Does Help Scout Work in China? PIPL Cross-Border, Data Residency & Consent
Help Scout is a US shared-inbox helpdesk hosted on AWS in the United States, with no mainland-China region and no self-host: your China customers' tickets, emails, chat transcripts and profiles sit offshore — a PIPL cross-border transfer — its Beacon widget ships visitor data offshore before consent, and its AI Answers bot auto-replies to customers. A compliance-first look at the residency, consent and automated-decision exposure.
Does Help Scout work in China?
Help Scout runs on AWS in the United States with no mainland-China region, so your China customers' tickets, emails, chat transcripts and profiles sit offshore, its Beacon widget ships visitor data offshore before consent, and its AI Answers bot auto-replies to customers — the support surface needs an ICP filing and a lawful in-country path.
A shared inbox holds personal information — the conversations, customer profiles and contact details your team collects — and the embedded Beacon widget loads third-party JavaScript that sends a visitor's IP, page behavior and messages to Help Scout on page load. Running that for mainland users is a PIPL cross-border transfer (Articles 38–40) that you, the handler, perform; the widget raises an Article 13/23 consent problem because data moves before any consent is given; and AI Answers and AI Drafts bring the Article 24 automated-decision duties. The lawful lever is to keep China conversations and PII in-country, gate and consent the widget, meet the Article 24 duties and ICP-file the surface — not to make the offshore widget reachable.
This is a risk map, not a verdict — which prongs bind turns on your entity, data volumes and users, so settle the specifics with counsel. Our China team can map your exposure →
What Help Scout's own documentation says about China
| Fact | Primary source |
|---|---|
| Help Scout hosts on AWS in the United States, with no mainland-China region. Its security documentation states: “Help Scout is hosted on AWS servers in the United States. We have customers all over the world.” The page names no mainland-China region, so your China customers' tickets, emails, chat transcripts and profiles are stored offshore. | Help Scout, “Security at Help Scout” (docs.helpscout.com), retrieved 2026-10-10 |
| Help Scout's own sub-processor list names AWS for hosting and OpenAI for AI — all in the USA, none in China. The list records Amazon Web Services under “Cloud infrastructure hosting” located in the “USA,” and names OpenAI (the engine behind its AI drafting and customer-facing AI Answers) as a USA sub-processor; every entry is in the USA or UK, with none in mainland China. Beacon, its embedded chat widget, loads this stack as third-party JavaScript on your site. | Help Scout, “Sub-processors” list (helpscout.com), retrieved 2026-10-10 |
| Sending mainland users' personal information to an offshore platform is a PIPL cross-border transfer. A support conversation — names, emails, and what customers disclose about themselves — is personal information; handled on a US-hosted helpdesk, it triggers PIPL Articles 38–40: notice, a separate consent distinct from agreeing to use the service, and one transfer mechanism (a CAC security assessment, the CAC standard contract, or certification). | Personal Information Protection Law of the PRC, Articles 38–40 (cac.gov.cn), retrieved 2026-10-10 |
| For a CIIO or high-volume handler, mainland personal information must stay in-country. China's Cybersecurity Law Article 39 (formerly Article 37 — the 2025 Cybersecurity Law amendment, in force January 1, 2026, renumbered the data-localization article from 37 to 39; the substance is unchanged) requires in-country storage — a duty a service that runs only on AWS in the United States cannot meet. | Cybersecurity Law of the PRC, Article 39 (formerly Article 37) (cac.gov.cn), retrieved 2026-10-10 |
Sources verified by the 21YunBox compliance team on 2026-10-10.
If you run customer support for users in mainland China on Help Scout, the deciding question is not whether the inbox loads or the Beacon widget appears — it is where your customers’ conversations and profiles live, whether that embedded widget ships visitor data offshore before anyone consents, whether Help Scout’s AI makes automated decisions about your customers, and whether the support surface is ICP-filed. Help Scout is a US shared-inbox and helpdesk platform: by its own security documentation it is hosted on AWS servers in the United States, with no mainland-China region, and it runs as managed SaaS with no self-hostable engine. Its Beacon widget is embedded JavaScript on your site, and its AI Answers bot auto-replies to customers inside it. That posture raises four compliance prongs — conversation and customer-PII residency and cross-border transfer, embedded-widget governance, AI automated decision-making, and ICP for the support surface.
Help Scout in China at a glance
| What decides it | In Help Scout's own terms — and China's law |
|---|---|
| What it holds | Tickets, emails and chat transcripts, plus the customer profiles and contact details your team collects — including what customers disclose about themselves. That is personal information, not anonymous metrics. The Beacon widget also captures each visitor's IP, page behavior and messages. |
| Where it runs | "Help Scout is hosted on AWS servers in the United States"; its sub-processor list places every sub-processor in the USA or UK, none in mainland China. Running it for China customers is a PIPL cross-border transfer (Articles 38–40, 数据出境); for a CIIO or high-volume handler, mainland data must stay in-country under Cybersecurity Law Article 39 (formerly Article 37). |
| The embedded-widget door | Beacon is third-party JavaScript that loads on page open and sends the visitor's IP, behavior and message content to Help Scout's US infrastructure before any consent. That is both a transfer and a PIPL Article 13/23 consent problem — it must be gated and consented, minimized, or replaced with an in-country path. |
| AI automated decisions | Help Scout ships AI Answers (a customer-facing bot inside Beacon), plus AI Drafts, AI Summarize and AI Assist on the agent side; its sub-processor list names OpenAI. Where AI auto-answers or scores a customer, that is automated decision-making under PIPL Article 24 — transparency, fairness, and a route to human review. |
| Reachability is not the axis | The inbox opening or the widget painting resolves none of the above. The lever is to keep China conversations and PII in-country, gate and consent the widget, meet the Article 24 duties for any AI, and ICP-file the support surface — not to make an offshore widget reachable. |
What you actually hold — conversations, customer profiles, and a widget that phones home
A helpdesk is a store of personal information. When you run Help Scout for China customers, the shared inbox holds the tickets, emails and chat transcripts your team exchanges with them, the customer profiles and contact details attached to each conversation, and — very often — what a customer volunteers about themselves while asking for help. None of that is anonymous telemetry; it names, contacts and profiles individual people, which is exactly the category China’s law protects. All of it is processed and stored on Help Scout’s infrastructure, which its own security page places on AWS servers in the United States, with no mainland-China region and no open-source engine you could self-host inside the mainland.
