious link/number, and issue details through official support channels.