Payments & udhaarPublished 14 Jun 2026 11 min read

UPI for business: QR codes, limits, MDR, refunds and matching payments to invoices

Static vs dynamic QR, UPI ID vs merchant VPA, what MDR you pay (usually none), transaction limits, sound boxes, reconciling UPI credits with invoices.

UPI for business: QR codes, limits, MDR, refunds and matching payments to invoices

UPI is now the default way Indian customers pay small businesses, and for most shops it costs nothing per transaction. Getting it right means choosing the right kind of QR, using a merchant VPA on a current account instead of your personal ID, knowing the limits, and having a routine for matching every UPI credit to an invoice so your books and your bank agree. This guide covers all of that, plus refunds, sound boxes and the collect-request frauds that target shopkeepers.

UPI ID vs merchant VPA: use the right one

Every UPI account has a virtual payment address, or VPA, like name@bank. A personal VPA is linked to your savings account and created in seconds from any UPI app. A merchant VPA is linked to a current account, is created through your bank or a payment service provider such as a payment app's business version, and comes with merchant features: higher receiving limits, settlement reports, a merchant category code, and the ability to generate dynamic QR codes and payment links.

Use a merchant VPA on a current account for the business. Three reasons. First, mixing business receipts into a personal savings account makes bookkeeping painful and looks bad under scrutiny. Second, personal accounts have per-day and per-transaction caps that a busy shop will hit. Third, a merchant VPA gives you daily settlement statements that you can reconcile against invoices. If you do not yet have a current account, /blog/current-account-opening-guide walks through the documents.

Register the merchant VPA under your trade name so the customer's app shows "Sharma Electricals" and not "Rakesh Kumar Sharma". Customers hesitate less when the name on screen matches the board on the shop.

Static vs dynamic QR: which one for which purpose

A static QR is a printed code that encodes your VPA and name. It sits on the counter, the customer scans it, types the amount, and pays. It never changes, costs nothing, and works with every UPI app. Its weakness is that the customer types the amount, so wrong amounts happen, and the payment arrives with no reference to a bill.

A dynamic QR is generated per transaction. It encodes your VPA, the exact amount, and a transaction reference (your invoice number, for example). The customer scans, sees the amount already filled, and confirms. Dynamic QRs are what you want on invoices, delivery challans and payment links, because the credit that lands in your bank carries the amount and reference you set, which makes matching automatic.

FeatureStatic QRDynamic QR
AmountCustomer types itPre-filled
Reference to invoiceNone unless customer adds a noteBuilt in
Where it works bestShop counter, delivery boy's phoneInvoices, payment links, WhatsApp
SetupPrint onceGenerate per bill
Risk of wrong amountYesNo
CostFreeFree

For a shop, use both. A static QR on the counter for walk-ins, and a dynamic QR or link on every credit invoice and quotation so customers pay the exact amount. A UPI QR generator will produce either from your VPA.

Sound box: worth it or not

A sound box is a small speaker linked to your QR that announces "Received ₹450" when a payment lands. It exists to solve one problem: the customer showing you a screenshot of a "successful" payment that never actually reached your account. With a sound box, you do not look at the customer's phone; you listen for your own confirmation.

Most payment apps rent sound boxes for a small monthly fee or a one-time deposit. For a shop doing more than 30 or 40 UPI transactions a day, it pays for itself in saved arguments and avoided fake-screenshot losses. For a business that mostly invoices on credit and gets paid later by bank transfer, it is unnecessary. If you take one, make sure it is linked to the merchant VPA on your current account, not to a staff member's personal account.

MDR: what you actually pay

MDR (merchant discount rate) is the fee a merchant pays on card payments, typically 1 to 2 percent. For UPI person-to-merchant transactions, government policy has kept MDR at zero, and the same zero-MDR rule covers RuPay debit cards. That is why a small shop can accept UPI without any per-transaction cost. The government has also been reimbursing banks and payment apps through an incentive scheme for small-value UPI merchant transactions, which is why the apps are keen to sign you up.

Two things to watch. There has been recurring public discussion about introducing MDR for large merchants (above a turnover threshold) or on certain UPI instruments such as credit cards on UPI and prepaid wallets; check the latest RBI and NPCI circulars before assuming anything for a larger business. And payment apps make money elsewhere: sound-box rent, settlement to a "wallet" that you then pay to withdraw, merchant loans, and premium dashboards. Read what you are signing up for. Zero MDR does not mean zero fees.

UPI limits you will run into

The general per-transaction limit for UPI is ₹1,00,000. NPCI allows higher limits for specified categories such as hospitals, educational institutions, tax payments, IPO applications and certain insurance and bill payments, in some cases up to ₹5,00,000, and it revises these from time to time. Banks may also set their own lower daily caps on personal accounts, often 20 transactions or ₹1,00,000 a day. Merchant VPAs on current accounts generally have higher receiving limits, which is another reason to use one.

