As Zepto Toggles After IPO Halt, Followed By Private Funding, Questions Around Alleged Dark Patterns Resurface!
How India’s quick-commerce poster boy became a test case for the country’s fight against manipulative app design?
On a Tuesday morning in August 2026, in a chamber of Parliament that rarely concerns itself with the mechanics of a grocery app’s checkout screen, the Indian government read into the record something that had until then lived mostly in regulatory filings and industry newsletters: Zepto, the ten-minute delivery company barrelling toward one of the country’s largest technology IPOs, which is now being halted, had been formally found to have deceived its own customers.
The mechanism was almost banal in its simplicity. A shopper would open the app, fill a cart, and see a price. Then, at the final screen, the one designed to be glanced at, not read, the number would have moved. A “handling charge” had appeared. So had a membership fee for Zepto Pass, the company’s delivery subscription, which had been added to the basket automatically, via a checkbox that was ticked before the customer ever touched it.
The Central Consumer Protection Authority (CCPA), India’s top consumer watchdog, examined this flow and concluded it was not an accident of interface design. It was, in the regulator’s own vocabulary, “drip pricing” — showing a low price up front and inflating it in stages — layered with “basket sneaking,” the act of adding a paid item to a customer’s cart without their consent. The CCPA classified this practice as drip pricing, and identified basket sneaking as Zepto added a paid Zepto Pass membership to the cart by default through a pre-ticked option, without asking for explicit consumer consent.
On December 4, 2025, the CCPA ordered Zepto Marketplace Private Limited to stop, to conduct and publish self-audits, and to pay a penalty of ₹7 lakh — the largest single fine among nine companies penalised in a coordinated crackdown on manipulative app design that also caught IndiGo, BookMyShow, FirstCry and Physics Wallah.
This is a story about that finding, and about everything sitting around it: a regulator experimenting with new enforcement powers, a company that told the same regulator months earlier it had audited itself and found nothing wrong, a labour dispute over delivery pay that the fee increases are entangled with, and a business racing toward a public listing while carrying an unusually candid list of open legal exposures in its own IPO paperwork.
Some of what follows is settled fact — a regulator’s written order, a company’s own disclosure to Indian securities regulators. Some of it is a live, contested fight, with the company’s defence stated plainly alongside the allegation. The distinction matters, and this piece tries never to lose track of it.
What a “Dark Pattern” Actually Means in Indian Law
The phrase gets thrown around loosely, but in India it now has a precise legal definition. In November 2023, under Section 18 of the Consumer Protection Act, 2019, the CCPA notified the Guidelines for Prevention and Regulation of Dark Patterns, which define a dark pattern as a design practice on a user interface that misleads or tricks a user into an action they did not intend, by subverting their autonomy or decision-making, and which amounts to a misleading advertisement, an unfair trade practice, or a violation of consumer rights under the Act.
Annexure I to the guidelines names thirteen specific patterns platforms are prohibited from using: false urgency, basket sneaking, confirm shaming, forced action, subscription traps, interface interference, bait and switch, drip pricing, disguised advertisements, nagging, trick questions, SaaS billing, and rogue malware. The guidelines apply to any platform “systematically offering goods or services” in India, including foreign platforms serving Indian users, and they sit alongside — not instead of — existing law: a dark pattern that also violates the Legal Metrology (Packaged Commodities) Rules, 2011, or the Consumer Protection Act’s separate provisions on unfair trade practices, can be pursued under either or both.
For roughly eighteen months after the guidelines took effect, enforcement was mostly advisory. That changed through 2025. In June, the CCPA directed e-commerce and quick-commerce platforms to conduct internal self-audits and publicly declare compliance. 26 platforms filed declarations; the CCPA published 18 of them in November 2025.
