Why 21YunBox Pricing Contact Log in
Talk to an expert Test your site in China

Does Iterable Work in China? PIPL Cross-Border, Delivery & Data Residency

Iterable takes your users' device tokens, profiles and message content and delivers push, email and SMS from its US or EU (Ireland) data centers — there is no mainland-China region — so each send to a China user is a PIPL cross-border transfer, and its Android push rides Firebase Cloud Messaging, unavailable on most mainland devices. A compliance-first look at the residency, cross-border and delivery-channel duties.

Does Iterable work in China?

You hand Iterable your China users' device tokens, profiles and message content to deliver push, email and SMS from its US or EU data centers — a PIPL cross-border transfer — and its Android push rides Firebase Cloud Messaging, which is unavailable on most mainland-China Android devices.

To send, you upload device push tokens, user IDs, email addresses, phone numbers, profile attributes and events; Iterable's segments and journeys decide who gets which message and deliver it. On users in China those identifiers and that content are personal information, so routing them to Iterable's offshore service is a PIPL cross-border transfer (Articles 38-40), with marketing-push consent (Articles 13 and 23) and Article 24 profiling duties. And because Firebase Cloud Messaging depends on Google Play Services — absent from most mainland Android devices — reliable Android push needs a licensed in-country delivery channel, not a reachable offshore endpoint. The lawful lever is to keep delivery and recipient data in-country on a licensed path (manufacturer channels for Android, minimize and pseudonymize, hold consent), never to make the offshore SDK reachable.

This is a risk map, not a verdict — settle the specifics with counsel. Our China team can map your exposure →

What Iterable's own documentation says about China

FactPrimary source
Iterable has no mainland-China region. Its own documentation offers two data centers — a US data center (USDC) and a European data center (EDC) in Ireland — and states that "Most Iterable customers use Iterable's US data center," with an organization's projects hosted entirely "in the US, or all in the EU." There is no mainland-China option, so your China users' device tokens, profiles, content and engagement events are processed and stored offshore. Iterable Support — Iterable's European Data Center (EDC), retrieved 2026-10-10
Android push rides Firebase Cloud Messaging (FCM). Iterable's setup guide states, "To send Android push notifications, Iterable uses Firebase Cloud Messaging (FCM)," and documents no Chinese manufacturer push channel (such as Huawei/HMS or Xiaomi). FCM depends on Google Play Services, which is absent from most mainland-China Android devices, so FCM-only push is unreliable to Chinese Android users; Iterable's published sub-processors sit in the US, Ireland and Germany — none in China. Iterable Support — Setting up Android Push Notifications; Iterable Sub-Processors (Aug 2026), retrieved 2026-10-10
Delivering to a person in China is a cross-border transfer you must govern. The device tokens, email/phone, profile attributes and message content you send Iterable are personal information; routing them to its offshore service is a PIPL cross-border transfer (Articles 38-40) requiring notice, a separate consent and a transfer mechanism. Marketing push adds a lawful-basis-and-consent and opt-out duty (Articles 13 and 23), and deciding who gets which message from a profile engages Article 24 automated decision-making. PIPL Articles 38-40 (cross-border), 13 and 23 (consent), 24 (automated decisions)
A CIIO or high-volume handler must keep the data in China. Where you are a critical information infrastructure operator or high-volume handler, personal information collected in China must be stored in the mainland (Cybersecurity Law Article 39, formerly Article 37 — the 2025 Cybersecurity Law amendment, in force January 1, 2026, renumbered the data-localization article from 37 to 39, substance unchanged; PIPL Article 40). An offshore US or EU region cannot satisfy that in-country storage duty. China Cybersecurity Law Article 39 (formerly Article 37); PIPL Article 40

Sources verified by the 21YunBox compliance team on 2026-10-10.

For a product that sends push, email, SMS or in-app messages to users in mainland China, the first question about Iterable is usually whether its API and SDKs can be reached. They can — so reachability is not where the China decision is made. It turns on what happens when you hand Iterable your China users’ identifiers and message content to deliver. Iterable is a cross-channel engagement platform: you upload device push tokens, user IDs, email addresses and phone numbers, profile attributes and events, and its segments and journeys decide who receives which message, then deliver it — all processed in Iterable’s US or EU (Ireland) data centers, with no mainland-China region. On China users that is at once a PIPL cross-border transfer of personal information and content (Articles 38–40, 数据出境); an Android delivery-channel door, because Iterable’s push rides Firebase Cloud Messaging, unavailable on most mainland Android devices; a marketing-consent duty (Articles 13 and 23); Article 24 profiling where segments decide who gets what; and, for a CIIO or high-volume handler, in-country storage.

