Why 21YunBox Pricing Contact Log in
Talk to an expert Test your site in China

Does Heap Work in China? PIPL Cross-Border, Automated Decisions & Data Residency

Heap — now part of Contentsquare — autocaptures every click, tap, and pageview your China users make and aggregates them into a persistent behavioral profile store in a US or EU AWS region, with no mainland-China option: a PIPL cross-border transfer and Article 24 automated decision-making about what each user sees. A compliance-first look at the cross-border, profiling, consent, and residency questions for Heap.

Does Heap work in China?

The question for Heap in China isn't whether its snippet loads — it's that Heap autocaptures everything your users do and aggregates it offshore into profiles that decide what each of them sees.

Heap — now part of Contentsquare — drops one snippet that captures every click, tap, pageview and form fill, resolves them to identities, and stores the resulting behavioral profiles in a US or EU AWS region, with no mainland-China option. Sending your China users' behavior there is a PIPL cross-border transfer of personal information, and using the profiles to segment, experiment and personalize is Article 24 automated decision-making about what each user sees. The lawful lever is to keep the behavioral data and the decisioning in-country — a licensed domestic analytics path, the least identifying data collected, the Article 13/23 consent, and the Article 24 right to a non-profiled option — not to make the offshore service reachable.

This is a risk map, not a verdict — your duties turn on your data volumes and role. Our China team can map your Heap exposure →

What Heap's own documentation says about China

FactPrimary source
Heap autocaptures everything by default. Heap's own platform page says a single snippet "grabs every click, swipe, tap, pageview, and fill — forever" and "collects all behavioral data immediately" for retroactive analysis — so the data leaving China is your users' entire behavioral stream plus identities, not a chosen subset. Heap — Autocapture (platform page), retrieved 2026-10-10
Heap hosts data only in a US or EU AWS region — none in mainland China. Heap is now part of Contentsquare, whose Sub-processors List lets a Product Analytics customer host data in "Europe: Ireland (AWS-EU-West-1)" or "USA: Virginia, USA (AWS-US-East-1)" (Frankfurt at-rest only); there is no mainland-China option, so China users' behavior is processed and stored offshore. Contentsquare Sub-processors List (Product Analytics / Heap), retrieved 2026-10-10
Segmenting and personalizing from a behavioral profile is automated decision-making under PIPL Article 24. Where a decision or push is based on profiling, the individual must be given a way to refuse and an option not to be targeted by their personal characteristics — a duty a buried terms line does not satisfy. PIPL Article 24 (automated decision-making / profiling), retrieved 2026-10-10
Sending China users' behavior to Heap is a PIPL cross-border transfer. Under PIPL Articles 38–40 you, the handler, must give notice, obtain a separate consent, and put a transfer mechanism in place before the data goes abroad; a CIIO or high-volume handler also owes in-country storage under Cybersecurity Law Article 39 (formerly Article 37). PIPL Articles 38–40 (cross-border transfer), retrieved 2026-10-10

Sources verified by the 21YunBox compliance team on 2026-10-10.

Whether Heap “works” in mainland China is a compliance question before a networking one, and for an autocapture analytics platform the shape is specific: not whether the snippet loads, but what happens to the behavior and identities it collects. Heap — now part of Contentsquare — drops a single snippet that captures every click, tap, pageview and form fill, resolves those events to identities, and aggregates them into unified behavioral profiles kept for retroactive analysis. For your China users, that data lands in a US or EU AWS region — Heap offers no mainland-China option — then drives the segments, experiments and personalization that decide what each person sees. Four prongs open at once: a cross-border transfer of personal information (PIPL Articles 38–40), automated decision-making and profiling (Article 24), consent for behavioral tracking (Articles 13 and 23), and in-country storage for a CIIO or high-volume handler.

Contentsquare Sub-processors List showing that a Heap Product Analytics customer may select either Europe (Ireland, AWS-EU-West-1) or USA (Virginia, AWS-US-East-1) to host the data, with Frankfurt as an at-rest option and no mainland-China region listed
Contentsquare's Sub-processors List, which now governs Heap, says a Product Analytics customer "may select either" "Europe: Ireland (AWS-EU-West-1)" or "USA: Virginia, USA (AWS-US-East-1)" to host the data — no mainland-China region is offered, so a China user's autocaptured behavior is processed and stored offshore. Source: Contentsquare Sub-processors List

