Why 21YunBox Pricing Contact Log in
Talk to an expert Test your site in China

Does Bill.com Work in China? Vendor Bank Data, the Payment-Licence Door & PIPL Residency

BILL (renamed from Bill.com) runs its production environment in AWS US-West-2 with US-East-2 backups — there is no mainland-China region. A compliance-first look at where your China entity's vendor and employee bank details, tax IDs and payment runs are allowed to rest under PIPL, and the non-bank payment-licence door that opens because BILL moves money.

Does Bill.com work in China?

BILL — the accounts-payable, accounts-receivable and spend platform formerly called Bill.com — runs entirely in United States infrastructure with no mainland-China region, so the real question is not whether it loads in China but whether your China entity's financial records are allowed to rest offshore. BILL states its “production environment is located in Amazon Web Services (AWS) across 3 physically separate availability zones in the US-West-2 region,” with backups “saved continuously to the US-East-2 environment.” There is no in-country region and, as multi-tenant SaaS, no self-hosted option to place the data on Chinese soil.

BILL is the system of record for vendor and employee bank-account and routing numbers, tax IDs, invoices and payment runs — personal information, and financial-account data is sensitive personal information under PIPL Article 28. When your mainland entity feeds those records in, they move to the United States: a cross-border transfer under PIPL (Articles 38–40 — notice, a separate consent, a transfer mechanism), with an in-country storage duty for CII operators and above-threshold handlers (PIPL Article 40; Cybersecurity Law Article 39, formerly Article 37). Because BILL also moves money, a second door applies: serving mainland payers is a licensed activity under State Council Order No. 768, which an offshore provider cannot satisfy on its own.

None of this means BILL is “blocked” — it is a risk map to settle with counsel against what you truly collect, store and pay. 21YunBox is a compliant overlay (and, on the payment leg, advisory — we hold no China payment licence): we map the exposure, keep the China-resident records in-country, and deliver any China-facing surface on ICP-filed infrastructure. Our China team can map your exposure →

What BILL's own documentation says about China

FactPrimary source
BILL hosts its production environment in United States AWS regions — there is no mainland-China region. BILL's security page states: “BILL's production environment is located in Amazon Web Services (AWS) across 3 physically separate availability zones in the US-West-2 region,” and “Full data backups are being saved continuously to the US-East-2 environment.” Both US-West-2 and US-East-2 are US regions, so records a China entity feeds in come to rest offshore. BILL, “Security” (bill.com/faq/security), retrieved 2026-10-10
BILL's own privacy notice describes a US-centric transfer model. Its Privacy Notice states that for users outside the United States, “We may transfer Your personal information to the United States or other countries outside of the country of Your residence.” For a vendor contact, employee or payer in the mainland, that transfer to US infrastructure is a cross-border transfer under PIPL. BILL, “BILL Privacy Notice” (bill.com/privacy), International Transfers, retrieved 2026-10-10
Vendor and employee bank details are sensitive personal information, and sending them offshore is a regulated cross-border transfer. Under PIPL, financial-account information is sensitive personal information (Article 28), and transferring personal information abroad requires notice, a separate consent and a transfer mechanism (Articles 38–40); above the state thresholds a data-export security assessment may be required first, and CII operators or above-threshold handlers must store China-collected personal information in-country (Article 40; Cybersecurity Law Article 39, formerly Article 37). Personal Information Protection Law of the PRC, Arts. 28 & 38–40 (npc.gov.cn); Cybersecurity Law Art. 39 (formerly Art. 37), retrieved 2026-10-10
Because BILL moves money, serving mainland payers is a licensed activity. Under the Regulations on the Supervision and Administration of Non-Bank Payment Institutions (State Council Order No. 768, in force May 1, 2024), a foreign non-bank provider offering payment services to mainland users must operate through a licensed non-bank payment institution established in China (Article 2); domestic transaction processing, settlement and data storage must be completed within China (Article 19); and a CII-operator or above-threshold payment institution must keep personal information in-country (Article 33). Regulations on the Supervision and Administration of Non-Bank Payment Institutions, State Council Order No. 768, Arts. 2, 19 & 33 (gov.cn), retrieved 2026-10-10

Sources verified by the 21YunBox compliance team on 2026-10-10.

