Indian food and grocery delivery giant Swiggy has implemented a major update to its payment processing system, requiring users across India to save and tokenise their credit and debit cards separately for its quick-commerce arm, Instamart, and its core food delivery service. This change, driven by strict Reserve Bank of India (RBI) data security mandates, aims to enhance transaction safety but introduces a new layer of friction for millions of daily active users who are accustomed to a unified checkout experience.
The Regulatory Catalyst: RBI’s Tokenisation Mandates
To understand this operational shift, consumers must look to the Reserve Bank of India’s Card-on-File Tokenisation (CoFT) directives. Introduced to safeguard sensitive financial data, these regulations prohibit merchants from storing actual card details like card numbers, expiry dates, and CVVs on their servers. Instead, transactions must be processed using unique, encrypted “tokens” that mask the real card information during payment processing.
Under the RBI framework, these tokens are highly specific and bound to a unique combination of the card, the token requestor, and the specific merchant identity. Because Swiggy Food and Swiggy Instamart operate under different merchant identifiers or distinct business verticals within the parent company, Bundl Technologies, a token generated for one service cannot legally or technically be applied to the other. Consequently, users must explicitly consent to tokenise their cards for each service independently.
The Operational Divide Between Food and Grocery
While Swiggy presents a seamless “super-app” interface to its users, the backend architecture tells a different story. Swiggy’s business operations range from restaurant food delivery to instant grocery fulfillment via Instamart. These services utilize different payment gateways, merchant accounts, and legal agreements with banking partners to manage their distinct supply chains and merchant settlements.
This operational segregation means that when a customer saves a card on the food delivery side, that consent does not automatically extend to the retail grocery side. Industry analysts point out that this strict interpretation of compliance is necessary to avoid regulatory penalties. The RBI has consistently penalized financial entities and payment aggregators that fail to maintain clear boundaries in data sharing and user consent, making compliance a top priority for tech platforms.
Balancing Security and User Friction
Fintech experts view the change as a necessary trade-off between absolute transaction security and user convenience. The RBI’s primary objective is to eliminate the systemic risk of massive data breaches, ensuring that if one merchant database is compromised, the leaked tokens cannot be used elsewhere. While requiring users to save cards twice introduces minor friction, it ensures that a security compromise in one vertical does not automatically expose customer data across the entire platform ecosystem.
According to data from the Indian digital payments sector, tokenised transactions have significantly reduced fraud rates since their industry-wide adoption in late 2022. However, quick-commerce platforms operate on the promise of speed and convenience, where even a few extra clicks at checkout can lead to cart abandonment. Swiggy’s challenge lies in educating its user base that this repetitive step is a security feature mandated by law, rather than a technical glitch in their application.
Future Outlook for India’s Super-Apps
This development carries broader implications for India’s rapidly growing super-app ecosystem, where companies try to bundle travel, shopping, food, and financial services into a single interface. Competitors like Zomato, which operates the Blinkit quick-commerce service, and Tata Neu, which integrates multiple retail brands, face similar compliance hurdles under the current regulatory scrutiny. As the RBI continues to monitor digital payment flows, these platforms must refine their user interfaces to make multi-vertical tokenisation as frictionless as possible.
Moving forward, industry observers expect payment aggregators to develop more unified consent flows that comply with RBI rules while minimizing checkout delays. Consumers should watch for updates from other multi-service applications as they adapt their payment architectures to meet these rigorous security standards, potentially leading to a standardized multi-consent screen during the initial card setup process.

