Privacy Notice
Last updated: 21 September 2026 · Version global-privacy-2026-09-21
This notice covers KaliCart Global, the federated multi-merchant catalog service at global.kalicart.com, its public MCP and REST interfaces, its merchant registry, and its optional provider-delivery channels. The companion KaliCart Bridge Privacy Notice explains what an individual merchant's Bridge sends.
Who operates this service
KaliCart Global is operated by SAVE THE BRAIN di Giuseppe Socci, P.IVA IT01830350706, SP 40 snc, 86044 Colletorto (CB), Italy.
What KaliCart Global is
KaliCart Global is a read-only discovery layer over independent WooCommerce stores running KaliCart Bridge. It lets an agent search across participating merchants and routes each result back to the merchant's Bridge and storefront for live verification and checkout.
KaliCart Global does not process payments, hold customer accounts, or obtain write access to a merchant's WooCommerce store.
Public API usage data
Calls to the public MCP and REST interfaces may record:
- network metadata such as the requesting IP address;
- the submitted search or lookup criteria;
- requested merchant domains or product identifiers;
- response metadata such as result counts, timing, status, and merchant domains touched;
- bounded technical metadata needed for abuse prevention, rate limiting, debugging, aggregate usage measurement, and service-quality monitoring.
This information is not sold and is not used to build advertising profiles of individual users.
Merchant registry and public catalog data
For a participating merchant, KaliCart Global may retain:
- the public store URL and public Bridge endpoints;
- Bridge version and public discovery capabilities;
- registration, probe, refresh, suspension, and deregistration timestamps;
- public reachability and liveness status;
- normalized copies of public commercial catalog information supplied through the merchant's Bridge.
Catalog information may include product identifiers, titles, descriptions, categories, images, prices, availability, brands, attributes, merchant identity, policies, and links back to the merchant.
The merchant remains authoritative for live price, availability, fulfilment, policies, and checkout.
Federated provider authorizations
A merchant may separately authorize KaliCart Global to deliver public product information to a named product-discovery or agentic-commerce provider. Each provider is disabled by default and requires its own explicit authorization. No authorization is inherited by a future provider.
For each grant or revocation, KaliCart Global may retain a minimal receipt containing:
- the public store URL and a unique consent identifier;
- provider and purpose identifiers;
- grant or revocation action and UTC timestamp;
- Bridge and applicable terms versions;
- the language shown to the merchant administrator;
- hashes of the canonical authorization text, localized text, and receipt record;
- receipt-processing status and timestamps.
The receipt does not include the WordPress administrator's identity, email address, password, credentials, or IP address.
Delivery to third-party providers
When all operational prerequisites are met, KaliCart Global may deliver the authorized merchant's public commercial catalog information to the specifically authorized provider. The provider's own terms and privacy notice apply to its subsequent processing.
Authorization, technical delivery, provider approval, indexing, display, and transaction availability are separate states. KaliCart Global does not represent that authorization alone makes a catalog active on a provider's service.
The direct merchant feed generated on a merchant's own server is outside this federated delivery path unless the merchant separately supplies it.
Purposes and recipients
KaliCart Global uses the information described above only to operate and secure the catalog service, answer discovery requests, keep merchant data current, prevent abuse, diagnose failures, measure aggregate service quality, document merchant authorizations, and deliver an authorized catalog to the provider selected by the merchant.
Information may be received by:
- hosting, infrastructure, security, and technical service providers acting only as needed to operate KaliCart Global;
- the product-discovery or agentic-commerce provider specifically authorized by the merchant;
- people and agents using the public catalog, limited to public commercial catalog information and merchant attribution;
- public authorities or professional advisers when disclosure is required by law or necessary to establish, exercise, or defend legal claims.
KaliCart Global does not sell personal data or provide public API usage records to merchants or product-discovery providers.
Information not collected through the catalog service
KaliCart Global does not obtain from Bridge:
- customer profiles or personal customer data;
- orders, carts, or transaction histories;
- payment information;
- store passwords, API keys, authentication secrets, or WordPress credentials;
- private or unpublished catalog content.
Retention
- Web-server access and error logs and detailed public-interface usage telemetry are retained for no more than 12 months, then deleted or irreversibly aggregated.
- Aggregate statistics that no longer identify a requester may be retained for longer to measure service quality and catalog coverage.
- A merchant's active catalog snapshot is retained while federation remains operational. After deregistration or revocation, affected records stop being served immediately through the revoked path and are removed from active snapshots during the next synchronization cycle.
- Minimal authorization receipts are retained while an authorization is active and for no more than five years after its final revocation, unless a longer period is required by law or needed for an ongoing legal claim.
Your controls and requests
A merchant administrator can disable a provider authorization without leaving the general federated catalog, or can revoke federation entirely from KaliCart Bridge. A revocation prevents further delivery through the affected KaliCart Global path.
Where applicable, a person may ask for access, correction, deletion, restriction, or objection concerning personal data processed by KaliCart Global. Because public-interface IP addresses are stored only as shortened cryptographic hashes, KaliCart Global may be unable to link a request to a particular log entry without additional information supplied by the requester. Requests are assessed under applicable law and may require identity verification.
Contact
For privacy questions or requests, contact privacy@kalicart.com. The general contact is giuso@kalicart.com; security reports should be sent to bug@kalicart.com.