Zepto submitted a self-declaration letter confirming that it conducted an internal review to identify and eliminate manipulative user interface designs, declaring its platform currently free from the 13 dark patterns prohibited by the Department of Consumer Affairs. The company maintains ongoing monitoring to ensure transparency, which followed public admissions by its CEO acknowledging past design mistakes, such as manipulative delivery and pricing fees, that were subsequently rolled back. However, despite these compliance claims and voluntary design corrections, the Central Consumer Protection Authority (CCPA) later penalised Zepto ₹7 lakh for actively deploying deceptive practices, specifically drip pricing and basket sneaking.
That declaration was filed during roughly the same window, June to September 2025, in which an independent citizen-input platform, LocalCircles, was running its own audit. LocalCircles found that 97% of major online platforms continued to use manipulative design, including hidden fees, drip pricing, bait and switch, false urgency, privacy zuckering and forced action, during the exact period the same companies were filing self-audits claiming compliance. A month after Zepto’s “we found nothing” filing became public, the CCPA’s own investigation into the company’s checkout flow concluded with a ₹7 lakh penalty for two of precisely the patterns Zepto had said it did not have.
That is not proof the self-audit was written in bad faith — the guidelines specify no audit methodology, no sampling standard, and no external verification requirement, so a shallow internal review filed in good faith could plausibly miss what a targeted regulatory investigation later found. But it is a fact worth sitting with: the gap between a platform’s own account of its practices and a regulator’s, filed almost simultaneously, was not small.
The Case: What the CCPA Actually Found
The paper trail is unusually well documented for a consumer-protection matter, because Zepto’s own IPO filing lays it out in more procedural detail than most news coverage does.
January 30, 2025 — The CCPA issues a show-cause notice to Zepto Marketplace Private Limited (ZMPL) over two alleged practices: a pre-ticked Zepto Pass membership fee added to carts without consent (basket sneaking), and handling fees disclosed only at the final payment screen rather than in the initial price (drip pricing).
Zepto’s defence, as recorded in the proceedings — the company contested both allegations, arguing that users could see the membership option and remove it with a single click, and that all charges were displayed before payment was made.
December 4, 2025 — The CCPA’s final order rejects that defence. It goes further than a straightforward interface-design finding: the order holds that because the checkout-stage fees pushed the total payable amount above the maximum retail price printed on the packaging, the practice also violated the Legal Metrology (Packaged Commodities) Rules, 2011 — a pre-existing pricing law with nothing to do with dark patterns as a concept.
By framing interface-led pricing practices as MRP violations, the CCPA’s order collapses the distinction between design manipulation and price illegality, a shift analysts say meaningfully raises compliance stakes for quick-commerce platforms, which often structure pricing flows to separate the advertised product price from mandatory add-on charges. The order directs Zepto to stop both practices, to run and publicly disclose regular self-audits, and to pay ₹7 lakh — the highest of the nine penalties issued in the same enforcement wave.
The Fee Stack: How “Free Delivery” Became a Line-Item Business
To understand why a membership fee ended up pre-ticked in a shopping cart, it helps to understand the economics that made platform fees attractive to quick-commerce companies in the first place, and Zepto’s specific role in starting that trend.
Zepto began charging a ₹2 platform fee per order for selected users in March 2024, becoming the first quick-commerce platform in India to introduce such a fee — food-delivery arms of Zomato and Swiggy had charged similar fees before, but no grocery-delivery quick-commerce player had. The timing was not incidental: the fee launched about a month after Zepto began testing its Zepto Pass subscription at ₹99 a month, offering free delivery on orders above ₹99 and discounts up to 20%.
We can drew a direct structural link between the two: subscription customers tend to be less profitable per order, because they cluster orders to make the most of “free” delivery, so platforms that launch subscriptions have an incentive to spread additional fees across the entire user base — subscribers included — to recover the lost margin. Zomato’s experience with Zomato Gold showed exactly this pattern before Zepto’s fee ever launched.
Consumer complaints gathered on forums such as Desidime and Trustpilot, which describe customers being charged what they characterise as unexplained extra amounts per order and receiving coupon-based credit rather than cash refunds when they disputed the charges. These are allegations from individual users, not findings from an investigation, and are presented here only to illustrate the texture of the complaint pattern that eventually fed into the CCPA’s own probe — not as independently established fact.