Iterable's own Android push setup documentation stating that to send Android push notifications Iterable uses Firebase Cloud Messaging (FCM), and describing a Firebase service account and JSON key — with no Chinese manufacturer push channel documented
Iterable's own setup guide states: “To send Android push notifications, Iterable uses Firebase Cloud Messaging (FCM).” It documents only FCM — which depends on Google Play Services, unavailable on most mainland-China Android devices — and no Chinese manufacturer push channel, so reaching Chinese Android users reliably needs a licensed in-country delivery path. Source: Iterable — Setting up Android Push Notifications

Iterable in China at a glance

What decides it In Iterable's own terms — and China's law
What you send Iterable is a cross-channel engagement platform. To send, you upload device push tokens, user IDs, email addresses and phone numbers, profile attributes and events — plus the message body itself (a one-time passcode, an order update, a promotion). For recipients in the mainland, all of it is personal information.
Where it is processed and stored Offshore. Iterable runs a US data center (USDC) and a European data center (EDC) in Ireland; most accounts sit in the US, and an organization's projects must all be in the US or all in the EU. There is no mainland-China region, and its published sub-processors — Amazon Web Services and its email and SMS providers — sit in the US, Ireland and Germany. Sending your China users' data there is a cross-border transfer (数据出境) under PIPL (Articles 38–40).
How Android push is delivered Iterable's Android push rides Firebase Cloud Messaging (FCM), which depends on Google Play Services — unavailable on most mainland-China Android devices — and Iterable documents no Chinese manufacturer push channel. Reaching Chinese Android users means routing through licensed in-country manufacturer channels (Xiaomi, Huawei/HMS, OPPO, vivo, Honor). iOS APNs works in China, but the device token and content still cross the border.
Consent, profiling and residency Promotional push needs a lawful basis and consent, with opt-out honored (PIPL Articles 13 and 23). Because Iterable's segments and journeys decide who receives which message, Article 24 automated decision-making applies. A critical information infrastructure operator or high-volume handler also carries an in-country storage duty (Cybersecurity Law Article 39, formerly Article 37).
The lawful path Reachability is not the axis. Keep China-user delivery and recipient data in-country — route Android push through licensed in-country manufacturer channels, minimize and pseudonymize what is sent, hold the marketing consent and the Article 24 opt-out — and deliver the China-facing app in-country on ICP-filed infrastructure. 21YunBox maps, localizes and delivers, in front of the stack you already run.

What you actually send — recipient identifiers, profiles and content

An engagement platform is not a passive pipe. To send a push notification, an email or an SMS to someone in Shanghai, you first give Iterable the raw materials: that person’s device push token or address, a user ID, often an email and phone number, and the profile attributes and behavioral events you have collected — then the message content itself. Iterable stores those profiles and events to build audiences, which is the point of the product: its segments and journeys target and time each message from the data you have loaded. So Iterable does not merely relay a message; it accumulates a persistent, queryable store of who your China users are and what they do.

That store, and the processing around it, live offshore. Iterable’s own documentation describes two data centers — a US data center and a European data center in Ireland — and states that “Most Iterable customers use Iterable’s US data center,” with each organization’s projects hosted entirely “in the US, or all in the EU.” Its published sub-processor list places its infrastructure (Amazon Web Services) and its email and SMS delivery providers in the United States, Ireland and Germany. None of that is in mainland China. The device tokens, contact details, profiles, message content and engagement events your China-facing program generates sit on that offshore infrastructure for as long as Iterable holds them — and that retained, offshore personal information is what China’s law weighs, not how quickly the API answers.

It’s a cross-border transfer — and Android delivery has its own door — under PIPL

Here is the gate most teams miss. The device tokens, email addresses, phone numbers, profile attributes and message content Iterable holds for your users in China are personal information — and once they sit on infrastructure in the United States or Ireland, you have made a cross-border transfer (数据出境) out of the mainland. China’s Personal Information Protection Law puts the duty on the handler — you, not Iterable: Articles 38–40 require notice to the individual, a separate consent distinct from any agreement to receive your messages, and one transfer mechanism — a CAC security assessment, the CAC standard contract, or certification. Delivery receipts, opens, clicks and the engagement profile then persist offshore.

Two further duties ride on top. Promotional or marketing push carries a lawful-basis-and-consent obligation of its own (PIPL Articles 13 and 23), and the recipient’s opt-out must be honored. And because Iterable’s segments and journeys decide who receives which message from a behavioral profile, PIPL Article 24 — automated decision-making — applies: the decision must be transparent and fair, and the individual must be able to refuse decisions made by profiling of their personal characteristics.

Then the distinctive second door: delivery itself. Iterable’s Android push runs on Firebase Cloud Messaging, and FCM depends on Google Play Services, which is absent from most mainland-China Android devices — so FCM-only push is unreliable or undeliverable to those users, and Iterable’s own documentation describes no Chinese manufacturer push channel. Reaching Chinese Android users lawfully and reliably means routing through each device manufacturer’s own push service — Xiaomi, Huawei (HMS), OPPO, vivo, Honor — each a licensed in-country channel requiring a registered app and credentials, and increasingly app and content filing. This is the push counterpart of SMS signature-and-template licensing: a lawful in-country delivery requirement, not a reachability setting. Apple’s APNs does operate in China through Apple’s local entity, so iOS push is deliverable — but the token and content still cross the border, so the transfer analysis above still applies.

