Appearance
Privacy and external services
Documentation scope: Guild 0.1.x pre-release builds. The exact public release version will be confirmed in the changelog before Theme Store publication.
Guild is a Shopify theme. Shopify, the merchant's store settings, installed apps, and any third-party embed providers all affect privacy behavior on the storefront. This guide explains the parts Guild controls and the parts merchants should review before publishing.
This page is not a legal policy and does not replace legal advice. Use it as a setup checklist for theme-related privacy and external-service decisions.
What Guild stores in the browser
Guild can use browser storage for functional storefront behavior. The theme does not use this storage for advertising, cross-site tracking, analytics, customer identification, or profiling.
Current functional storage areas include:
| Area | Storage pattern | Purpose | Typical stored value | Retention behavior |
|---|---|---|---|---|
| Section dismissal memory | guild:section-dismissed:* | Keeps a closable section hidden after a visitor closes it when the merchant enables dismissal memory. | Expiry timestamp or never. | Merchant setting controls 1 day, 7 days, 30 days, or no expiry. |
| Popup dismissal memory | forma:dialog-dismissed:* | Keeps an automatically displayed popup hidden after a visitor closes it when the merchant enables dismissal memory. | Expiry timestamp or never. | Merchant setting controls 1 day, 7 days, 30 days, or no expiry. Expired values are removed when checked. |
| Accessibility controls | ui:acc:* | Remembers visitor preferences for reduced motion, increased contrast, and larger text when those controls are used. | 1 or 0 preference values. | Persists until the visitor changes the preference or clears browser storage. |
| Collection view controls | collection-view:* | Remembers a visitor's selected grid or list view for a collection-style product list on the same browser and path. | grid or list. | Persists until the visitor changes the preference or clears browser storage. |
| Recently viewed products | rte:recently-viewed-products | Lets recently viewed product sections show products the visitor has viewed on the same browser. | Product handles, capped by the theme. | Persists until overwritten by later product views or cleared by the browser/user. |
| Cart cross-tab coordination | forma:cart:invalidation:v1 | Lets another tab know that the cart changed when BroadcastChannel is unavailable, so visible cart surfaces can refresh. | A short synchronization message containing protocol/version data, a random tab/message identifier, timestamp, mutation source/category, sequence, and optional item count. It does not contain cart line contents or customer identity. | The latest fallback message can remain until overwritten or browser storage is cleared. Guild ignores received messages older than 2 minutes. |
These values are stored in the visitor's browser. They are not sent to Guild support by the theme.
Recently viewed product handles can reflect product-browsing history on that browser. Review your store privacy policy and cookie/consent setup before using recently viewed product sections, especially for stores where viewed products can reveal sensitive interests.
A development-only tabs debug flag can also be read from browser storage when a developer manually sets debug:tabs to 1. Guild does not set this flag for normal shoppers.
Shopify customer privacy settings
Configure store-level privacy, cookie, data sharing, and policy settings in Shopify Admin. Guild does not replace Shopify's customer privacy settings, cookie banner, privacy policy, data-sharing controls, app consent behavior, or checkout privacy behavior. For platform setup and current limitations, see Shopify's customer privacy settings documentation.
Before publishing, review:
- Shopify Admin customer privacy settings.
- Store privacy policy, terms, refund, shipping, and contact pages.
- Installed apps, pixels, analytics, marketing tools, and app embeds.
- Any custom scripts or provider embeds added through Custom HTML or Custom Liquid.
External services and provider requests
Guild can render merchant-configured media and external services. The table below separates theme behavior from provider-controlled behavior.