The broader industry context matters here too. In 2024, a distributor federation representing traditional retailers, the All India Consumer Products Distribution Federation, filed a formal complaint with the Competition Commission of India alleging that Zepto, along with Blinkit and Swiggy Instamart, was engaged in predatory, below-cost pricing designed to drive smaller retailers out of business; a claim the CCI’s chairperson has said the regulator now has new cost-assessment tools to properly evaluate, though no formal finding against any named platform has yet been issued.
That complaint, alongside a second one that specifically named Zepto Marketplace, led the CCI to seek information from the company in mid-2026; Zepto’s IPO filing confirms the CCI has not opened a formal investigation, and that the company intends to contest any proceedings that follow. This is a separate legal track from the dark-patterns matter — predatory pricing is a competition-law question, not a consumer-protection one — but it belongs in the same picture: a company simultaneously accused of overcharging individual customers through hidden fees and of underpricing the broader market to squeeze out competitors, two allegations that are not contradictory so much as they describe different sides of an aggressive, IPO-driven push for both revenue and market share.
The Membership Trap Question
Zepto Pass itself, the subscription whose pre-ticked default became the centrepiece of the CCPA’s basket-sneaking finding, has drawn a further layer of consumer complaint around its cancellation flow: users describing confusing renewal-decline language and difficulty finding a cancel option inside the app.
They are noted only because they align directionally with the CCPA’s own “subscription trap” category and with the basket-sneaking finding already confirmed in the December 2025 order — the membership being defaulted-on at checkout and the membership being hard to cancel would, if both true, be two ends of the same design problem. Only the first half of that has been formally adjudicated.
Ten Minutes, and What It Costs to Deliver Them
Dark patterns in the strict CCPA sense are about interface design and pricing disclosure. But “10-minute delivery“, the promise that built Zepto’s entire brand, sits adjacent to that category as a marketing claim under sustained government pressure, and its consequences reach into a different area entirely: labour conditions for the workers who have to make the promise true.
In January 2026, following closed-door meetings between the Union Labour Ministry and executives from Blinkit, Zepto, Zomato and Swiggy, the government asked quick-commerce platforms to stop explicitly advertising 10-minute delivery timelines, citing safety concerns for gig workers. Blinkit changed its tagline from promising “10 minutes” to promising delivery “at your doorstep”; Swiggy stopped promoting Instamart as a 10-minute service; Zepto removed 10-minute branding from its marketing to comply with the directive.
The discussions followed nationwide strikes by delivery riders over pay, safety and working conditions late in 2025. Notably, Eternal (Blinkit’s parent) told stock exchanges the change was cosmetic and did not alter the underlying business model, which was a useful reminder that a branding rollback is not the same as an operational one.

The mechanics behind the promise explain why regulators were worried. Industry reporting describes a typical dark store operating with four to eight pickers, one to two supervisors, and six to twelve delivery riders per shift, with pickers scanning and packing an order in roughly thirty seconds to two minutes under ideal conditions, leaving riders with as little as seven to eight minutes to complete the actual delivery — a window that leaves almost no margin for traffic, building access, or any other real-world friction. Moneycontrol has reported that riders sometimes take around fourteen minutes to complete deliveries once promised in ten, with partners describing 15–20 minute actual delivery times during peak demand.
This is where the labour allegations become directly relevant to a piece about consumer-facing design, because the same profitability pressure that produced the fee stack shows up on the workforce side of the ledger.
In May 2025, the Telangana Gig and Platform Workers’ Union wrote to the state’s Department of Labour alleging Zepto paid delivery workers as little as ₹10–15 per order — well below what the union characterised as a living wage — while imposing 10–15 minute delivery deadlines the union said forced workers to drive at unsafe speeds, on top of arbitrary fines, ratings-based penalties, and account suspensions without clear appeal, and a lack of basic facilities like restrooms at dark stores. One rider quoted in MediaNama’s reporting said weekly order targets had risen from roughly 230 to 300–330 without a proportional increase in pay, while delivery radii had grown from two–three kilometres to around 4.5 kilometres in the same period.