Practical implications for a business:

  • A customer paying a ₹1,80,000 invoice by UPI will need two transactions, or NEFT/IMPS instead. Put your bank details on the invoice alongside the UPI QR.
  • UPI Lite handles small payments (up to a few hundred rupees) without a PIN, which speeds up a busy counter. It is a payer-side feature; you need nothing special to receive.
  • UPI AutoPay lets a customer set up a recurring mandate, useful for subscriptions, rentals and monthly retainers. Small-value mandates run without a PIN each time; larger ones need the customer to approve. If you sell on a monthly basis, AutoPay is a better collection tool than reminders.

Remember also that the Income Tax Act's Section 269ST prohibits receiving ₹2,00,000 or more in cash from a person in a day, per transaction or per event, but UPI is not cash, so large UPI receipts are fine from that angle. See /blog/cash-transaction-limits-income-tax.

Reconciling UPI credits with invoices

This is where most small businesses lose control. UPI money arrives in dozens of small credits with descriptions like UPI/512345678901/Payment from PhonePe/name@ybl. Three weeks later, nobody knows which credit was for which invoice, the customer ledger shows balances that do not match what the customer believes, and your CA gets a bank statement with 900 unmatched lines.

A workable routine:

  1. Put a reference on every request. Dynamic QR and payment links carry your invoice number. For static QR payments, ask the customer to type the bill number in the remark. Print "Please mention invoice number in UPI remark" on the invoice.
  2. Issue a receipt the same day. Every UPI credit against a credit invoice gets a numbered receipt that quotes the UPI transaction ID (the 12-digit UTR-style reference). The receipt is what updates the customer ledger. Counter sales paid by UPI on the spot do not need a separate receipt; the invoice marked "Paid by UPI, ref 5123..." is enough.
  3. Match weekly, not monthly. Download the merchant settlement report or bank statement every Friday and tick each credit against a receipt. Anything unmatched is either a customer who forgot to tell you, a wrong amount, or a payment to the wrong VPA.
  4. Handle differences immediately. A customer who paid ₹4,500 against a ₹4,550 invoice has a ₹50 balance; either collect it or write it off with a credit note. Do not let small differences accumulate.

VyaparKit's bank statement to Excel converter turns a PDF statement into a spreadsheet so you can filter UPI lines by amount and reference, but note that it does not do the matching for you; that remains a weekly human job.

Worked example: a Pune freelance designer

Priya, a freelance graphic designer in Pune, sends 15 to 20 invoices a month, mostly between ₹8,000 and ₹40,000. She used to share a static QR and got payments with no reference. In April she received ₹1,72,000 across 19 UPI credits and could match only 11 of them to invoices without calling clients.

She switched to sending each invoice with a payment link carrying the invoice number. In May, 17 of 18 UPI credits arrived with the invoice number in the remark. Matching took 15 minutes. The one exception was a client who paid ₹18,000 against two invoices of ₹10,000 and ₹8,000; she issued two receipts against the single UTR and noted it in both. Her outstanding statement at month-end was correct for the first time, and one client who believed he had paid was shown the ledger and found he had paid a different vendor by mistake.

Refunds and reversals

There are three situations that look similar to a customer but are different for you.

Failed transaction, money debited. The customer's app shows failed or pending, but their bank has debited. This is a bank-side reversal, not your refund. The money never reached you. Tell the customer to wait; RBI rules require auto-reversal within a set turnaround time (T+1 for most UPI failures) and pay compensation to the customer if the bank is late. Never hand over goods against a pending screenshot.

Genuine refund for a return or cancellation. The money reached you and you are giving it back. Refund it to the same VPA it came from, using your app's refund function or a fresh UPI transfer, and issue a credit note against the original invoice so GST and the customer ledger are correct. Keep the refund's UTR with the credit note. If you are registered under GST, the credit note must be reported in your return and follows the rules in /blog/credit-note-debit-note-guide.

Wrong-amount or wrong-recipient payments. A customer paid ₹5,400 instead of ₹4,500, or paid you when they meant to pay someone else. Refund the excess or the full amount promptly and keep a record; a small business that refunds fast builds trust, and unexplained credits in your account are a headache at year end.

Fraud red flags every shopkeeper should know

UPI's simplicity is also its weak spot. The frauds that target merchants almost always work by getting you to approve something instead of receiving something.