| Surface | When it can load | Theme behavior | Provider-controlled behavior |
|---|---|---|---|
| YouTube external video | Thumbnail can load before play when no Shopify preview image is available. The player iframe loads after the visitor presses play. | Runtime player iframe uses youtube-nocookie.com; YouTube ID is validated before the iframe is created. | YouTube controls thumbnail delivery, player behavior, cookies or similar technologies, captions, availability, and embedded-player terms. |
| Vimeo external video | Poster lookup can load before play when no Shopify preview image is available. The player iframe loads after the visitor presses play. | Vimeo poster lookup omits credentials and uses no-referrer. Vimeo ID is validated before the iframe is created. | Vimeo controls poster delivery, player behavior, cookies or similar technologies, captions, availability, and embedded-player terms. |
| Google Maps | The map iframe loads when a configured map section or media block is present on the page. | Guild accepts only HTTPS Google Maps-style sources from the supported Google Maps hosts and renders the iframe with no-referrer. | Google controls map availability, embedded map behavior, cookies or similar technologies, provider terms, and location/map output. |
| 3D model media | Model files load when the configured model media appears on the page. | Guild renders model media through the storefront media markup and model-viewer output. | Shopify, the browser, and the hosted model asset control media delivery and device support. |
| Dynamic product sections | Product recommendations, recently viewed product cards, collection updates, cart updates, pickup availability, and search/section updates can use same-origin Shopify requests. | Guild requests Shopify storefront/theme endpoints to render theme content. | Shopify controls platform endpoint behavior and store-level privacy settings. |
| App blocks and app embeds | App output loads when the merchant enables or places the app. | Guild provides theme insertion points and styling boundaries where applicable. | The app developer controls app scripts, cookies or similar technologies, data use, and support. |
Review your store privacy policy and cookie/consent setup when external videos, maps, apps, or custom embeds are used.
YouTube and Vimeo videos
Guild supports Shopify-hosted video and configured YouTube/Vimeo external videos. External video providers control their own player behavior, cookies or similar technologies, availability, captions, privacy controls, and embedded-player terms.
Where possible, add a Shopify preview image for external videos. This lets the theme show a merchant-controlled preview image instead of loading a provider thumbnail before the visitor plays the video.
Guild creates the external video iframe only after a visitor selects the play control. If a YouTube or Vimeo thumbnail is loaded from the provider, the provider can receive a request for that thumbnail before the video is played.
Review your store privacy policy and cookie/consent setup when external videos are used.
Google Maps
Google Maps embeds are provided by Google. Guild can display a configured Google Maps embed URL or iframe source, but Google controls map availability, embedded map behavior, cookies or similar technologies, and provider terms.
Before publishing a map section:
- Add the store's own public addresses and map URLs before publishing. Do not use placeholder addresses, copied map links, or private location details in a public storefront.
- Test the map on desktop and mobile.
- Confirm the store privacy policy and cookie/consent setup cover map embeds where required.
- Consider using a regular link to directions instead of an embedded map when you want to avoid loading the map provider on the page.
Custom HTML, Custom Liquid, and third-party embeds
Custom HTML and Custom Liquid are advanced insertion points. Use them only for trusted code that cannot be created with normal theme settings.
Provider snippets such as social posts, booking widgets, review widgets, chat widgets, analytics snippets, and marketing scripts can affect:
- privacy and consent behavior;
- cookies or browser storage;
- page speed;
- accessibility;
- layout;
- support scope for issues caused by the customization;
- theme updates.
Guild support can help with built-in Guild behavior. It does not include debugging provider snippets, third-party apps, custom scripts, modified theme files, or legal/privacy setup for a merchant's store.
Support requests and privacy
When contacting support, include enough detail to reproduce the issue, but avoid sending passwords, private keys, payment data, full customer records, full order exports, broad admin access details, unnecessary personal data, or unredacted customer/order information.
Screenshots and recordings should show the affected theme behavior. Blur or remove customer, order, email, address, payment, and personal information when it is not needed for the support request.
Before publishing
Use this checklist before publishing a page that uses external services or custom code:
- Review Shopify customer privacy settings.
- Review the store privacy policy and cookie/consent setup.
- Review installed apps and app embeds.
- Test YouTube, Vimeo, Google Maps, Custom HTML, and Custom Liquid content on desktop and mobile.
- Add Shopify preview images for external videos when you do not want provider thumbnails to load before play.
- Remove provider embeds while troubleshooting layout, speed, accessibility, privacy, or loading issues.
- Keep a record of custom code and third-party snippets added to the theme.