Zepto’s response was specific and on the record, not a generic denial. The company told PTI that 97% of its per-order cost goes to delivery partners, that Hyderabad riders were earning ₹100–120 per hour with earnings holding steady, that its payouts were transparent with 2X incentives for peak summer shifts and full flexibility over working hours, and it directly called “allegations of low or inconsistent pay… simply untrue.”
The company also said it does not rush deliveries or penalise workers for delays, that partners carry insurance coverage up to ₹1 lakh, and that dark stores provide shaded rest areas and free drinking water. Both accounts cannot be fully reconciled from outside — this is a genuine dispute between the union’s figures and the company.
Beyond that specific dispute, Zepto’s own IPO filing discloses a broader pattern of labour friction that the company itself chose to make public to securities regulators: a May 2025 strike in Hyderabad over low payouts and incentives, a second strike in Delhi in October 2025 over Diwali incentives, brief disruptions at a small number of dark stores in December 2025, ongoing minimum-wage proceedings brought by Karnataka labour authorities against Zepto representatives, and a September 2024 criminal complaint filed by a labour inspector against co-founder Kaivalya Vohra alleging the company failed to maintain wage registers and issue wage slips.
The same filing notes Zepto held discussions during both strikes but did not change its fee or incentive structures as a result, and that the company has moved 48,011 workers who were previously staffed through third-party contractors — pickers, packers, hub loaders and other dark-store roles — onto its own payroll, a move it says improves operational control and compliance.
Marketplace Integrity: What Gets Listed, and What Stays Listed
A separate, related thread concerns not Zepto’s own checkout design but the products sold on its marketplace by third-party brands, which is a governance question about what a platform is responsible for policing.
In June 2026, India’s food safety regulator FSSAI issued notices to fourteen direct-to-consumer food brands over misleading branding and health claims, including a pomegranate juice the regulator said implied it was pure juice while actually containing about 4% pomegranate concentrate, and a “Zero Maida” bread claim FSSAI said was misleading given the product’s actual ingredients. A MediaNama analysis found that most of the flagged products remained available with the same disputed claims on Blinkit, Zepto, Swiggy Instamart, Amazon Fresh and Flipkart Minutes, with the outlet specifically documenting a “Zero Maida” bread listing still live on Zepto after the FSSAI notice.
This is not a dark pattern under the CCPA’s checkout-focused definition, but it speaks to the same underlying question the guidelines are trying to address: whether a platform’s interface accurately represents what a consumer is buying. It is also worth noting for balance that a broader Scroll.in investigation into FSSAI’s flagging system found this is an industry-wide enforcement gap, not something specific to quick commerce — of 163 cases FSSAI’s own internal committee discussed as far back as 2022, most of the flagged products were found to still be in circulation years later, across e-commerce broadly, not on any single platform.
Separately, and on a narrower, Zepto-specific basis, an Economic Times-sourced report from mid-2024 described regulatory crackdown escalating surprise hygiene audits at quick-commerce dark stores after a customer reported finding worms in oranges ordered from Zepto, and another customer reported finding a dead mouse in a bottle of Hershey’s syrup ordered from the platform. These are individual consumer complaints reported by a business outlet, not adjudicated regulatory findings, and are included here as evidence of the kind of consumer-facing quality complaint that has periodically accompanied Zepto’s growth — not as proof of systemic food-safety failure.
On advertising specifically, it is worth noting a case that cuts the other way. Zepto’s IPO filing discloses that it periodically receives inquiries from the Advertising Standards Council of India, and that in one instance a consumer alleged Zepto’s promotional banners were misleading — a complaint ASCI reviewed and dismissed, concluding the app adequately displayed its qualifying conditions and that the advertisement was not misleading. This is a rare instance in Zepto’s regulatory record of a formal complaint that did not result in an adverse finding, and it belongs in this article for the same reason the CCPA order does: because an evidence-based account has to include the exonerations as well as the penalties.