Layered on top is the Beacon widget, and it behaves differently from the inbox. Beacon is an HTML-and-JavaScript snippet you embed in your pages; once it loads it can offer a contact form, live chat, your Docs articles and AI help. Because it is third-party script running on your China-facing site, it reaches out to Help Scout’s US infrastructure as the page opens — carrying the visitor’s IP, the pages they view and anything they type — rather than waiting for a deliberate action. Help Scout also ships AI: AI Answers replies to a visitor’s question directly inside Beacon, while AI Drafts, AI Summarize and AI Assist work on the agent side, and its sub-processor list names OpenAI as the engine behind them. Any model that answers or scores a customer is a PIPL Article 24 automated-decision concern.
The doors: cross-border conversation data, widget consent, and automated decisions
Cross-border transfer. Because your China customers’ conversations and profiles are collected in the mainland and stored on AWS in the United States, PIPL treats the flow as a cross-border transfer that you — the handler, with Help Scout as the processor — must clear: notice to the individual, a separate consent distinct from agreeing to use your product, and one transfer mechanism, namely a CAC security assessment, the CAC standard contract, or certification (Articles 38–40). See cross-border data transfers under PIPL. If your operating entity is critical information infrastructure, or handles personal information above the state threshold, the mainland-collected data must stay in the mainland — the data-localization duty in Cybersecurity Law Article 39 (formerly Article 37, renumbered by the 2025 Cybersecurity Law amendment in force January 1, 2026; the substance is unchanged) — which a service that runs only on AWS in the United States cannot satisfy.
Widget consent. The Beacon widget is a consent problem of its own. Because it ships the visitor’s IP, behavior and message content offshore on page load, data crosses the border before the visitor has agreed to anything — which is both a transfer and a PIPL Article 13/23 consent failure. Making the offshore endpoint reachable does not fix it; the widget has to be gated so it does not fire before a lawful basis exists, pared back to the minimum it needs, or replaced with an in-country path.
Automated decisions. Where AI Answers auto-replies to a customer, or any model triages, routes or scores them, that is automated decision-making under PIPL Article 24, which requires transparency, fairness in the outcome, and a route to human review. Name it only where the feature is actually in use — but on Help Scout, with a customer-facing bot built into Beacon, it frequently is.
Loading the widget isn’t the question — a compliant in-country support path is
That the Beacon script loads and the inbox opens from inside China tells you nothing about any of these doors. Reachability is not the axis; the axis is compliance risk. A lawful setup has a definite shape: your China customers’ conversations and personal information are kept on an in-country path — an in-country support deployment, with what you collect minimized and pseudonymized — the Beacon widget is gated and consented so it does not ship visitor data before a basis exists, the Article 24 duties are met for AI Answers and any scoring model, and the China-facing help center, chat page or widget host is ICP-filed. What it is not is a hidden route that carries the conversations offshore anyway while presenting them as local; keeping the data in-country means the data actually stays in-country.
This page is a risk map, not a verdict. Which prongs bind your specific deployment — whether you owe a cross-border mechanism, in-country storage, widget-consent changes, Article 24 measures, or all of them — turns on your entity, your data volumes and who your users are, so settle the specifics with counsel before you build.
The lawful path — map, localize, deliver
There is a clean way to run Help Scout for customers in mainland China, and it does not involve working around anything. Our China team does three things. We map what your support stack holds — the tickets, emails, chat transcripts and customer profiles, and the data the Beacon widget captures on load — where each is processed and stored (an offshore region, with no mainland-China option), whether Help Scout’s AI answers or scores your customers (Article 24), and the consent basis you need. We localize: keep China-customer conversations and PII on an in-country path, gate and consent the Beacon widget so it does not ship visitor data before a lawful basis, minimize and pseudonymize what is collected, meet the Article 24 duties for AI Answers and AI Drafts, and obtain the Article 13/23 consent — localizing means the data stays on an in-country path, never a route that sends it offshore anyway. We deliver the China-facing support surface — a public service that carries an ICP filing duty — on compliant, in-country infrastructure, the 21YunBox Optimizer, in front of the stack you already run, with no rebuild. 21YunBox is a compliant overlay and partner, not a competitor to Help Scout. The result is customer support that runs legally and compliantly for your users in China. 21YunBox never uses or suggests circumvention of any kind.
Related reading:
- Cross-border data transfers under PIPL
- China’s Cybersecurity Law — data localization (Article 39, formerly Article 37)
- China’s Personal Information Protection Law (PIPL)
- How to get an ICP filing for China