Residency can bite last. Above certain volumes, or where the data is “important data,” the transfer may require China’s data-export security assessment (数据出境安全评估) before anything leaves. And if your organization is a critical information infrastructure operator, the Cybersecurity Law’s Article 39 (formerly Article 37 — the 2025 Cybersecurity Law amendment, in force January 1, 2026, renumbered the data-localization article from 37 to 39, substance unchanged) requires personal information collected and generated in China to be stored in China — an in-country duty no US or EU region can meet.

Reaching the SDK isn’t the question — lawful in-country delivery is

None of this is a latency problem, so none of it is solved by making the offshore endpoint faster or more reachable. The exposure is that the recipient data and the delivery both sit offshore; the lawful answer is to bring both onto an in-country path.

Concretely, that means routing your Chinese Android push through the licensed in-country manufacturer channels instead of relying on an FCM path that cannot reach those devices; keeping the recipient data — tokens, contact details, profiles and events — on an in-country footing, minimized and pseudonymized so the least identifying data crosses the border; holding the Article 13/23 consent for anything promotional and honoring the Article 24 right to a non-profiled option; or, where residency or volume demands it, routing China traffic through a licensed in-country engagement alternative. This is a governed, in-country delivery path — never a tunnel that ships the same data offshore under another name.

Which of these duties apply to your program, and in what combination, depends on what recipient data and content you send, whether you profile to target, your data volumes, and who your users are — worth settling the specifics with counsel before you build. This page is a risk map, not a verdict.

The lawful path — map, localize, deliver

You keep running Iterable. 21YunBox adds the piece its offshore service cannot, as a compliant overlay in front of the stack you already run — no rebuild, no migration.

  • Map — our China team inventories what recipient identifiers, profile attributes and message content your Iterable programs send offshore, what personal information each carries, where it is processed and stored, how your Chinese Android push is delivered today (an FCM path that silently fails versus licensed manufacturer channels), the consent basis you rely on, and any Article 24 profiling.
  • Localize — we keep China-user delivery and recipient data on an in-country, licensed path: Chinese Android push routed through the licensed in-country manufacturer channels, APNs tokens and content governed, the data minimized and pseudonymized, the marketing consent held and the Article 24 opt-out honored — or China traffic routed through a licensed in-country engagement alternative where residency demands it. 21YunBox never uses or suggests circumvention of any kind.
  • Deliver — the app or site that triggers the notifications carries an ICP filing duty and needs compliant, in-country delivery — the 21YunBox Optimizer, placed in front of your existing origin, so a mainland audience is served lawfully without moving off your global stack.

The result is Iterable that runs legally and compliantly for your users in China, with delivery and the recipient data behind it on an in-country footing. Where any telecom or push-licensing question touches the arrangement, that sits with a licensed in-country operator and your counsel — 21YunBox is advisory there.

Get a compliance assessment →


Related reading:

Frequently Asked Questions

Does Iterable store Chinese users' data in China?
No. By Iterable's own documentation it runs two data centers — a US data center and a European data center in Ireland — and most accounts sit in the US; there is no mainland-China region. So the device tokens, profiles, message content and engagement events for your China users are processed and stored offshore, which is what China's cross-border rules weigh.
Can Iterable deliver push notifications to Android phones in China?
Only through Firebase Cloud Messaging, which Iterable's setup guide names as its Android push transport. FCM relies on Google Play Services, absent from most mainland-China Android devices, and Iterable documents no Chinese manufacturer push channel (such as Huawei/HMS or Xiaomi). Reaching Chinese Android users reliably and lawfully means routing push through licensed in-country manufacturer channels — the push counterpart of SMS signature and template licensing — not making an offshore endpoint reachable. iOS APNs works in China, but the token and content still cross the border.
Can 21YunBox make our Iterable setup compliant for China?
Yes. Our China team maps what recipient data and content your Iterable programs send offshore and how your Android push is delivered today, keeps China-user delivery and recipient data on an in-country licensed path — manufacturer channels for Android, minimized and pseudonymized data, marketing consent and the Article 24 opt-out honored — and delivers your China-facing app in-country on ICP-filed infrastructure, in front of the stack you already run. 21YunBox never uses or suggests circumvention of any kind. Get in touch to work through your case.

ARTICLES RELATED TO ITERABLE

Make Your Site Work inside the Great Firewall of China

Enter your information, and our staff will assist you in getting a 21YunBox account for China.

Make Your Site Work Within the Great Firewall of China
Make Your Site Work Within the Great Firewall of China

By clicking 'Get Started', I also agree to 21YunBox's Terms of Service and Privacy Policy.