Introduction
Freecharge Payment Technologies Pvt Ltd. takes the security and privacy of its systems, applications, and customer data with the highest priority. We are committed to maintaining a secure and resilient environment for all users, partners, and stakeholders. If you identify any potential security vulnerability related to Freecharge Payment Technologies Pvt Ltd. services, we encourage responsible disclosure in accordance with our Responsible Disclosure Policy.
Freecharge Payment Technologies Pvt Ltd. is committed to promptly acknowledging, validating, and remediating reported vulnerabilities while collaborating transparently with security researchers. We will not pursue legal action against good-faith researchers complying with this policy and will recognize responsible contributions through our Security Hall of Fame.
Responsible Disclosure Policy
At Freecharge Payment Technologies Pvt Ltd., the security of our customers’ information and payment transactions is our highest priority. We value the contributions of security researchers and ethical hackers in helping us identify potential vulnerabilities and strengthen our defences. We are committed to validating and addressing reported vulnerabilities in accordance with our policies and applicable laws. Any testing, research, or activities conducted outside the scope of this policy, or in violation of applicable laws and regulations, may result in Freecharge exercising its legal rights, including reporting such activities to law enforcement authorities and pursuing appropriate legal action.
Response Targets
We will do our best to keep you updated on the progress of your report from start to finish.
Program Rules
Researchers are expected to act in good faith and avoid privacy violations, data destruction, or disruption of services. Please only test accounts you own or have explicit authorization to access.
Please refrain from the following activities:
- We will acknowledge your submission only if you are the first person to report the vulnerability.
- Previously reported or known issues will not be considered valid submissions.
- Avoid privacy violations, service disruption, or data destruction during testing.
- Do not access other users' accounts, data, or personal information.
- Use your real email address for registration and vulnerability reporting.
- Keep all discovered vulnerabilities confidential until officially fixed and approved for disclosure.
- Do not perform harmful activities such as DDoS, spam, or attacks affecting service reliability.
- Do not use automated scanners or noisy tools for vulnerability testing.
- Add a custom header in all testing traffic: X-Bug-Bounty: RDP-<random_uuid> and ensure all submitted findings are original and authorized for disclosure.
Vulnerability Report Requirements
To help us check and fix issues quickly, every report must include:
- A clear description of the vulnerability
- Step-by-step instructions to reproduce the issue
- What could happen because of this issue, and which systems are affected
- Proof of the issue — screenshots, videos, or test scripts
- Any special setup needed to reproduce the issue
- Your name and email address so we can contact you
In Scope of this Policy
- Domains: *.freecharge.in and *.freechargepg.in
- Freecharge Android apps on the Google Play Store
- Freecharge iOS apps on the Apple App Store
Out of Scope Vulnerabilities
The items below are not covered by this program. They are not eligible for rewards or acknowledgment unless there is a clear and serious security impact.
General Exclusions
- Issues in third-party services or software that we do not own or manage
- Any domain, app, or service not listed in the In Scope section
- Duplicate reports or issues we are already working to fix
- Reports that only suggest best practices with no real security risk
- Multiple reports of the same type of issue with only small differences
- Issues that need physical access to someone else's unlocked device
- Actions that could slow down or break our services
- Phishing, social engineering, or any attacks that target people
Low-Risk or Informational Findings
- Missing security headers with no proven real-world impact
- Clickjacking issues with no clear sensitive impact
- Open redirects with no security risk
- Text injection or self-XSS
- DOM-based Self-XSS
- Formula Injection / CSV Injection
- Reports about outdated libraries or missing patches with no working proof of exploit
- Missing CAA records
- Security patches released in the last 30 days
- Software version or banner info visible on public services
- Public files like robots.txt being accessible
- Pages that return a 404 or other non-200 error response
- SSL pages that can be cached
- General network observations with no real security risk
Authentication, Session & Account Related
- Session timeout concerns
- Missing CAPTCHA
- Browser auto-fill or save password features
- Password complexity recommendations
- Brute-force on the forgot-password flow with no proven account takeover
- Email or phone number enumeration with little or no impact
- IDOR reports where you already had permission to access the object
SSL/TLS & Email Related
- SSL/TLS issues with low real-world impact
- SPF, DKIM, or DMARC configuration observations
- Acceptance of Gmail "+" or "." aliases
- Email subscription or unsubscribe-related issues
- Email flooding or email bomb attacks
Abuse & Business Logic Exclusions
- Brute-forcing promo codes, referral codes, or coupons
- Attempts to change prices without completing an unauthorized transaction
- Rate-limiting issues unless they lead to a real security or data risk
Browser & Platform Limitations
Issues found only on old, unsupported, or end-of-life browsers or operating systems. We have the final say on whether any report is eligible, how serious it is, and what impact it has.
Our Commitment to Researchers
If you find a valid security vulnerability and follow this policy, we will:
- Acknowledge your report when we receive it.
- Work with you to understand and confirm the issue.
- Fix the issue as our security team sees fit.
- Work with you, where possible, to stop misuse and strengthen our defences.
Rewards & Recognition
- We do not currently run a public bug bounty or monetary reward program.
- We do not pay for reports. But we value your help and may publicly recognise good reports.
- We may launch a paid bug bounty program in the future. If we do, we will post the details here.
Public Disclosure Policy
This program has a strict non-disclosure rule. You must not share, publish, or talk about any vulnerability you find here without our written permission first. Doing so may lead to legal action.