Heap in China at a glance

What decides it In Heap's own terms — and China's law
What you send it Heap's snippet autocaptures behavior by default — in Heap's own words, "a single snippet grabs every click, swipe, tap, pageview, and fill — forever" — and resolves those events to user identities. That stream is personal information: who did what, when, on which screen, from which device. Autocapture collects everything up front, not a chosen subset, so the dataset leaving China is broad by design.
Where it is processed and stored Heap (part of Contentsquare) hosts Product Analytics in a US region (Virginia, AWS-US-East-1) or an EU region (Ireland, AWS-EU-West-1; Frankfurt at-rest), the region chosen by the customer. There is no mainland-China region. So your China users' autocaptured behavior is carried out of the country — a cross-border transfer of personal information under PIPL Articles 38–40 (数据出境).
It decides what each user sees The profiles and segments Heap builds drive experiments, audiences and personalization — automated decision-making and profiling under PIPL Article 24, which requires transparency and fairness, a way for the individual to refuse, and, where a decision or push is based on profiling, an option not to be targeted by their personal characteristics.
Consent and residency Autocapturing behavioral events needs a lawful basis and consent under PIPL Articles 13 and 23 — a buried "by using this product" line is not enough. And because the profile store grows permanently offshore, a CIIO or high-volume handler also owes in-country storage (Cybersecurity Law Article 39, formerly Article 37).
Reachability is not the axis The snippet loads from China; that is not the question. The lawful move is to keep the behavioral data and the decisioning in-country — a licensed domestic analytics path — minimize and pseudonymize what is collected, obtain the Article 13/23 consent, and honor the Article 24 opt-out, not to make the offshore service reachable. The app that runs Heap still owes an ICP filing and in-country delivery.

What you actually send — your users’ attributes and behavior

Start with what Heap actually collects. Heap is an autocapture analytics platform: you add one snippet, and from that moment it records your users’ interactions automatically. Heap’s own platform page is blunt about the breadth — “a single snippet grabs every click, swipe, tap, pageview, and fill — forever,” it “collects all behavioral data immediately,” and it keeps “all data available for analysis” so you can “dig through and analyze historical data in any way you want.” There is no track('event') to decide in advance what matters; the default is to capture everything. For your China users that means the payload leaving the country is their whole behavioral stream — what they clicked, typed into (not necessarily the values, but the fields and flows), viewed, and when — joined to an identity when you call Heap’s identify step and enriched with user traits (account, role, device, approximate location).

Then the part teams forget: Heap does not just measure, it retains and resolves. Events are stitched to persistent user identities and accumulated into unified behavioral profiles that sit in Heap’s US or EU region indefinitely, queryable retroactively. Heap’s warehouse-sync feature can replicate that behavioral dataset onward into your own data warehouse, so the same personal information fans out to further systems. This is the sub-type that matters here: not a flag evaluated once and forgotten, but a permanent, growing offshore store of profiles built from your China users’ behavior — exactly the asset a product-analytics and customer-data platform exists to create.

Where does it go? To a region outside the mainland. Heap, now part of Contentsquare, lets a customer host Product Analytics in the US (Virginia) or the EU (Ireland, with Frankfurt for at-rest storage); its ingestion endpoints are US-default with an EU alternative, and neither is in China. The “pick the nearest region” reflex does not help: every Heap region is offshore from the mainland, and Hong Kong would be a separate jurisdiction for data-export purposes anyway. So the behavioral profiles your China users generate are built and kept abroad.

It’s a cross-border transfer — and an automated decision — under PIPL

Because your China users’ behavior and identities leave China to be processed, stored and acted on, sending them to Heap is a cross-border transfer of personal information, not a routing detail — and the duty sits on you as the handler, not on Heap as the processor. PIPL Articles 38–40 require that, before personal information is sent abroad, you give notice, obtain a separate consent distinct from any general agreement to use your product, and put one transfer mechanism in place — a CAC security assessment, the CAC standard contract, or certification. Autocapturing behavioral events in the first place needs a lawful basis and consent under Articles 13 and 23; a “by using this product you agree” line does not carry non-essential behavioral tracking. Above certain thresholds, genuinely necessary exports also run through China’s data-export security assessment (数据出境安全评估) before anything leaves.

The distinctive prong is the one most teams miss. A behavioral profile is not collected for its own sake — it is used to decide what each user sees: which segment they fall into, which experiment variant, which personalized experience. Under PIPL Article 24, that is automated decision-making. Article 24 requires the decisioning to be transparent and fair in result, gives the individual a way to refuse, and — where a decision or a push is based on profiling — requires that you offer an option not to target them by their personal characteristics. Running an experiment on a cohort, targeting an audience, or personalizing from a Heap profile is profiling under Article 24; “we only analyze aggregates” does not exempt a system that resolves events to a named person and acts on their profile.

Residency is the other half. If your organization is a critical information infrastructure operator — or a high-volume personal-information handler — the Cybersecurity Law’s Article 39 (formerly Article 37 — the 2025 Cybersecurity Law amendment, in force January 1, 2026, renumbered the data-localization article from 37 to 39, its substance unchanged) requires personal information generated in China to be stored in China, with any genuinely necessary export cleared through a security assessment (see also PIPL Article 40). A platform whose whole value is a permanent, growing offshore profile of each user is squarely in tension with that duty. None of this turns on how fast the snippet loads, so this page publishes no China latency figure for Heap: speed is not the axis for a decision that turns on cross-border transfer, automated decision-making, consent and residency.