  • Collect requests. A "customer" says the payment is stuck and asks you to accept a request on your phone "to release it". A collect request that you approve sends money from your account. You never need to enter your PIN or approve anything to receive money. Ever.
  • Fake payment screenshots. Edited screenshots of successful payments. Use a sound box or check your own app before handing over goods; the customer's screen is not proof.
  • "Refund" scams. Someone claims they overpaid you and asks you to send back a "refund" before the original credit has actually landed. Check your statement first.
  • QR sticker swaps. Fraudsters paste their own QR over yours on the counter or shutter. Check your QR sticker every morning and scan it yourself once a week to confirm the name that appears.
  • Screen-sharing and remote-access apps. Anyone asking you to install an app to "fix" a UPI problem is stealing from you.
  • KYC and "your VPA will be blocked" calls. Banks do not ask for PINs or OTPs. Disconnect and call the bank's number from its website.

If money leaves your account by fraud, report it to your bank within hours (the RBI's limited-liability rules protect customers who report fast), call the national cybercrime helpline 1930, and file at cybercrime.gov.in.

Accounting for UPI receipts

For your books, UPI money is bank money, not cash. Treat every UPI credit as a bank receipt in the bank book, referenced to a receipt or an invoice. This matters for three reasons.

First, the cash limits under Sections 40A(3) and 269ST do not apply to UPI, so a large UPI receipt does not need the care a large cash receipt does. Second, under presumptive taxation, Section 44AD deems profit at 6 percent of turnover received through banking channels and digital modes, against 8 percent for cash; keeping UPI receipts clean and separately identifiable directly lowers deemed income for many small traders. Third, GST is due on the invoice (time of supply), not on the receipt, so a UPI receipt does not change your GST liability; it only settles the customer's balance.

Settlement timing matters too. Some payment apps settle to your bank account the next working day, and some park money in a wallet first. Record the receipt on the date the customer paid (the UPI transaction date), not the date the app settled to your bank, and reconcile the wallet-to-bank transfer separately. Your bank statement conversion and weekly matching will catch the timing differences.

Common mistakes

  • Receiving business money on a personal VPA linked to a savings account.
  • No reference on the payment, so credits cannot be matched to invoices.
  • Approving a collect request to "receive" money.
  • Handing over goods against a screenshot of a pending payment.
  • Not issuing a credit note for refunds, so the GST return and ledger both go wrong.
  • Recording UPI receipts on the settlement date instead of the payment date.
  • Assuming zero MDR means zero fees; read the app's fee schedule.

How VyaparKit helps

Every invoice, quotation and receipt you make in VyaparKit can be shared as a link with a Pay-via-UPI button and a dynamic QR for the exact amount, and the UPI QR generator makes a static QR for your counter from any VPA. The UPI payment link tool builds a link with the amount and reference you can drop into a WhatsApp message. When money arrives, the payment receipt records the UPI reference and updates the customer ledger. VyaparKit does not reconcile your bank statement for you, but the weekly matching routine above takes minutes once every request carries a reference.

Next steps

  • Open a current account and get a merchant VPA in your trade name.
  • Print a static QR for the counter and check the name it shows when scanned.
  • Add a dynamic QR or payment link with the invoice number to every credit invoice.
  • Set a Friday slot to match UPI credits against receipts.
  • Brief your staff: never approve a collect request, never trust a screenshot.

Frequently asked questions

Is there any charge for accepting UPI payments in a shop?
For most merchants, no. Government policy has kept MDR at zero for person-to-merchant UPI payments, and the same applies to RuPay debit cards. Some payment apps charge for extras such as a sound box, a settlement account or loans, and there has been public discussion about MDR for large merchants, so check the latest NPCI and RBI position, but a small shop today pays nothing per transaction.
What is the difference between a static and a dynamic UPI QR code?
A static QR encodes your UPI ID and name; the customer types the amount. A dynamic QR is generated per bill with the amount and a reference already filled in, so the customer only confirms. Static is fine for a counter; dynamic is better for invoices because the payment arrives with the exact amount and a note you can match to the bill.
Can I use my personal UPI ID for business payments?
You can receive money on it, but you should not. Personal VPAs have lower daily limits, mix business and personal money in one bank account, and give you no merchant features such as settlement reports. Open a current account, get a merchant VPA from your bank or a payment app, and keep business receipts separate. Your CA and the income tax department will both thank you.
What should I do if a customer's UPI payment failed but money was debited?
Tell the customer to wait; failed UPI debits are auto-reversed, usually within a few hours and at most within a few working days. Do not issue goods against a screenshot of a pending or failed transaction. If the reversal does not happen, the customer raises a dispute in their app, and the bank must resolve it within the RBI's turnaround time.

This guide is general information for Indian small businesses as of 14 Jun 2026. Rates, thresholds and due dates change by notification; confirm the current position on the relevant government portal or with your chartered accountant before acting.