Whether a browser in Shanghai can open the BILL dashboard was never the real question — it loads. (BILL is the accounts-payable, accounts-receivable and spend platform renamed from Bill.com in 2022–2023; the parent is BILL Holdings, Inc.) The real question is where the records it holds are allowed to come to rest. BILL is the system of record for a company’s money and the people attached to it: vendor and customer master files, bank-account and routing numbers, tax IDs, invoices, payment runs, and employee corporate-card and expense data on the Spend & Expense side. Bank-account and payment-card details are sensitive personal information under China’s PIPL. BILL states its production environment runs in Amazon Web Services’ US-West-2 region, with backups in US-East-2 — there is no mainland-China region to select. So the instant your China entity feeds records in, they come to rest in the United States, a cross-border transfer. And because BILL moves money, a second door opens.

BILL's security page stating that its production environment is located in Amazon Web Services (AWS) across three physically separate availability zones in the US-West-2 region, with full data backups saved continuously to the US-East-2 environment — all United States regions, with no mainland-China region named
"BILL's production environment is located in Amazon Web Services (AWS) across 3 physically separate availability zones in the US-West-2 region" — BILL's own security page, which also saves backups continuously to a US-East-2 environment, names only United States AWS regions, so there is no mainland-China region to select and records a China entity feeds in come to rest offshore. Source: bill.com/faq/security

BILL in China at a glance

What decides it In BILL's own terms — and China's law
Where the records live Offshore, in the United States. BILL states its "production environment is located in Amazon Web Services (AWS) across 3 physically separate availability zones in the US-West-2 region," with "Full data backups … being saved continuously to the US-East-2 environment." Both are US regions; there is no mainland-China region to select.
What it holds, and why it is personal (and sensitive) Vendor and customer master data, bank-account and routing numbers, tax IDs, invoices, approval chains, payment runs, and employee corporate-card and expense records. Named counterparties and employees with financial-account details make this personal information — and bank-account and payment-card data are sensitive personal information under PIPL Article 28.
Your China entity's data = a cross-border transfer When your mainland entity feeds vendor or employee records into BILL, that personal information moves to US infrastructure — a cross-border transfer under PIPL (Articles 38–40: notice, a separate consent, and one transfer mechanism — a CAC security assessment, the standard contract, or certification).
In-country storage duty For a critical information infrastructure operator or an above-threshold handler, personal information collected in China must be stored in China (PIPL Article 40; Cybersecurity Law Article 39, formerly Article 37). An offshore store in US-West-2 cannot meet an in-country storage duty.
Reachability is not the axis — plus a second, payment door Opening the dashboard is not compliance. Any China-facing surface (an approval portal or intake form) is a mainland internet service that needs an ICP filing and in-country delivery; and because BILL moves money, serving mainland payers is a licensed activity under State Council Order No. 768.

No mainland region, so your vendor and payroll records leave the country

Start with BILL’s own description of where it runs, because it settles the first question on its own. BILL’s security page states that its “production environment is located in Amazon Web Services (AWS) across 3 physically separate availability zones in the US-West-2 region,” and that “Full data backups are being saved continuously to the US-East-2 environment.” It adds that “BILL Spend & Expense is hosted in Amazon Web Services (AWS),” while the Accounts Payable and Accounts Receivable “servers and network infrastructure are hosted at secure data center facilities managed by leading certified data center providers,” replicating to a co-location facility for disaster recovery. Every location BILL names is in the United States. There is no mainland-China region offered, no in-country deployment, and — because BILL is multi-tenant software-as-a-service — no self-hosted option to place the data on Chinese soil.

