Why 21YunBox Pricing Contact Log in
Talk to an expert Test your site in China

Does Help Scout Work in China? PIPL Cross-Border, Data Residency & Consent

Help Scout is a US shared-inbox helpdesk hosted on AWS in the United States, with no mainland-China region and no self-host: your China customers' tickets, emails, chat transcripts and profiles sit offshore — a PIPL cross-border transfer — its Beacon widget ships visitor data offshore before consent, and its AI Answers bot auto-replies to customers. A compliance-first look at the residency, consent and automated-decision exposure.

Does Help Scout work in China?

Help Scout runs on AWS in the United States with no mainland-China region, so your China customers' tickets, emails, chat transcripts and profiles sit offshore, its Beacon widget ships visitor data offshore before consent, and its AI Answers bot auto-replies to customers — the support surface needs an ICP filing and a lawful in-country path.

A shared inbox holds personal information — the conversations, customer profiles and contact details your team collects — and the embedded Beacon widget loads third-party JavaScript that sends a visitor's IP, page behavior and messages to Help Scout on page load. Running that for mainland users is a PIPL cross-border transfer (Articles 38–40) that you, the handler, perform; the widget raises an Article 13/23 consent problem because data moves before any consent is given; and AI Answers and AI Drafts bring the Article 24 automated-decision duties. The lawful lever is to keep China conversations and PII in-country, gate and consent the widget, meet the Article 24 duties and ICP-file the surface — not to make the offshore widget reachable.

This is a risk map, not a verdict — which prongs bind turns on your entity, data volumes and users, so settle the specifics with counsel. Our China team can map your exposure →

What Help Scout's own documentation says about China

FactPrimary source
Help Scout hosts on AWS in the United States, with no mainland-China region. Its security documentation states: “Help Scout is hosted on AWS servers in the United States. We have customers all over the world.” The page names no mainland-China region, so your China customers' tickets, emails, chat transcripts and profiles are stored offshore. Help Scout, “Security at Help Scout” (docs.helpscout.com), retrieved 2026-10-10
Help Scout's own sub-processor list names AWS for hosting and OpenAI for AI — all in the USA, none in China. The list records Amazon Web Services under “Cloud infrastructure hosting” located in the “USA,” and names OpenAI (the engine behind its AI drafting and customer-facing AI Answers) as a USA sub-processor; every entry is in the USA or UK, with none in mainland China. Beacon, its embedded chat widget, loads this stack as third-party JavaScript on your site. Help Scout, “Sub-processors” list (helpscout.com), retrieved 2026-10-10
Sending mainland users' personal information to an offshore platform is a PIPL cross-border transfer. A support conversation — names, emails, and what customers disclose about themselves — is personal information; handled on a US-hosted helpdesk, it triggers PIPL Articles 38–40: notice, a separate consent distinct from agreeing to use the service, and one transfer mechanism (a CAC security assessment, the CAC standard contract, or certification). Personal Information Protection Law of the PRC, Articles 38–40 (cac.gov.cn), retrieved 2026-10-10
For a CIIO or high-volume handler, mainland personal information must stay in-country. China's Cybersecurity Law Article 39 (formerly Article 37 — the 2025 Cybersecurity Law amendment, in force January 1, 2026, renumbered the data-localization article from 37 to 39; the substance is unchanged) requires in-country storage — a duty a service that runs only on AWS in the United States cannot meet. Cybersecurity Law of the PRC, Article 39 (formerly Article 37) (cac.gov.cn), retrieved 2026-10-10

Sources verified by the 21YunBox compliance team on 2026-10-10.

If you run customer support for users in mainland China on Help Scout, the deciding question is not whether the inbox loads or the Beacon widget appears — it is where your customers’ conversations and profiles live, whether that embedded widget ships visitor data offshore before anyone consents, whether Help Scout’s AI makes automated decisions about your customers, and whether the support surface is ICP-filed. Help Scout is a US shared-inbox and helpdesk platform: by its own security documentation it is hosted on AWS servers in the United States, with no mainland-China region, and it runs as managed SaaS with no self-hostable engine. Its Beacon widget is embedded JavaScript on your site, and its AI Answers bot auto-replies to customers inside it. That posture raises four compliance prongs — conversation and customer-PII residency and cross-border transfer, embedded-widget governance, AI automated decision-making, and ICP for the support surface.