Reaching the snippet isn’t the question — keeping the decisioning in-country is

The reflex is to point Heap at the nearest region and treat the distance as the problem solved. But every Heap region sits outside mainland China, and — unlike some analytics engines — Heap offers no self-hosted or private mainland deployment: the only residency choice is a US or EU region, both offshore. A nearer region changes the latency, not the law; the behavior, identities and profiles still cross the border, are still built and kept abroad, and are still used to decide what each user sees.

So the honest levers are these, and none of them is “make the offshore service reachable.” First, because Heap offers no in-country region and no self-hosted build, the durable option for China users is to keep the behavioral data and the decisioning in-country — route China-user analytics and personalization through a licensed, China-resident product-analytics or customer-data path that keeps the events and profiles in the mainland — while you keep Heap for the markets it already serves. Second, minimize, pseudonymize and consent: autocapture the least identifying data the use case needs (evaluate and segment without raw identifiers where you can), obtain the Article 13/23 consent for behavioral tracking, and honor the Article 24 right to refuse profiling and to a non-profiled option. Third, keep a lawful cross-border basis for anything that genuinely still leaves. What none of this is: a tunnel that ships the behavioral data offshore anyway and calls it local.

This is a risk map, not a verdict that Heap is “blocked” or “illegal.” Which of these obligations bite depends on your entity, the behavior and identities your snippet captures, your role under Chinese law and who your users are — worth settling the specifics with counsel before your analytics and personalization pipeline depends on it.

The lawful path — map, localize, deliver

There is a compliant way to run product analytics and personalization for a China-facing audience, and it has a shape.

First, map. Our China compliance team inventories what your Heap snippet actually captures today — which events and traits reach China users, what personal information they carry, where they are processed and stored, how the resulting profiles drive segments, experiments and personalization (the automated decision-making), whether a persistent profile store accumulates offshore, and the consent basis for the behavioral tracking. We build the technical picture; the legal conclusions are settled with your counsel.

Then localize. Where China-user analytics has to run on a China footing, we move the behavioral data and the decisioning onto a licensed, China-resident path — the events and profiles kept in the mainland — minimize and pseudonymize what is collected, obtain the Article 13/23 consent, and wire in the Article 24 right to refuse profiling and to a non-profiled option. Localize means your China users’ behavior and profiles stop leaving the country by default — never a tunnel that ships the data offshore anyway. You keep Heap for the markets and products where it already serves you, and 21YunBox is advisory on which lawful basis and which in-country operator fit your case.

Then deliver. The China-facing site or app that embeds the Heap snippet is itself a public-facing service in the mainland, so it carries an ICP filing duty and needs compliant, in-country delivery. 21YunBox delivers it in-country — the 21YunBox Optimizer — set in front of the origin you already run, with no rebuild and no re-platform. The result is a China-facing product whose analytics and delivery both run legally and compliantly for your users in China. 21YunBox never uses or suggests circumvention of any kind: we keep China-user behavior on a consented, in-country path, honor the Article 24 rights, deliver in-country, and never move personal information out of China by stealth. We are a compliant overlay and a partner to Heap and Contentsquare, not a competitor and not a migration.

Get a compliance assessment →


Related reading:

Frequently Asked Questions

Does Heap store Chinese users' data in China?
No. Heap — now part of Contentsquare — hosts Product Analytics data only in a US region (Virginia) or an EU region (Ireland, with Frankfurt for at-rest storage). There is no mainland-China region, so the behavior Heap autocaptures from your China users is processed and stored offshore — a PIPL cross-border transfer of their personal information.
Is using Heap in China an automated-decision problem under PIPL?
It can be. Building segments, running experiments and personalizing what each user sees from Heap's behavioral profiles is automated decision-making and profiling under PIPL Article 24, which requires transparency, a way to refuse, and — for profiling-based decisions — an option not to be targeted by personal characteristics. Autocapturing the behavior in the first place also needs Article 13/23 consent.
Can 21YunBox make our Heap setup compliant in China?
We map what behavior and identities flow to Heap and how they drive decisions, keep the data and the decisioning on a lawful in-country path (a licensed domestic analytics alternative, minimized and consented, with the Article 24 opt-out), and deliver the China-facing app in-country on ICP-filed infrastructure — in front of the stack you already run. We keep China-user behavior on a lawful in-country path and never move personal information out of the country by stealth; the legal specifics are settled with your counsel.

ARTICLES RELATED TO HEAP

Make Your Site Work inside the Great Firewall of China

Enter your information, and our staff will assist you in getting a 21YunBox account for China.

Make Your Site Work Within the Great Firewall of China
Make Your Site Work Within the Great Firewall of China

By clicking 'Get Started', I also agree to 21YunBox's Terms of Service and Privacy Policy.