Zepto Against Its Peers
How does Zepto’s record compare with Blinkit (Eternal/Zomato), Swiggy Instamart, and BigBasket? The honest answer is that the comparison is uneven, because the available evidence is uneven, not because one platform is demonstrably cleaner than another.
On the self-audit disclosures published by the CCPA in November 2025, the clearest split was not quick-commerce-versus-e-commerce but depth-of-review-versus-shallow-assurance. Flipkart, Myntra and Walmart India were the only companies that commissioned an external reviewer — Deloitte — to test their interfaces and disclosed that the review had identified potential dark patterns which were then remediated. Every quick-commerce platform, Zepto included, relied on internal review only.

Eternal and Blinkit both stated they had conducted internal reviews and were “materially compliant,” without describing what was tested or whether issues were found; Swiggy reported it had tested for all thirteen patterns and found itself “materially in adherence,” again without describing its process; BigBasket’s declaration was the thinnest of the group, stating only that it had conducted an internal review and remained “committed to transparency.”
On regulatory enforcement, Zepto is, as of this writing, the only quick-commerce platform among the nine companies fined in the CCPA’s 2025–26 enforcement wave; Blinkit, Instamart and BigBasket do not appear in that specific order.
That does not establish that Zepto’s practices were categorically worse than its competitors’: it establishes that Zepto was the platform the CCPA investigated and found violations against, in a landscape where the LocalCircles audit found manipulative design present on 97% of the 290 major platforms it examined, quick commerce among the sectors it flagged as having the highest concentration of dark patterns. Absence of a competitor’s name from a CCPA order is not the same as a clean bill of health; it may simply mean no formal case has yet concluded.
On platform fees, the direction of travel is industrywide rather than Zepto-specific. Zepto introduced the first quick-commerce platform fee in March 2024; Swiggy subsequently increased its own platform fee from roughly ₹3 to ₹10 in a “take-rate experiment,” suggesting an industry-wide pattern of spreading subscription-driven margin loss across the wider user base rather than a Zepto-specific innovation. On predatory-pricing scrutiny, the AICPDF’s core CCI complaint named Blinkit, Swiggy Instamart and Zomato specifically, alongside Zepto, as platforms allegedly selling below cost to capture market share — this is a shared industry accusation, not one isolated to any single company.
The Behavioural Economics of a Pre-Ticked Box
It is worth pausing on why regulators treat something as small as a pre-checked box as a serious violation rather than a trivial UI choice, because the psychological mechanics are well studied and not particularly subtle.
A pre-ticked default exploits what behavioural economists call status-quo bias: people are measurably more likely to keep whatever option is already selected than to actively change it, even when the two options require identical effort to choose. This is precisely the mechanism the CCPA’s basket-sneaking finding targets — a customer who would very likely have declined a paid membership if asked directly is, instead, asked to notice and actively remove it, and a meaningful share of people simply will not.
Drip pricing works through anchoring: the first number a shopper sees becomes their reference point for what the purchase “costs,” and by the time additional charges appear at the final screen, the sunk psychological (and often literal, cart-filling) investment makes abandoning the purchase over an unexpected ₹15 handling fee feel disproportionate, even though the same person would likely never have started the purchase had the true total been shown up front. Confirm shaming — the pattern behind IndiGo’s “No, I will take the risk” language, which the CCPA also acted on in the same enforcement wave — works through loss aversion and social discomfort, framing the act of declining an add-on as an admission of recklessness rather than a neutral choice.
None of this requires assuming bad intent on the part of any individual product designer. These patterns are, almost by definition, effective precisely because they exploit well-documented, universal features of human decision-making rather than any particular company’s malice — which is exactly why regulators have concluded that disclosure and default-design rules, rather than appeals to corporate goodwill, are the only durable fix.
