Does Braze Work in China? PIPL Cross-Border, Delivery & Data Residency
Braze ingests your users' device push tokens, profiles, behavioral events and message content and delivers multichannel engagement from its offshore US, EU, or Australia instances — for China users a PIPL cross-border transfer — while Android push must route through licensed in-country manufacturer channels because Google's FCM is unavailable in mainland China. A compliance-first look at the recipient-data exposure, the delivery-channel door, and the lawful China path.
Does Braze work in China?
Braze is reachable from China, but you hand it your users' device tokens, profiles and message content to deliver — on China users that is a cross-border transfer, and Android push must route through licensed in-country manufacturer channels because Google's FCM is unavailable in mainland China.
You upload device push tokens, user IDs, phone and email, profile attributes and behavioral events, plus the message body, and Braze builds segments and delivers push, in-app, email and SMS from its offshore US, EU, or Australia instances — there is no mainland-China data center. Handing that recipient data and content to an offshore service to reach a person in China is a PIPL cross-border transfer you are responsible for (notice, a separate consent, a transfer mechanism), and because FCM is unavailable in mainland China, Chinese Android delivery must run through the device manufacturers' own push services. The lawful lever is to keep delivery and recipient data on an in-country, licensed path — manufacturer channels for Android, data minimization and marketing consent — not to make the offshore SDK reachable.
This is a risk map, not a verdict — settle the specifics with counsel. Our China team can map your exposure →
What Braze's own documentation says about China
| Fact | Primary source |
|---|---|
| Chinese Android push can't use Google's FCM — it routes through manufacturer channels. Braze's own Huawei integration guide states that Huawei devices use Huawei Mobile Services (HMS) "to deliver push instead of Google's Firebase Cloud Messaging (FCM)," which depends on Google Play Services that are unavailable in mainland China; Braze also documents delivery steps (auto-start, battery) for Xiaomi, OPPO, Vivo and Huawei OEM devices. | Braze Docs — Huawei push integration (retrieved 2026-10-10) |
| Braze processes and stores data in offshore regions — none in mainland China. Braze's data-centers page lists instances in Australia, the European Union, Indonesia, Japan, South Korea and the United States; a China user's tokens, profile, events and message content are handled on one of these offshore instances, so delivering to China crosses the border. | Braze Docs — Data centers (retrieved 2026-10-10) |
| Reaching a person in China with their tokens and content is a PIPL cross-border transfer. As the handler you owe notice, a separate consent, and a transfer mechanism under PIPL Articles 38–40; marketing push additionally needs a lawful basis and consent (Articles 13 and 23) and must honor opt-out. | PIPL Articles 38–40, 13, 23 — China cross-border transfer and marketing rules |
| Profile-based sends touch Article 24, and a CIIO or high-volume handler must store China data in-country. Deciding who receives which push from a behavioral profile is automated decision-making under PIPL Article 24; where the app operator is a CIIO or high-volume handler, China-collected personal information must stay in the mainland under Cybersecurity Law Article 39 (formerly Article 37). | PIPL Article 24; Cybersecurity Law Article 39 (formerly Article 37) |
Sources verified by the 21YunBox compliance team on 2026-10-10.
For a mainland-China audience, the question to settle about Braze is not whether its SDK and REST endpoints answer from Shanghai — they generally do. It is what happens to the recipient data and content you hand it. Braze is a customer-engagement platform: you upload device push tokens, user IDs, phone and email, profile attributes and events, plus the message body, and it builds segments and delivers push, in-app, email and SMS. All of that is processed on Braze’s offshore instances — it lists data centers in the US, the EU and Australia, among others, with none in mainland China. Four prongs then decide the risk: a cross-border transfer of your China users’ personal information and content; the Android delivery-channel door, since Google’s FCM is unavailable in mainland China; marketing consent; Article 24 profiling, since Braze targets by behavioral segment; and data residency for a CIIO or high-volume handler.
