Does LiveChat Work in China? PIPL Cross-Border, Data Residency & Consent
LiveChat (by Text Inc.) stores your China customers' chat transcripts and visitor profiles on Google Cloud in the US and EU - never mainland China - so running it is a PIPL cross-border transfer, its embedded JavaScript widget ships visitor data offshore before consent, any AI auto-reply is an automated decision, and the support surface needs an ICP filing. A compliance-first look at the residency, consent and automated-decision exposure.
Does LiveChat work in China?
Loading the chat bubble was never the question - LiveChat (by Text Inc.) runs no mainland-China region, so your China customers' transcripts and visitor profiles sit on Google Cloud in the US and EU, its embedded JavaScript widget ships each visitor's IP and browsing to LiveChat before any consent, and its AI auto-answers customers - so the support surface needs an ICP filing and a lawful in-country path.
LiveChat holds chat transcripts, visitor profiles and the IP address and page-browsing its widget records before a chat even starts, all on Google Cloud in two regions - the EU and the USA - with no mainland-China option, which makes running it for China customers a PIPL cross-border transfer you perform as the handler (Articles 38-40). The widget's on-load data flow is also a PIPL Article 13/23 consent problem, and its AI auto-reply and chat categorization are automated decisions under Article 24. The lawful lever is to keep China conversations and PII in-country, gate and consent the widget, meet the Article 24 duties, and ICP-file the support surface - not to make the offshore widget reachable.
This is a risk map, not a verdict - settle the specifics with counsel. Our China team can map your exposure →
What LiveChat's own documentation says about China
| Fact | Primary source |
|---|---|
| LiveChat stores your chat data only in the EU or the US - there is no mainland-China region. LiveChat's own data-center page states its servers are "strategically located in two independent regions: one within the EEA/EU and the other in the USA," and Text's security page names the provider and cities: data "hosted on secure cloud infrastructure provided by Google Cloud" in the United States (Texas, Iowa) and the European Union (Frankfurt, Germany), with uploaded files on Amazon S3. None is inside mainland China, so your China customers' conversations are held offshore. | LiveChat - Data Center in Europe; Text (text.com) - Security FAQ, retrieved 2026-10-10 |
| The LiveChat widget records each visitor's IP address and browsing before a chat ever starts. Installing LiveChat's JavaScript snippet feeds its Traffic view, where, before anyone types, a visitor is identified by "an IP address" and LiveChat infers their country, state and city from it, listing "all visitors who are currently on your website" and the pages they are on. That visitor data is sent to LiveChat's offshore servers on page load, before any consent. Its AI also provides "instant answers to common questions automatically" and "response suggestions and chat categorization," with chat content shared with AI partners such as OpenAI. | LiveChat - Traffic section overview; How AI enhances customer support in LiveChat, retrieved 2026-10-10 |
| Holding your China customers' conversations offshore is a cross-border transfer you must justify under PIPL. Because transcripts, visitor profiles and IP addresses are personal information collected from people in China and stored in the US or EU, the Personal Information Protection Law treats the flow as a cross-border transfer: you, the handler, must give notice, obtain a separate consent, and clear one transfer mechanism - a CAC security assessment, the CAC standard contract, or certification (Articles 38-40). The widget sending visitor data on load raises a distinct Article 13/23 consent question, and its AI auto-reply is an automated decision under Article 24. | PIPL Articles 38-40 (cross-border transfer), 13/23 (consent) and 24 (automated decision-making) |
| For a CIIO or high-volume handler, that data cannot sit offshore at all - and the support surface still needs an ICP filing. Personal information collected in mainland China by a critical-information-infrastructure operator or a large-volume handler must be stored in the mainland under Cybersecurity Law Article 39 (formerly Article 37) - the 2025 Cybersecurity Law amendment, in force January 1, 2026, renumbered the data-localization article from 37 to 39, with the substance unchanged - a duty a US/EU-only service cannot meet. Separately, the public page or help center that hosts the widget carries an ICP filing duty. | Cybersecurity Law Article 39 (formerly Article 37); PIPL Article 40; State Council Order No. 292 & MIIT Order No. 33 (ICP) |
Sources verified by the 21YunBox compliance team on 2026-10-10.
If you run customer support for users in mainland China on LiveChat, the deciding question is not whether the chat widget appears — it is where your customers’ conversations and profiles live, whether the embedded widget ships visitor data offshore before anyone consents, whether its AI makes automated decisions about customers, and whether the support surface is ICP-filed. LiveChat, built by Text Inc. (Polish-origin), is a live-chat widget: third-party JavaScript you install on your site. It runs no mainland-China region — its data sits on Google Cloud in the United States (Texas, Iowa) and the European Union (Frankfurt), with uploaded files on Amazon S3. That posture raises four compliance prongs: cross-border transfer and residency of the conversation data; the embedded widget’s on-load data flow and its consent problem; automated decisions where its AI auto-answers or categorizes customers; and an ICP filing for the public support surface.
