This policy explains what information The Period Box collects, why we collect it, who we share it with, and the choices you have.
The Period Box is a business application used by organizations to manage sanitary-napkin vending machines and the teams that operate them. Through the app, authorized staff can register and configure machines, track and transfer stock, set pricing and UPI payment details, manage RFID balance cards and member groups, assign machines to operators, and administer user accounts, roles and permissions within their organization.
The app is intended for workplace use. User accounts are created and issued by an administrator at the organization that operates the machines — the app has no public self-registration. If you were given an account, the organization that issued it decides what data is recorded about you and which parts of the system you can reach.
A note on roles. Good Period provides and operates the software and the servers behind it. The organization that issued your account decides what is entered into the system about you and its machines. If your question is about why a particular record about you exists, your organization's administrator is the fastest route; we will still help if you contact us directly.
When your organization creates your account, and when you or an administrator updates it, we process:
This is business data about machines and inventory rather than data about you personally, but it is linked to the account that recorded it:
Requests from the app to our servers necessarily include standard network information such as your IP address and the time of the request, which our servers log to keep the service running and secure. The app itself does not build a profile of you, and it carries no analytics, advertising or crash-reporting SDK.
Signing in also involves an automated anti-abuse check run by Firebase Authentication to confirm the request comes from a genuine installation of this app rather than an automated script. That check processes device signals, and on iOS a push notification token, solely to prevent fraudulent sign-in attempts. It is not used to identify you, to advertise to you, or for any analytics.
To be explicit, The Period Box does not collect, request or transmit:
We do not sell your personal information, and we do not share it with data brokers or advertisers.
| What we use | Why |
|---|---|
| Phone number, OTP, password, session token | To verify it is you and keep you signed in securely |
| Name, username, email, role, organization and branch | To show your profile, and to decide which screens, machines and actions your role is allowed to reach |
| Machine, stock, pricing, RFID and assignment records | To provide the core features of the app and keep an accurate record of machine operations for your organization |
| Network and server logs | To operate the service, diagnose faults, and detect abuse or unauthorized access |
We process this information because it is necessary to provide the service your organization has asked us to provide, to meet our legal obligations, and to keep the service secure. Where the law requires your consent for a particular use, we ask for it and you may withdraw it.
We do not use your information for automated decision-making that produces legal or similarly significant effects about you.
The app is a shared workspace. Administrators and users senior to you in your organization's hierarchy can see your account details, your role and the records you create — for example the stock changes or machine edits made under your account. This visibility is the point of the product and is controlled by your organization's own role and permission settings.
We may disclose information where we are legally required to — for example in response to a valid legal process — or where it is necessary to establish, exercise or defend legal claims, or to protect the rights and safety of users and the public.
If Good Period is involved in a merger, acquisition or sale of assets, your information may be transferred as part of that transaction. We will give notice before your information becomes subject to a different privacy policy.
On Android, the app declares only the two permissions it needs to reach our servers:
INTERNET — to communicate with our backendACCESS_NETWORK_STATE — to detect whether your device is online, so the app can show a meaningful message instead of failing silentlyOn iOS, the app asks for no permission prompts at all. It registers for push notifications, which iOS grants silently and without asking you, because Firebase Authentication uses a silent, invisible notification to verify your device during phone sign-in. The app sends no marketing or alert notifications, and nothing appears on your screen as a result.
No location, camera, microphone, contacts, photo library, storage or other sensitive permission is requested by the app on either platform.
To keep you signed in and to remember your preferences, the app stores a small amount of data locally:
All of it is removed when you sign out, and when you uninstall the app.
No method of transmission or storage is completely secure, so we cannot guarantee absolute security. If we become aware of a breach affecting your personal information, we will notify you and the relevant authorities as required by applicable law.
We keep your account information for as long as your account is active with the organization that issued it. Operational records — stock movements, assignments, pricing changes — are retained as your organization's business records for as long as that organization needs them, and may survive the deletion of an individual account in a form that no longer identifies you. We also retain what we must to comply with legal, tax and audit obligations, and to resolve disputes. When information is no longer needed for these purposes, we delete it or anonymize it.
To request deletion of your account and the personal data associated with it, email appdesign@aalroot.com from the email address on your account, or include your registered mobile number, with the subject “Account and data deletion request”.
We will verify that the request came from you, action it, and confirm in writing. We aim to respond within 7 days and to complete the deletion within 30 days of verifying your identity.
What is deleted: your account record and profile details — name, username, phone number, email address, role and organization assignments — along with the credentials used to sign you in.
What may be retained: operational and transaction records belonging to your organization (for example a stock movement or a machine configuration change) are its business records. Where we must keep them, we sever the link to your personal details or retain them in aggregated form. We may also retain limited information where law requires it, or where it is needed to resolve a dispute or enforce our agreements.
If your account was issued by an employer or another organization, please also inform its administrator, since they control account provisioning on their side. You can remove all locally stored data at any time by signing out or uninstalling the app.
Subject to applicable law, you may:
To exercise any of these, write to appdesign@aalroot.com. We do not charge for this and we will not treat you differently for asking.
The Period Box is a workplace tool and is not directed to children. We do not knowingly collect personal information from anyone under 18 years of age. If you believe a child has provided us with personal information, contact us at appdesign@aalroot.com and we will delete it.
We may update this policy as the app changes or as the law requires. When we do, we revise the “Last updated” date at the top of this page. If a change materially affects how we handle your personal information, we will give you notice in the app or by other reasonable means before it takes effect. Please review this page from time to time.
For any question about this policy, about how your information is handled, or to exercise any of the rights above:
Good Period
Privacy enquiries: appdesign@aalroot.com
Application: The Period Box
Android com.goodperiod.good_period · iOS com.goodperiod.goodPeriod