BILL’s privacy notice describes the same US-centric model from the data-protection side: it says that if you are located outside the United States, “We may transfer Your personal information to the United States or other countries outside of the country of Your residence.” For a vendor contact, an employee or a payer in the mainland, moving their personal information to infrastructure in the United States is a cross-border transfer under China’s PIPL. PIPL puts the duty on the handler — your China entity, alongside BILL: Articles 38–40 require notice, a separate consent distinct from any general terms, and one lawful transfer mechanism (a CAC security assessment, the CAC standard contract, or certification). Where the volumes cross the state thresholds, or the records amount to “important data,” that transfer may first require China’s data-export security assessment before anything leaves the country.

A residency duty can sit on top of the transfer rules. For a critical information infrastructure operator, or a handler above the state personal-information threshold, personal information collected in China must be kept in China — a duty that runs through PIPL Article 40 and the Cybersecurity Law Article 39 (formerly Article 37; the 2025 Cybersecurity Law amendment, in force January 1, 2026, renumbered the data-localization article from 37 to 39, with its substance unchanged). An offshore store in US-West-2 cannot satisfy an in-country storage duty, however the account is configured.

Vendor bank details, tax IDs and payment runs are personal information — and sensitive

A payables file is not abstract “business data.” It is a list of named vendors, contractors and employees, each tied to a bank-account number, a routing or SWIFT identifier, a tax ID, and — where BILL verifies a counterparty — onboarding and know-your-customer details. Under China’s PIPL, financial-account information is sensitive personal information (Article 28): the tier whose handling demands a specific purpose, strict necessity, and its own separate consent, precisely because misuse can harm the person. Payment runs and approval chains carry more than numbers, too — they reveal who pays whom, how much, and when, which is commercially sensitive counterparty information about businesses operating in China.

That changes how the store should be read. BILL is not holding a little incidental contact data; it is a concentrated record of sensitive financial personal information about Chinese employees and vendors, resting in a US region. Sending or keeping that offshore is exactly the cross-border transfer the sensitive-information rules were written to govern — so the consent, necessity and transfer-mechanism tests apply at their strictest, not their most relaxed.

A second door: moving money in China is a licensed activity

Residency is the first door; the second opens because BILL does not merely store records — it moves money. Paying an overseas supplier from a US entity is an ordinary cross-border payout, and nothing here says you cannot do that. The regulated question is different: serving mainland users with payment services — collecting from them, or running domestic payment inside China — is a licensed activity. Under the Regulations on the Supervision and Administration of Non-Bank Payment Institutions (State Council Order No. 768, in force May 1, 2024), a foreign non-bank provider that wants to offer payment services to users in the mainland must do so through a licensed non-bank payment institution established in China (Article 2); for domestic transactions, processing, settlement and data storage must be completed within China (Article 19); and a payment institution that is a critical information infrastructure operator or an above-threshold handler must keep that personal information in-country (Article 33).

BILL is not a licensed mainland non-bank payment institution, so a domestic-China payment leg needs a licensed onshore path — not a workaround, and not something a foreign provider operated from the United States supplies on its own. This is where 21YunBox is deliberately modest: we are not a payment institution and hold no China payment licence. On the payment leg our role is advisory — we map which part of your flow touches licensed activity and what your PIPL exposure is, while the licence and the rails sit with a licensed onshore provider and your counsel. None of this means BILL is “blocked”; it means the money-movement leg carries its own gate, separate from where the data rests.

Narrowing the exposure doesn’t close the door

Teams reach for levers to shrink the footprint: mask a bank number, limit which entities’ records enter BILL, choose a nearer hosting region, or self-host. With BILL most of those levers are thin. It is multi-tenant SaaS: there is no mainland region to select and no on-premise deployment, so the store cannot be localized by configuration. And the levers that do exist reduce what crosses, not that it crosses. Redacting a tax ID still leaves a named vendor and a live bank account; entering fewer fields still sends them to US-West-2. The cross-border and residency analysis is unchanged — only the volume moves, and volume mostly affects which threshold-based obligations bite, not whether a transfer has occurred.

