KaliCartKaliCart
Bridge Solutions Docs MCP Spec Blog Download EN·IT·DE·FR·ES
KaliCart Bridge

Privacy Notice

Last updated: 27 September 2026 · Version bridge-privacy-2026-09-27

This notice explains the external connections and public catalog functions provided by KaliCart Bridge. The plugin does not send customer, order, cart, payment, credential, or private catalog data to KaliCart Global.

Who operates the external services

KaliCart Global is operated by Save The Brain, P.IVA IT01830350706, SP 40, 86042 Colletorto (CB), Italy.

Standalone operation

KaliCart Bridge can operate entirely on the merchant's WordPress and WooCommerce installation. Its REST, MCP, discovery, checkout handoff, and direct product-feed functions do not require the merchant to join KaliCart Global.

The WordPress.org distribution receives plugin updates through WordPress's standard update infrastructure. KaliCart Bridge does not add a separate KaliCart update-telemetry request to that distribution.

Direct merchant feed

The direct merchant feed is generated and stored on the merchant's own server. Its URL contains a non-guessable token, but anyone who receives that URL may be able to access the public product data in the file.

Generating the file does not transmit it, or its URL, to KaliCart Global, OpenAI, or any other provider. If the merchant supplies the file or URL directly to a provider, that is a separate relationship managed by the merchant and governed by that provider's terms and privacy notice.

The direct merchant feed is independent from the Federated Catalog and from every federated distribution authorization described below.

Optional KaliCart Global Federated Catalog

The Federated Catalog is disabled unless a WooCommerce administrator explicitly activates it from the KaliCart Bridge administration screen.

What is sent

When an administrator selects Activate Federated Catalog, the plugin sends one value to the KaliCart Global technical service at https://dashboard.kalicart.com: the store's public site URL.

When an administrator selects Revoke consent, the plugin sends the same public site URL to request deregistration.

The separate Check external visibility action also sends the public site URL to the technical status endpoint. This manual check reads Global's latest observation; it does not activate federation or transmit catalog contents.

No automatic federation request is made merely because the plugin is installed, activated, or updated.

Installation identity and status signals

Only while the Federated Catalog is active, Bridge creates an Ed25519 signing key for this installation and proves that the same installation controls the store domain. The private key remains encrypted on the merchant's WordPress installation and is never transmitted.

The identity exchange sends the store host, a random installation identifier, the public key, a one-time verification code, the consent state, and the installed plugin, WordPress, and PHP versions. About once a day, Bridge sends a signed status signal with those versions and consent state. If WordPress recorded a fatal error caused by Bridge, the signal may also contain only a normalized error code, its time, and a short non-reversible hash; it never contains the error message, file paths, or a stack trace.

These signals let KaliCart Global verify the Bridge installation, distinguish an active store from one that is broken or has left, and diagnose compatibility without receiving customer or order data. A verified identity does not mean that KaliCart Global can receive or serve the catalog: catalog reception is reported separately.

Bridge sends a signed leaving signal when the plugin is deactivated or deleted, and a signed consent-off signal when federation is revoked. Identity and status signals are never sent while the Federated Catalog is inactive.

What KaliCart Global does

After successful activation, KaliCart Global uses the public site URL to locate the Bridge's public discovery and catalog endpoints. It periodically reads public product information and includes eligible products in federated agent search. It does not write to the store.

While the Federated Catalog is active, the plugin also publishes static catalog files at /.well-known/kalicart/, or at wp-content/uploads/kalicart/ when the first location cannot be written. They contain the same public product fields as the catalog endpoint — names, descriptions, categories, prices, availability, variants, image URLs and product links — but never exact stock quantities. They are refreshed when products change and, as a best effort, once a day. Anyone can read them, just like the public product pages. They are deleted when consent is revoked or the plugin is deactivated or uninstalled. If the plugin folder is removed outside WordPress, the files may remain, but KaliCart Global will not use them without a current signed status from the site.

Authoritative price, availability, fulfilment, and checkout remain on the merchant's WooCommerce site.

Optional federated distribution channels

Some Bridge versions may allow a federated merchant to authorize KaliCart Global to distribute public product information to a named third-party product-discovery or agentic-commerce provider.

This is separate from both the Federated Catalog activation and the direct merchant feed:

  • KaliCart Global must already be active and successfully registered.
  • Each provider is disabled by default.
  • Each provider requires a separate, unselected authorization action.
  • Authorizing one provider does not authorize any current or future provider.
  • Authorization does not prove that the provider has approved, received, indexed, or displayed the catalog.

The first channel proposed for the pilot is OpenAI / ChatGPT product discovery, identified technically as openai_acp.

Authorization receipt

When the merchant grants or revokes a federated provider authorization, Bridge records the act locally and sends KaliCart Global a minimal receipt containing:

  • the store's public site URL;
  • a unique consent identifier;
  • provider and purpose identifiers;
  • whether authorization was granted or revoked;
  • the UTC timestamp;
  • the plugin and terms versions;
  • the language shown to the administrator;
  • hashes of the canonical authorization text, the localized text, and the receipt record.

The receipt does not contain the administrator's name, email address, IP address, password, or WordPress credentials.

When the installation identity is already verified, Bridge signs the receipt with that installation’s existing private key and includes the existing host and random installation ID plus a one-time anti-replay request ID. KaliCart Global verifies the signature with the public key already bound to the installation, so verification does not depend on reaching the store’s discovery endpoint. The private key never leaves the store. An older Global or an unavailable local identity uses the existing discovery-verified compatibility path; a rejected signature is never bypassed through that path.

Public product information delivered through a provider channel

Subject to the merchant's specific authorization and the provider's technical approval, KaliCart Global may transmit public commercial product information such as product identifiers, titles, descriptions, product and image URLs, prices, sale prices, availability, condition, brand, seller information, return-policy URL, target country, and merchant-declared product identifiers or attributes where available.

No customer, order, cart, payment, account, or credential data is included.

Revocation and suspension

Revoking a provider authorization stops KaliCart Global from continuing delivery through that provider channel. It does not disable the direct merchant feed or remove the store from the general Federated Catalog.

Revoking the Federated Catalog suspends all provider delivery through KaliCart Global because the required federation is no longer active. Provider authorization records remain in the audit history unless the provider authorization is separately revoked.

Revocation cannot require a third party to erase information that it lawfully received before revocation. Any such retention is governed by the third party's own terms, privacy notice, and applicable law.

Record retention

The Federated Catalog consent receipt stays in the merchant's WordPress database until the plugin is uninstalled and is not sent to KaliCart Global. Separate provider-channel authorization receipts are sent as described above and retained only while needed for operation, audit, dispute resolution or legal claims.

KaliCart Global keeps current operational state while the store participates. Domain-bearing operational events and catalog-reading reports are kept for 90 days, then only anonymous daily totals without site address, URL or IP address remain. Server access logs containing IP addresses are kept for 30 days.

Within 30 days after revocation or removal, KaliCart Global deletes the catalog, its copies, operational events and the current identity state. Only a minimal revocation record (site address and revocation date, to prevent accidental relisting) and the signing-key history (public keys and verification dates, kept as a security record) remain.

Contact

For questions, access requests, or deletion requests relating to KaliCart Global, contact privacy@kalicart.com or use https://www.kalicart.com/contact/.

© 2026 Save The Brain · From Colletorto With Love · KaliCart Bridge — GPLv2
kalicart.com global.kalicart.com mcp.kalicart.com Spec ARC/1.0 RSS WordPress.org Privacy