Help Scout's Security documentation stating 'Help Scout is hosted on AWS servers in the United States,' naming no mainland-China region
"Help Scout is hosted on AWS servers in the United States." Help Scout's own security page names Amazon Web Services in the US as its hosting and lists no mainland-China region, so your China customers' tickets, emails and chat transcripts are stored offshore. Source: Help Scout — Security

Help Scout in China at a glance

What decides it In Help Scout's own terms — and China's law
What it holds Tickets, emails and chat transcripts, plus the customer profiles and contact details your team collects — including what customers disclose about themselves. That is personal information, not anonymous metrics. The Beacon widget also captures each visitor's IP, page behavior and messages.
Where it runs "Help Scout is hosted on AWS servers in the United States"; its sub-processor list places every sub-processor in the USA or UK, none in mainland China. Running it for China customers is a PIPL cross-border transfer (Articles 38–40, 数据出境); for a CIIO or high-volume handler, mainland data must stay in-country under Cybersecurity Law Article 39 (formerly Article 37).
The embedded-widget door Beacon is third-party JavaScript that loads on page open and sends the visitor's IP, behavior and message content to Help Scout's US infrastructure before any consent. That is both a transfer and a PIPL Article 13/23 consent problem — it must be gated and consented, minimized, or replaced with an in-country path.
AI automated decisions Help Scout ships AI Answers (a customer-facing bot inside Beacon), plus AI Drafts, AI Summarize and AI Assist on the agent side; its sub-processor list names OpenAI. Where AI auto-answers or scores a customer, that is automated decision-making under PIPL Article 24 — transparency, fairness, and a route to human review.
Reachability is not the axis The inbox opening or the widget painting resolves none of the above. The lever is to keep China conversations and PII in-country, gate and consent the widget, meet the Article 24 duties for any AI, and ICP-file the support surface — not to make an offshore widget reachable.

What you actually hold — conversations, customer profiles, and a widget that phones home

A helpdesk is a store of personal information. When you run Help Scout for China customers, the shared inbox holds the tickets, emails and chat transcripts your team exchanges with them, the customer profiles and contact details attached to each conversation, and — very often — what a customer volunteers about themselves while asking for help. None of that is anonymous telemetry; it names, contacts and profiles individual people, which is exactly the category China’s law protects. All of it is processed and stored on Help Scout’s infrastructure, which its own security page places on AWS servers in the United States, with no mainland-China region and no open-source engine you could self-host inside the mainland.

Layered on top is the Beacon widget, and it behaves differently from the inbox. Beacon is an HTML-and-JavaScript snippet you embed in your pages; once it loads it can offer a contact form, live chat, your Docs articles and AI help. Because it is third-party script running on your China-facing site, it reaches out to Help Scout’s US infrastructure as the page opens — carrying the visitor’s IP, the pages they view and anything they type — rather than waiting for a deliberate action. Help Scout also ships AI: AI Answers replies to a visitor’s question directly inside Beacon, while AI Drafts, AI Summarize and AI Assist work on the agent side, and its sub-processor list names OpenAI as the engine behind them. Any model that answers or scores a customer is a PIPL Article 24 automated-decision concern.

Cross-border transfer. Because your China customers’ conversations and profiles are collected in the mainland and stored on AWS in the United States, PIPL treats the flow as a cross-border transfer that you — the handler, with Help Scout as the processor — must clear: notice to the individual, a separate consent distinct from agreeing to use your product, and one transfer mechanism, namely a CAC security assessment, the CAC standard contract, or certification (Articles 38–40). See cross-border data transfers under PIPL. If your operating entity is critical information infrastructure, or handles personal information above the state threshold, the mainland-collected data must stay in the mainland — the data-localization duty in Cybersecurity Law Article 39 (formerly Article 37, renumbered by the 2025 Cybersecurity Law amendment in force January 1, 2026; the substance is unchanged) — which a service that runs only on AWS in the United States cannot satisfy.

Widget consent. The Beacon widget is a consent problem of its own. Because it ships the visitor’s IP, behavior and message content offshore on page load, data crosses the border before the visitor has agreed to anything — which is both a transfer and a PIPL Article 13/23 consent failure. Making the offshore endpoint reachable does not fix it; the widget has to be gated so it does not fire before a lawful basis exists, pared back to the minimum it needs, or replaced with an in-country path.

