Why 21YunBox Pricing Contact Log in
Talk to an expert Test your site in China

Does Gorgias Work in China? PIPL Cross-Border, Data Residency & Consent

Gorgias is an e-commerce helpdesk with no mainland-China region: your China customers' tickets, chats, profiles and store order data sit on its offshore Google Cloud, so running China support is a PIPL cross-border transfer, the embedded chat widget ships visitor data offshore before consent, and its AI Agent auto-resolves tickets. A compliance-first look at the residency, consent and automated-decision exposure.

Does Gorgias work in China?

Your China customers' conversations, tickets and profiles - plus the order and customer data Gorgias ingests from your store - sit on its offshore Google Cloud with no mainland-China region, its embedded chat widget ships visitor data offshore before consent, and its AI Agent auto-resolves tickets, so the support surface needs an ICP filing and a lawful in-country path.

Gorgias is a managed e-commerce helpdesk with no self-host and no China region; running China support on it is a PIPL cross-border transfer (Articles 38-40) that you, the handler, perform, the embedded chat widget raises a PIPL Article 13/23 consent problem, and the AI Agent is a PIPL Article 24 automated decision. The lawful lever is to keep conversations and PII in-country, gate and consent the widget, meet the Article 24 duties, and ICP-file the surface - not to make the offshore widget reachable.

This is a risk map, not a verdict - settle the specifics with counsel. Our China team can map your exposure →

What Gorgias's own documentation says about China

FactPrimary source
Gorgias runs on Google Cloud Platform in the US, the EU and Australia - no mainland-China region. Its own list of data subprocessors names Google Cloud Platform as its Cloud Service Provider located in "United States, European Union and Australia," with Cloudflare (US) as CDN; your China customers' tickets, chats and profiles are stored offshore, making China support a cross-border transfer. Gorgias - List of Data Subprocessors (retrieved 2026-10-10)
Gorgias ships an AI Agent that auto-resolves tickets - automated decision-making under PIPL Article 24. Its site describes an "AI Agent trained on your brand" that resolves inquiries automatically, and its subprocessor list names OpenAI (US); automated triage, scoring or auto-answers about a customer trigger the PIPL Article 24 duties of transparency, fairness and a route to human review. Gorgias - AI Agent (retrieved 2026-10-10)
China support on Gorgias is a PIPL Articles 38-40 cross-border transfer you perform as the handler. Sending tickets, chats, customer profiles and store order data to Gorgias's offshore cloud is a cross-border transfer (数据出境) requiring notice, a separate consent and a transfer mechanism (a CAC security assessment, the CAC standard contract, or certification). PIPL Articles 38-40 (China); 21YunBox gov-doc translation, retrieved 2026-10-10
A CIIO or high-volume handler must keep mainland personal information in-country. The data-localization duty sits in Cybersecurity Law Article 39 (formerly Article 37) - the 2025 Cybersecurity Law amendment, in force January 1, 2026, renumbered it from 37 to 39, substance unchanged - so an offshore-only helpdesk cannot satisfy it. Cybersecurity Law Article 39 (formerly 37); 21YunBox gov-doc translation, retrieved 2026-10-10

Sources verified by the 21YunBox compliance team on 2026-10-10.

If you run customer support for buyers in mainland China on Gorgias, the deciding question is not whether the helpdesk loads or the chat widget appears. It is where your customers’ conversations and profiles live, whether the embedded chat widget ships visitor data offshore before consent, whether Gorgias’s AI makes automated decisions about your customers, and whether the support surface is ICP-filed. Gorgias is an e-commerce helpdesk — a shared inbox for tickets, email, chat and social that ingests your store’s order and customer data from platforms like Shopify, BigCommerce and Magento — and it is a managed SaaS with no self-host option. Its own list of data subprocessors runs it on Google Cloud Platform in the United States, the European Union and Australia, with no mainland-China region. That posture raises four compliance prongs: conversation-and-customer-PII residency and cross-border transfer; the embedded chat widget’s on-load data flow and consent; AI auto-reply as an automated decision; and an ICP filing for the support surface.