The Business Behind the Design Choices
None of the above happens in a vacuum. Zepto’s IPO filing — its updated draft red herring prospectus, filed with SEBI on June 8, 2026 for a fresh issue of ₹8,010 crore — puts a number on the pressure the company is under. Zepto has not reported a profit since launching in July 2021: revenue from operations reached ₹22,623.6 crore in FY26, more than double the ₹11,109.9 crore of FY25, but the full-year loss also widened, to ₹5,905.2 crore in FY26 from ₹4,699.7 crore in FY25 and ₹1,214.8 crore in FY24. The company operated 1,139 dark stores across 66 cities and served 47.97 million annual transacting users as of March 31, 2026.
That same filing is unusually candid — likely because securities law compels the disclosure — about the scale of regulatory and legal exposure sitting alongside the dark-patterns case: Enforcement Directorate summons to both founders under India’s foreign-exchange law over the company’s status as a “foreign owned and controlled” entity, a pending accessibility lawsuit over the platform’s usability for people with disabilities, contested trademark applications including for “Zepto Pharmacy” and “Zepto Atom,” and an acknowledgment that compliance with India’s new Digital Personal Data Protection Act will raise costs going forward, alongside no material data breach reported in the past three financial years.
None of this is a dark pattern in the CCPA’s technical sense, but taken together it paints a picture of a company disclosing, in its own words to regulators, a wide and specific list of live legal fronts — a useful corrective to any narrative, in either direction, that either overstates or understates how contested Zepto’s compliance record currently is.
It is also relevant, and rarely stated plainly, that dark-pattern enforcement in India currently generates a striking mismatch between the scale of the alleged harm and the size of the penalty. The CCPA’s entire nine-company enforcement wave collected roughly ₹20 lakh in total penalties — a figure a company the size of Zepto, now disclosing revenue in the tens of thousands of crores, could absorb without materially affecting a single quarter.
A separate industry report cited by MediaNama estimated dark patterns generate up to ₹28,000 crore annually in additional revenue across Indian online marketplaces as a whole — a figure that, if directionally accurate, dwarfs the deterrent value of the fines currently being levied by several orders of magnitude. That gap is arguably the central policy question the Zepto case raises: not whether the specific practices were wrong (the CCPA has already ruled on that, pending appeal), but whether the current penalty structure gives any large platform a real incentive to change before being caught.
Zepto’s own self-audit declaration, filed shortly before that order and asserting the platform was free of all thirteen defined dark patterns, is a matter of public record. Zepto introduced the first platform fee in Indian quick commerce, in March 2024. The government-mandated rollback of explicit “10-minute” marketing claims, in January 2026, is confirmed by multiple outlets and by the companies’ own public statements. Labour strikes in Hyderabad and Delhi, a criminal complaint against a Zepto co-founder over wage-record compliance, and ongoing Karnataka minimum-wage proceedings are all disclosed in Zepto’s own IPO filing.
What It Means
Set against India’s own definition of a dark pattern, the record on Zepto specifically is neither the sweeping indictment a headline like “Zepto deceives customers” would suggest, nor the clean bill of health the company’s own self-audit claimed months before a regulator found otherwise. It is something more specific and, in its way, more useful: a single, well-documented regulatory finding against one company, for two clearly defined practices, sitting inside a much larger pattern of industry-wide fee inflation, self-regulation that independent audits suggest is not working, and a penalty regime whose current scale looks unlikely to change corporate behaviour on its own.

For regulators, the case is a template — the first time India’s dark-patterns guidelines have been fused with a pre-existing pricing statute to produce real financial consequences, and a live test, via the NCDRC appeal, of whether that legal fusion holds up. For consumers, it is a reminder that a platform’s own claim of compliance, filed in a regulatory disclosure, is not the same thing as a regulator’s independent finding — and that the gap between the two, at least in Zepto’s case, turned out to be real.
For Zepto, heading toggling between a public listing with a widening loss, and private funding, a stack of open legal fronts disclosed in its own IPO paperwork, and a fee structure it pioneered and its competitors have since matched, the dark-patterns order is one item on a longer list — but it is the one item where an independent regulator has already looked closely and ruled, at least provisionally, against the company’s own account of itself.