Automated decisions. Where AI Answers auto-replies to a customer, or any model triages, routes or scores them, that is automated decision-making under PIPL Article 24, which requires transparency, fairness in the outcome, and a route to human review. Name it only where the feature is actually in use — but on Help Scout, with a customer-facing bot built into Beacon, it frequently is.

Loading the widget isn’t the question — a compliant in-country support path is

That the Beacon script loads and the inbox opens from inside China tells you nothing about any of these doors. Reachability is not the axis; the axis is compliance risk. A lawful setup has a definite shape: your China customers’ conversations and personal information are kept on an in-country path — an in-country support deployment, with what you collect minimized and pseudonymized — the Beacon widget is gated and consented so it does not ship visitor data before a basis exists, the Article 24 duties are met for AI Answers and any scoring model, and the China-facing help center, chat page or widget host is ICP-filed. What it is not is a hidden route that carries the conversations offshore anyway while presenting them as local; keeping the data in-country means the data actually stays in-country.

This page is a risk map, not a verdict. Which prongs bind your specific deployment — whether you owe a cross-border mechanism, in-country storage, widget-consent changes, Article 24 measures, or all of them — turns on your entity, your data volumes and who your users are, so settle the specifics with counsel before you build.

The lawful path — map, localize, deliver

There is a clean way to run Help Scout for customers in mainland China, and it does not involve working around anything. Our China team does three things. We map what your support stack holds — the tickets, emails, chat transcripts and customer profiles, and the data the Beacon widget captures on load — where each is processed and stored (an offshore region, with no mainland-China option), whether Help Scout’s AI answers or scores your customers (Article 24), and the consent basis you need. We localize: keep China-customer conversations and PII on an in-country path, gate and consent the Beacon widget so it does not ship visitor data before a lawful basis, minimize and pseudonymize what is collected, meet the Article 24 duties for AI Answers and AI Drafts, and obtain the Article 13/23 consent — localizing means the data stays on an in-country path, never a route that sends it offshore anyway. We deliver the China-facing support surface — a public service that carries an ICP filing duty — on compliant, in-country infrastructure, the 21YunBox Optimizer, in front of the stack you already run, with no rebuild. 21YunBox is a compliant overlay and partner, not a competitor to Help Scout. The result is customer support that runs legally and compliantly for your users in China. 21YunBox never uses or suggests circumvention of any kind.

Get a compliance assessment →


Related reading:

Frequently Asked Questions

Does Help Scout have a data center in mainland China?
No. By its own security documentation Help Scout is hosted on AWS servers in the United States, and its sub-processor list places every sub-processor in the USA or UK — none in mainland China. Running China support on it therefore stores your customers' tickets, emails, chat transcripts and profiles offshore, which makes it a PIPL cross-border transfer (Articles 38–40) that you, as the handler, must give notice of, obtain a separate consent for, and clear a transfer mechanism for. Reachability is not the question; residency and consent are. Settle the specifics with counsel.
Is the Help Scout Beacon chat widget a compliance problem in China?
It can be. Beacon is embedded JavaScript on your site, and it loads before a visitor acts — sending the visitor's IP, page behavior and any message to Help Scout's US infrastructure on page load. That is both a cross-border transfer and a PIPL Article 13/23 consent problem, because data moves before any consent is given. And where the AI Answers bot replies to a customer inside Beacon, that is automated decision-making under PIPL Article 24. The lawful fix is to gate and consent the widget, minimize what it collects, or replace it with an in-country path — not to make the offshore widget reachable.
What is the lawful way to run Help Scout for China customers, and what does 21YunBox do?
Keep your China customers' conversations and personal information on an in-country path, gate and consent the Beacon widget, meet the Article 24 duties for AI Answers and AI Drafts, and ICP-file the China-facing help center or support page. Help Scout stays where it runs for your other markets. 21YunBox is a compliant overlay and partner: we map your conversation-data, widget and AI exposure, help you stand up the in-country support-data path and widget governance, and deliver the ICP-filed support surface in front of the stack you already run — no rebuild. We never use or suggest circumvention of any kind. Get in touch to map your case.

ARTICLES RELATED TO HELP SCOUT

Make Your Site Work inside the Great Firewall of China

Enter your information, and our staff will assist you in getting a 21YunBox account for China.

Make Your Site Work Within the Great Firewall of China
Make Your Site Work Within the Great Firewall of China

By clicking 'Get Started', I also agree to 21YunBox's Terms of Service and Privacy Policy.