Braze in China at a glance
| What decides it | In Braze's own terms — and China's law |
|---|---|
| What you send it | Device push tokens, user IDs, phone and email, profile attributes, behavioral events, and the message body — an order update, an OTP, a live chat line, a promo. Tokens and identifiers are personal information, and the content frequently is too. Braze keeps a persistent user profile and event history to build the segments it targets. |
| Where it is processed | On Braze's offshore instances. Its data-centers page lists clusters in Australia, the European Union, Indonesia, Japan, South Korea and the United States — none in mainland China. Uploading a China user's data and content to an offshore service to deliver is a cross-border transfer under PIPL (Articles 38–40, 数据出境): notice, a separate consent, and one transfer mechanism. |
| How Android push is delivered | Google's FCM relies on Google Play Services, which are unavailable in mainland China, so push cannot ride FCM to most Chinese Android devices. Braze's own guide routes Huawei devices through Huawei Mobile Services (HMS) "instead of Google's Firebase Cloud Messaging," and documents Xiaomi, OPPO and Vivo delivery steps — each a licensed in-country manufacturer channel with a registered app. Apple's APNs reaches Chinese iOS devices, but the token and content still cross the border. |
| Consent, profiling & residency | Marketing and promotional push needs a lawful basis and consent, and must honor opt-out (PIPL Articles 13 and 23). Deciding who gets which message from a behavioral profile is automated decision-making (PIPL Article 24), which carries a right to refuse a purely profiled decision. Where the app operator is a CIIO or high-volume handler, China personal information must be stored in-country (Cybersecurity Law Article 39 (formerly Article 37)). |
| The lawful path | Reachability was never the axis. Route Chinese Android push through the licensed in-country manufacturer channels, keep recipient data and delivery on an in-country path, minimize and pseudonymize what still leaves, obtain the Article 13/23 consent for marketing, honor opt-out and any Article 24 option — and deliver the China-facing app in-country on an ICP-filed footing. 21YunBox maps that path and delivers the app, in front of the stack you already run. |
What you actually send — recipient identifiers, profiles and content
Braze is an engagement platform, so the thing you hand it is your users. To send to a person in China you upload their device push token (and, for SMS or email channels, their phone number or email), a user ID, and profile attributes — city, language, lifecycle stage, purchase history — along with the behavioral events that trigger a campaign. A device token tied to a real account is personal information, and so are the identifiers and attributes around it; the message body often carries more, from a name to an order reference to a one-time passcode. None of this merely passes through. Braze builds and keeps a persistent user profile and event history so it can segment your audience and decide who receives which message, and it logs sends, opens, clicks and conversions. That profile and event store lives on Braze’s offshore instances — the US, the EU, or Australia cluster your account is provisioned on — which means your China users’ identifiers, attributes and engagement history are processed and retained outside the mainland for as long as the profile exists.
It’s a cross-border transfer — and Android delivery has its own door — under PIPL
Start with the data. A device token, a phone number or email, a user ID and the attributes attached to them are personal information, and so is most of what a message carries. Collected from a user in the mainland and handed to a service operated offshore to deliver, that is a cross-border transfer of personal information under China’s Personal Information Protection Law. PIPL puts the duty on the handler — you, the operator of the app, not only Braze: Articles 38–40 require notice, a separate consent distinct from the user’s agreement to use the service, and one transfer mechanism (a CAC security assessment, the CAC standard contract, or certification). Because Braze targets by segment — deciding who gets which push from a behavioral profile — automated-decision-making rules under Article 24 also apply, with a right for the individual to refuse a decision made solely by profiling. And where the messages are marketing rather than transactional, Articles 13 and 23 require a lawful basis and consent and the ability to opt out.