Gorgias's own list of data subprocessors showing Google Cloud Platform as its Cloud Service Provider located in the United States, European Union and Australia, with no mainland-China region
"United States, European Union and Australia" is where Gorgias's own subprocessor list places its Cloud Service Provider, Google Cloud Platform — none of it in mainland China, so your China customers' tickets, chats and profiles are stored offshore. Source: Gorgias — List of Data Subprocessors

Gorgias in China at a glance

What decides it In Gorgias's own terms — and China's law
What it holds Tickets, emails, live-chat and social messages, customer profiles, and the order and customer data it ingests from your store. These are the full content of what your China customers write and disclose — personal information under PIPL.
Where it runs On Google Cloud Platform in "United States, European Union and Australia," per Gorgias's own subprocessor list, with Cloudflare (US) as CDN. None is in mainland China, so running China support on it is a PIPL cross-border transfer (Articles 38–40, 数据出境); a CIIO or high-volume handler must keep data in-country under Cybersecurity Law Article 39 (formerly Article 37).
The embedded chat widget A Gorgias chat widget on your China storefront is third-party JavaScript that can ship the visitor's IP, behavior and message content to Gorgias's offshore infrastructure on page load, before any consent — both a cross-border transfer and a PIPL Article 13/23 consent problem.
AI automated decisions Gorgias ships an "AI Agent trained on your brand" that resolves inquiries automatically, with OpenAI (US) named as a subprocessor. Auto-triage, scoring or auto-answers about a customer are automated decision-making under PIPL Article 24 — transparency, fairness, and a route to human review.
Reachability is not the axis The widget appearing and the dashboard loading resolve none of the above. The lever is to keep China-customer conversations and PII in-country, gate and consent the widget, meet the Article 24 duties, and ICP-file the support surface — not to make an offshore endpoint reachable.

What you actually hold — conversations, customer profiles, and a widget that phones home

A helpdesk is never just an inbox. When you run Gorgias for China, it holds the full content of your customers’ tickets, emails, live-chat threads and social messages — their questions, complaints and whatever they disclose about themselves — alongside their identifiers and profiles. Because Gorgias is built for e-commerce, it also ingests order and customer data from your store, so a single ticket view can carry a named shopper’s contact details, address and purchase history. All of that is personal information, and a good deal of it is the kind customers reveal in the course of a complaint.

That data does not stay on your side. Gorgias is a managed SaaS with no open-source, self-hostable engine, and its own list of data subprocessors runs it on Google Cloud Platform in the United States, the European Union and Australia — no mainland-China region. A Gorgias live-chat widget embedded on your China-facing storefront is third-party JavaScript loaded from Gorgias’s infrastructure: the moment the page loads, such a widget can capture the visitor’s IP, on-page behavior and message content and send it to the offshore vendor, before the visitor has consented to anything. And Gorgias ships an AI Agent that auto-resolves tickets — a model that decides or answers per customer, which is the territory of PIPL Article 24 automated decision-making.

Cross-border transfer and residency. Routing tickets, chat threads, customer profiles and store order data to Gorgias’s offshore Google Cloud is a cross-border transfer that you — the handler — perform under PIPL Articles 38–40: a notice, a separate consent distinct from agreeing to use support, and one lawful transfer mechanism (a CAC security assessment, the CAC standard contract, or certification). See cross-border data transfers. If your operating entity is designated critical information infrastructure, or handles personal information above the state threshold, the mainland-collected data must stay in the mainland — the data-localization duty in Cybersecurity Law Article 39 (formerly Article 37, renumbered by the 2025 Cybersecurity Law amendment in force January 1, 2026; the substance is unchanged).

The widget’s consent problem. An embedded chat widget that ships the visitor’s IP, behavior and messages to an offshore vendor on page load collects and transfers personal information before any basis exists for it. That is a PIPL Article 13/23 consent problem layered on top of the cross-border transfer, and it cannot be resolved by making the offshore endpoint reachable — it has to be gated and consented, minimized, or served from an in-country path.