So treat this page as a risk map, not a ruling. Which duties actually apply — a transfer mechanism, a data-export security assessment, an in-country storage duty, the payment-licence path — turns on your specific entity, your data volumes, your role under Chinese law, and who your users are. Settle those specifics with your counsel against what you truly collect, store and pay, rather than against a general rule.

The lawful path — map, localize, deliver

There is a lawful shape for keeping BILL and still serving China, and it does not rip BILL out of your finance stack. First, map. Our China compliance team reads your PIPL cross-border, sensitive-information and residency obligations against your actual entity, data volumes and users — identifying which vendor and employee records collected in China must stay in the country, what may lawfully cross the border, where a data-export security assessment or an in-country storage duty applies, and what your notice and separate-consent flow must cover. The legal conclusions are settled with your counsel; we build the technical and architectural picture that feeds that decision.

Then localize. Where the records must stay in China, we stand up consented, in-country processing and storage for them — kept on mainland soil where the law requires — while BILL keeps doing what it does well for everything that may lawfully remain in US-West-2. On the money-movement leg we stay advisory: the licensed onshore payment path sits with a licensed provider, and we map how your flow connects to it.

Then deliver. Any China-facing surface — an approval portal, a vendor-intake form, a dashboard your mainland staff open — is a public mainland internet service, so it needs an ICP filing and compliant in-country delivery. 21YunBox delivers it in-country — the 21YunBox Optimizer — in front of the stack you already run, with no rebuild and no re-platform. 21YunBox is a compliant overlay, not a migration, and for a platform like BILL a partner to it, not a competitor. And what we never do — what no one lawfully can — is route around China’s data-export rules or any network restriction: 21YunBox never uses or suggests circumvention of any kind. We map the path, localize the records that must stay, and deliver the surface in-country, so your finance operation runs legally and compliantly for your users in China.

Get a compliance assessment →


Related reading:

Frequently Asked Questions

Does Bill.com (BILL) store my data in China?
No. BILL's security page states its production environment runs in Amazon Web Services' US-West-2 region across three availability zones, with backups continuously saved to US-East-2 — both United States regions. BILL offers no mainland-China region and, as multi-tenant SaaS, no self-hosted deployment, so vendor and employee records your China entity feeds in come to rest in the United States. For those records that is a cross-border transfer under PIPL, and for a CII operator or above-threshold handler it can collide with an in-country storage duty (PIPL Article 40; Cybersecurity Law Article 39, formerly Article 37).
Can I use BILL to pay vendors in China?
Paying an overseas supplier from a US entity is an ordinary cross-border payout, and this page does not say you cannot. The regulated question is serving mainland users with payment services — collecting from them or running domestic payment inside China — which is a licensed activity under State Council Order No. 768; a foreign non-bank provider must do that through a licensed non-bank payment institution established in China. Separately, the payer and vendor data BILL holds still rests offshore, so the PIPL cross-border and sensitive-information rules apply. Confirm both the payment-licence path and the data path with counsel. BILL is not “blocked.”
What's the lawful way to keep BILL and serve China, and what does 21YunBox do?
Keep BILL where it serves you for what may lawfully remain in US-West-2, and keep the China-resident vendor and employee records on a consented, in-country footing where the law requires. 21YunBox is a compliant overlay, not a migration, and a partner to BILL rather than a competitor. We map your PIPL cross-border, sensitive-information and residency exposure, localize the China-resident data onto in-country storage, and deliver any China-facing surface in-country on ICP-filed infrastructure. On the payment leg we are advisory only — we hold no China payment licence; that sits with a licensed onshore provider and your counsel. 21YunBox never uses or suggests circumvention of any kind. Get in touch to map your case.

ARTICLES RELATED TO BILL

Make Your Site Work inside the Great Firewall of China

Enter your information, and our staff will assist you in getting a 21YunBox account for China.

Make Your Site Work Within the Great Firewall of China
Make Your Site Work Within the Great Firewall of China

By clicking 'Get Started', I also agree to 21YunBox's Terms of Service and Privacy Policy.