Then the second door, which is specific to push. Reaching a Chinese Android device is not a single offshore API call. Google’s Firebase Cloud Messaging depends on Google Play Services, which are unavailable in mainland China, so FCM cannot reliably deliver to most Chinese Android phones — a foreign push setup that speaks only FCM silently fails to reach those users. The lawful, reliable route is through each device manufacturer’s own push service: Braze’s own documentation routes Huawei devices through Huawei Mobile Services (HMS) “instead of Google’s Firebase Cloud Messaging,” and gives delivery guidance for Xiaomi, OPPO and Vivo handsets. Each of those is a licensed in-country manufacturer channel that requires a registered app and credentials with that vendor — the push analogue of China’s SMS signature-and-template regime. Apple’s APNs does reach Chinese iOS devices, because Apple operates locally, but the token and content still transit to Braze’s offshore instance, so the cross-border-transfer duty does not go away on iOS.
Residency can bite on top of consent. Where the sending app’s operator is a critical information infrastructure operator or processes personal information above the state-set threshold, personal information collected and generated in the mainland must be stored in the mainland — the data-localization duty the Cybersecurity Law sets in its Article 39 (formerly Article 37, renumbered by the 2025 amendment in force January 1, 2026, with the substance unchanged). None of this turns on how fast a notification arrives; it turns on whether your China users’ identifiers, profile and content had a lawful basis to leave the country, whether they had to stay in the first place, and whether Android delivery runs through a licensed in-country channel.
Reaching the SDK isn’t the question — lawful in-country delivery is
Because FCM cannot carry push to most Chinese Android devices and an offshore profile store is a cross-border transfer by default, the productive question is not how to make Braze’s endpoint respond from Shenzhen — it is how to reach your China users lawfully. That has a shape. Route Chinese Android push through the licensed in-country manufacturer channels (Huawei/HMS, Xiaomi, OPPO, Vivo) with a registered app for each, keep the recipient data and delivery for China users on an in-country path rather than a persistent offshore profile, and minimize and pseudonymize whatever still has to leave. Obtain the Article 13/23 consent for any marketing push, honor opt-out, and offer the Article 24 option not to be targeted solely by profile. This is the opposite of a tunnel that ships the data offshore anyway: localizing means your China users’ contact data and content stop leaving without a basis, and China delivery moves onto a licensed in-country path.
Which arrangement fits your entity, your volumes, your consent model and your data map is a judgment to confirm with qualified counsel against what you actually ship — treat this page as a risk map, not a verdict, and settle the specifics with counsel.
The lawful path — map, localize, deliver
There is a lawful way to reach your users in China with push and multichannel engagement, and it does not run through an offshore endpoint reached from the mainland. It runs through licensed in-country delivery, a governed transfer, and a China-facing app that is itself filed and served in-country — in front of the stack you already run, with no rebuild. 21YunBox does three things on that footing.
Map. We inventory what recipient identifiers (device tokens, user IDs, phone and email), profile attributes, events and message content flow to Braze; what personal information they carry; where they are processed and retained; how your Chinese Android push is actually being delivered today (FCM that silently fails versus manufacturer channels); whether a persistent offshore profile and event store is being built; your marketing-consent basis; and any Article 24 profiling — so you know exactly what counsel needs to confirm.
Localize / govern. We help you route Chinese Android push through the licensed in-country manufacturer channels, keep China-user delivery and recipient data on an in-country path, minimize and pseudonymize what still leaves, secure the Article 13/23 consent for marketing and honor opt-out, and keep a lawful cross-border basis and an Article 24 option for anything that remains. Localizing means keeping delivery and recipient data on an in-country, licensed path — never a tunnel that ships the data offshore anyway.
Deliver. The app or site that triggers these notifications is a public internet service that carries an ICP filing duty and needs compliant, in-country delivery to perform for users in China. We serve it in-country on ICP-filed infrastructure — the 21YunBox Optimizer — so it runs legally and compliantly for your users in China. 21YunBox never uses or suggests circumvention of any kind. 21YunBox is a compliant overlay and partner to your engagement vendor, not a competitor to it.
Related reading:
- Cross-border data transfers under PIPL
- China’s Cybersecurity Law — data localization (Article 39, formerly Article 37)
- China’s Data Export Security Assessment Measures
- How to get an ICP filing for China