LiveChat in China at a glance
| What decides it | In LiveChat's own terms — and China's law |
|---|---|
| What it holds | Chat transcripts, visitor names, emails and profiles, and — through its Traffic view — each visitor's IP address, location and the pages they browse, captured before a chat even begins. That is personal information under PIPL, not anonymous metrics. |
| Where it runs | On Google Cloud in two regions only — the United States (Texas, Iowa) and the European Union (Frankfurt) — with uploaded files on Amazon S3. None is in mainland China, so running it for China customers is a PIPL cross-border transfer (Articles 38–40, 数据出境). |
| The embedded-widget door | LiveChat's JavaScript snippet records the visitor's IP, location and page activity and sends it to LiveChat's offshore servers on page load — before any chat or consent. That is both a cross-border transfer and a PIPL Article 13/23 consent problem; making the endpoint reachable does not cure it. |
| AI automated decisions | Where LiveChat's AI auto-answers common questions, suggests replies or categorizes a chat — and shares chat content with AI partners such as OpenAI — that is automated decision-making under PIPL Article 24: transparency, fairness and a route to human review. |
| Residency & reachability | For a CIIO or high-volume handler, personal information collected in China must be stored in the mainland (PIPL Article 40), which a US/EU-only service cannot meet. The widget loading is the easy half; the lever is to keep conversations and PII in-country, gate and consent the widget, meet the Article 24 duties, and ICP-file the surface. |
What you actually hold — conversations, visitor profiles, and a widget that phones home
A support conversation is built from exactly the data China’s law protects. On LiveChat you hold chat transcripts, the names and email addresses your visitors share, and the customer profiles your team builds to resolve a ticket. But the exposure starts earlier than the first message. LiveChat is a widget — JavaScript you embed on your pages — and its Traffic view shows your team a live list of everyone currently on your site. Before a visitor ever types, LiveChat identifies them by “an IP address” and infers their country, state and city from it, and lists “all visitors who are currently on your website” and the pages they are on. That is personal information, collected and sent the moment the widget loads.
All of that rides LiveChat’s offshore infrastructure. Its own pages place its data in “two independent regions: one within the EEA/EU and the other in the USA” — Google Cloud in the United States (Texas, Iowa) and the European Union (Frankfurt), with uploaded files on Amazon S3 — and no region inside mainland China; LiveChat is a managed service with no self-hostable engine you could stand up in-country. LiveChat also ships AI: it provides “instant answers to common questions automatically,” offers agents “response suggestions and chat categorization,” and shares chat content with AI partners such as OpenAI when a chat is transferred or summarized. Any model that answers, routes or scores a customer is a PIPL Article 24 automated-decision concern.
The doors: cross-border conversation data, widget consent, and automated decisions
Because your China customers’ transcripts, profiles and IP addresses are collected in the mainland and stored in the US or EU, PIPL treats the flow as a cross-border transfer. As the handler — with LiveChat the processor — you must give notice, obtain a separate consent distinct from agreeing to use the chat, and clear one transfer mechanism: a CAC security assessment, the CAC standard contract, or certification (PIPL Articles 38–40). See cross-border data transfers.
The embedded widget adds a door of its own. Because its JavaScript records the visitor’s IP, location and page activity and sends it offshore on load — before the visitor has agreed to anything — that collection needs its own lawful basis and consent under PIPL Articles 13 and 23, not an after-the-fact notice. And if your operating entity is critical information infrastructure, or handles personal information above the state threshold, the mainland-collected data must stay in the mainland — the data-localization duty in Cybersecurity Law Article 39 (formerly Article 37, renumbered by the 2025 Cybersecurity Law amendment in force January 1, 2026; the substance is unchanged) — which a service running only in Texas, Iowa and Frankfurt has no way to satisfy.
Where LiveChat’s AI auto-answers a customer, suggests the reply an agent sends, or categorizes and routes a chat, it is making an automated decision about a person. PIPL Article 24 attaches: the customer is owed transparency, a decision that is not unfair, and a route to human review — and the chat content shared with AI partners such as OpenAI is itself a further transfer to account for.
Loading the widget isn’t the question — a compliant in-country support path is
That the LiveChat widget paints and connects from a device in China tells you nothing about any of these doors. Reachability is not the axis; compliance risk is. A lawful setup has a definite shape: the China-customer conversations and profiles are kept on an in-country path — an in-country support deployment, with what is collected minimized and pseudonymized — the widget is gated and consented so it does not ship visitor data on load without a basis, the Article 24 duties are met for any AI, and the public support surface is ICP-filed. What it is not is a hidden route that carries the conversations offshore anyway while presenting them as local; keeping the data in-country means the data actually stays in-country.
This page is a risk map, not a verdict. Which prongs bind your specific setup — whether you are a CIIO or high-volume handler, which consents apply, how much you collect — turns on exactly what your support stack carries, so settle the specifics with counsel.
The lawful path — map, localize, deliver
There is a clean way to run LiveChat-powered support for customers in China, and it does not involve working around anything. Our China team does three things. We map what LiveChat carries — the transcripts, the visitor profiles, the IP and browsing data the widget records on load, and the chat content its AI processes — where each is processed and stored (Google Cloud in the US and EU, with no mainland-China option), whether its AI answers or scores your customers (Article 24), and the consent basis you need (Articles 13/23 and 38–40). We localize: keep China-customer conversations and PII on an in-country path — an in-country support deployment in place of any flow that cannot run compliantly — gate and consent the chat widget so it does not ship visitor data before there is a basis, minimize and pseudonymize what is collected, meet the Article 24 duties for any AI, and obtain the required consent. We deliver the China-facing support surface — the help center, chat page or widget host, a public service that carries an ICP filing duty — on compliant, in-country infrastructure, the 21YunBox Optimizer, in front of the stack you already run, with no rebuild. 21YunBox is a compliant overlay and partner, not a competitor to LiveChat. The result is customer support that runs legally and compliantly for your users in China. 21YunBox never uses or suggests circumvention of any kind.
Related reading:
- Cross-border data transfers under PIPL
- China’s Cybersecurity Law — data localization (Article 39, formerly Article 37)
- China’s Personal Information Protection Law (PIPL)
- How to get an ICP filing for China
