KaliCartKaliCart
Bridge Solutions Docs MCP Spec Blog Download EN·IT·DE·FR·ES
KaliCart Bridge

Privacy Notice

Last updated: 17 July 2026

This notice explains the two external connections used by the standalone KaliCart Bridge distribution: automatic software update checks and the built-in KaliCart Global federated catalog. Neither service receives customer, order, cart, credential or private catalog data.

Software update checks

When WordPress performs its normal plugin update check, the standalone distribution requests https://bridge.kalicart.com/updates/kalicart-bridge.json. The response contains the current version, WordPress and PHP compatibility fields, changelog information and the HTTPS URL of the versioned plugin ZIP.

The request does not contain the store URL, catalog, customers, orders, credentials or API keys. Its User-Agent identifies only the installed KaliCart Bridge version. As with any HTTPS request, normal network metadata such as the requesting server’s IP address is visible to the update host. A package is downloaded only when an administrator or WordPress automatic updates starts an upgrade.

Built-in Federated Catalog

Federated discovery is an intrinsic Bridge capability. Installing or updating to version 1.0.122 automatically announces the store to KaliCart Global; no separate activation is required.

What is sent, and when

Activation and the 1.0.122 migration schedule an announcement to https://dashboard.kalicart.com. Failed announcements are retried at most five times with bounded backoff. No federation request runs on ordinary storefront, REST, MCP or checkout traffic.

The announcement contains one value: your site’s public URL (for example https://yourstore.com). Deleting the plugin sends the same URL once to request immediate deregistration.

What KaliCart Global does with it

The URL tells KaliCart Global where the public Bridge endpoints are available. KaliCart Global periodically reads the public catalog — the same product data already exposed through the Bridge’s public REST endpoints — and includes it in federated agent search. KaliCart Global only reads; it never writes to your store.

What is never sent

  • No customer data of any kind.
  • No orders, carts, or transaction data.
  • No personal data, accounts, or credentials.
  • No API keys or secrets.

KaliCart Global only ever sees what is already public on your storefront.

Lifecycle and removal

While Bridge is installed, its public discovery document publishes allow_global_indexing=true. Federation follows the plugin lifecycle:

  • Activation or update to 1.0.122 announces the public store URL.
  • Deleting the plugin requests immediate deregistration.
  • If uninstall cannot run or cannot reach Global, periodic liveness checks suspend the store after its Bridge endpoints become unavailable.

Data retention

While Bridge is reachable, KaliCart Global keeps a normalized copy of the public catalog to serve federated search and refreshes it periodically. After deregistration or liveness suspension, the catalog is no longer served. Retained catalog data can be deleted on request at the address below.

Contact

For any request relating to your data — including deletion of parked catalog data — contact privacy@kalicart.com.

© 2026 Save The Brain · From Colletorto With Love · KaliCart Bridge — GPLv2
kalicart.com global.kalicart.com mcp.kalicart.com Spec ARC/1.0 RSS WordPress.org Privacy