Automated decisions. Where Gorgias’s AI Agent auto-triages, scores, routes or auto-answers a customer, that is automated decision-making under PIPL Article 24, which requires transparency, fairness in the outcome, and a route to human review. Any user-generated content you carry also attracts content-moderation duties under Cybersecurity Law Article 49 (formerly Article 47).

Loading the widget isn’t the question — a compliant in-country support path is

That a Gorgias widget renders on a device in China, or that the agent dashboard opens, tells you nothing about any of the doors above. Reachability is not the axis; the axis is compliance risk. A lawful setup has a definite shape: your China-customer conversations and PII are kept on an in-country path — an in-country support deployment, with what you collect minimized and pseudonymized — the embedded widget is gated and consented so it does not ship visitor data on load without a basis (or is replaced with an in-country path), the Article 24 duties are met for any AI that decides about a customer, and the support surface is ICP-filed. What it is not is a hidden route that carries the conversation data offshore anyway while presenting it as local; keeping data in-country means the data actually stays in-country.

This page is a risk map, not a verdict. Which prongs bind your specific setup — whether you are a CIIO or high-volume handler, which consents apply, how your AI is configured — turns on exactly what your support stack carries and how Gorgias is wired into it, so settle the specifics with counsel.

The lawful path — map, localize, deliver

There is a clean way to run Gorgias-powered support for customers in China, and it does not involve working around anything. Our China team does three things. We map what the helpdesk holds — the ticket, email, chat and social content, the customer profiles, the order and customer data ingested from your store, and the embedded widget’s on-load data flow — where each is processed and stored (an offshore region, with no mainland-China option), whether Gorgias’s AI Agent scores or auto-answers your customers (Article 24), and the consent basis you need. We localize: keep China-customer conversations and PII on an in-country path — an in-country support deployment in place of any flow that cannot run compliantly — gate and consent the chat widget so it does not phone home on load without a basis, minimize and pseudonymize what is collected, meet the Article 24 duties for the AI, and obtain the Article 13/23 consent. We deliver the China-facing support surface — a help center, chat page or widget host is a public service that carries an ICP filing duty — on compliant, in-country infrastructure, the 21YunBox Optimizer, in front of the stack you already run, with no rebuild. 21YunBox is a compliant overlay and partner, not a competitor to Gorgias. The result is customer support that runs legally and compliantly for your users in China. 21YunBox never uses or suggests circumvention of any kind.

Get a compliance assessment →


Related reading:

Frequently Asked Questions

Does Gorgias have a data center in mainland China?
No. Gorgias's own list of data subprocessors places its cloud provider, Google Cloud Platform, in the United States, the European Union and Australia, with no mainland-China region. Running China support on it stores your customers' conversations and personal information offshore, which makes it a PIPL cross-border transfer rather than a residency-compliant deployment.
Is running Gorgias for China customers a cross-border data transfer?
Yes. You, as the handler, transfer tickets, chats, emails, customer profiles and the order and customer data Gorgias ingests from your store to its offshore cloud. That is a PIPL Articles 38-40 cross-border transfer, which needs a notice, a separate consent distinct from agreeing to use support, and a lawful transfer mechanism.
Can 21YunBox make the Gorgias chat widget reachable in China?
Reachability is not the question. The lawful path keeps your China customers' conversations and PII in-country, gates and consents the embedded chat widget (or uses an in-country replacement), meets the PIPL Article 24 duties for Gorgias AI, and ICP-files the support surface - never a hidden route that ships data offshore anyway. Settle the specifics with counsel.

ARTICLES RELATED TO GORGIAS

Make Your Site Work inside the Great Firewall of China

Enter your information, and our staff will assist you in getting a 21YunBox account for China.

Make Your Site Work Within the Great Firewall of China
Make Your Site Work Within the Great Firewall of China

By clicking 'Get Started', I also agree to 21YunBox's Terms of Service and Privacy Policy.