Why 21YunBox Pricing Contact Log in
Talk to an expert Test your site in China

Does Ninetailed Work in China? Personalization Profiles, PIPL & Data Residency

Ninetailed is now Contentful Personalization — the standalone Ninetailed app was retired in March 2026 — and its SDK and endpoints are callable from the mainland, so reachability is not the question. The decision is data residency and consent: Contentful documents hosting only in the United States and the European Union, with no mainland-China region, so the visitor profiles and behavioral events your China-facing site collects rest offshore, which makes their collection a cross-border transfer (数据出境) of personal information under PIPL, while profiling and automatically tailoring what each visitor sees is automated decision-making under PIPL Article 24 with its own consent duty, and for a critical information infrastructure operator the Cybersecurity Law's in-country storage duty under Article 39 (formerly Article 37) is one an offshore region cannot meet. A compliance-first look at where the profiles live, the consent and automated-decision duties, and the lawful in-country path.

Does Ninetailed work in China?

Yes — the personalization SDK and endpoints are callable from mainland China, so the honest answer is that reachability is not the problem. Note first that Ninetailed is now Contentful Personalization: the standalone Ninetailed app was retired in March 2026. What decides the China question is data residency and consent.

Contentful, which now runs Personalization, documents hosting only in the United States and the European Union — its Sub-processors page names AWS storage in “United States, Ireland, Germany,” with no mainland-China region. So the visitor profiles, behavioral events, and identifiers your site builds from people in China come to rest offshore, which makes their collection a cross-border transfer (数据出境) under PIPL — notice, a separate consent, and a transfer mechanism — and it may trigger China's data-export security assessment. Deciding what each visitor sees from their profile is automated decision-making under PIPL Article 24, which carries transparency, fairness, and opt-out duties, with consent owed before the profile is built. For a critical information infrastructure operator, the Cybersecurity Law's Article 39 (formerly Article 37) requires such data to be stored in China, which neither the US default nor the EU add-on can satisfy.

21YunBox maps your cross-border, residency, consent, and automated-decision exposure, localizes the China profile data onto a China-resident store (sending the personalization layer only what may lawfully leave), and delivers your China-facing site in-country on ICP-filed infrastructure — with no rebuild, and never any form of circumvention. Treat the specifics as a risk to confirm with counsel. Our China team can map your exposure with you →

What Ninetailed's own documentation says about China

FactPrimary source
Ninetailed is now Contentful Personalization — the standalone app was sunsetted in March 2026. Contentful's changelog states: “We have sunsetted the Ninetailed legacy app in March as part of our transition to a more unified personalization experience within Contentful,” that “All existing customers have been migrated to the fully integrated Contentful Personalization dashboard,” and that “You can no longer access or sign up through the legacy app.” The product still profiles visitors and tailors content; its data now lives in Contentful's infrastructure. Contentful changelog — “Ninetailed app has been sunsetted,” dated Mar 26, 2026, retrieved 2026-10-09
Hosting is documented only in the US and the EU — scoped to Personalization — with no mainland-China region. Contentful's Sub-processors and Affiliates page (effective October 8, 2026) lists AWS “Storage of Customer Content” in “United States, Ireland, Germany,” and scopes a further hosting sub-processor to “Hosting and storage of Customer Content; applicable only where a customer uses Contentful Personalization,” with another Personalization sub-processor in Belgium. Every location named is offshore; none is in mainland China, so the visitor profiles your China-facing site builds rest outside the country. Contentful — Sub-processors and Affiliates (effective October 8, 2026), retrieved 2026-10-09
Even the opt-in EU data-residency region is still offshore — and there is no China option. Contentful's EU data residency FAQ states: “The EU data residency region consists of AWS Dublin, Ireland, (eu-west-1) as the primary region and AWS Frankfurt, Germany, (eu-central-1) as the secondary region for automatically created backups.” The only residency choices are the US default and this EU add-on, so moving China profiles between them relocates the cross-border transfer rather than ending it. Contentful Help Center — EU data residency FAQ, retrieved 2026-10-09
China-collected profiles sent to an offshore account are a PIPL cross-border transfer, and profiling is automated decision-making. Moving personal information collected from users in mainland China to a US- or EU-hosted account triggers PIPL Articles 38–40 (notice, a separate consent, and one transfer mechanism — a CAC security assessment, the CAC standard contract, or certification), while deciding what each visitor sees from their profile is automated decision-making governed by PIPL Article 24 (transparency, fair results, and the right to opt out of profiling-based push). Personal Information Protection Law of the PRC, Articles 24 and 38–40 (cac.gov.cn), retrieved 2026-10-09

Sources verified by the 21YunBox compliance team on 2026-10-09.

For a product that personalizes what visitors in mainland China see, the first instinct with Ninetailed is to ask whether its SDK and endpoints even reach the mainland — and on the wire they do. So reachability is not where the China decision is settled. One fact is worth stating plainly first, though: Ninetailed is no longer a standalone product. Contentful acquired it, retired the legacy Ninetailed app in March 2026, and folded it into Contentful Personalization — ninetailed.io now resolves to Contentful’s own site. That does not change what the tool does: it builds a profile of each visitor from their behavior and serves them a tailored experience. And it does not change the China question, which is data residency and consent — where those visitor profiles come to rest, and whether you had a lawful basis to profile those users and move their data at all.

That is because the personalization data lives in Contentful’s infrastructure, and Contentful documents only two homes for it — the United States and the European Union. The moment the behavioral events, visitor profiles, and identifiers your site gathers from people in China land in a US or EU environment, you have made a cross-border transfer (数据出境) of personal information — and a different body of law decides whether that was allowed.

Contentful's Sub-processors and Affiliates page, effective October 8, 2026, listing AWS storage of Customer Content in the United States, Ireland and Germany, and a hosting sub-processor scoped to customers who use Contentful Personalization — naming only US and EU locations, with no mainland-China region
Contentful's own Sub-processors and Affiliates page — the home of the former Ninetailed, now Contentful Personalization — effective October 8, 2026, lists AWS “Storage of Customer Content” in “United States, Ireland, Germany,” and ties a further hosting sub-processor to “Hosting and storage of Customer Content; applicable only where a customer uses Contentful Personalization.” Every location it names is offshore; none is in mainland China. Source: Contentful — Sub-processors and Affiliates

Ninetailed in China at a glance

What decides it In the vendor's own terms — and China's law
What it is A composable customer-data and personalization layer — now Contentful Personalization, after the standalone Ninetailed app was retired in March 2026. It builds a profile of each visitor from behavioral, demographic, and technical signals, groups them into audiences, and serves a tailored experience — so it keeps a continuous, identifiable record of what your users do.
Is it reachable from the mainland? Yes. The personalization SDK and Experience API endpoints are callable from China, and it is not blocked at the border. Reachability is not the China question. (Cross-border calls from the mainland to an offshore endpoint can be inconsistent — an operational matter, below, not the decision.)
Where do the visitor profiles sit? Offshore. Contentful — which now runs Personalization — documents hosting only in the United States and the European Union: its Sub-processors page lists AWS storage of Customer Content in “United States, Ireland, Germany,” with further Personalization sub-processors in the EU and Belgium, and an opt-in EU data-residency region on AWS Dublin and Frankfurt. There is no mainland-China region.
Collecting China profiles into it The events, profiles, and identifiers are personal information. Holding them in a US or EU environment is a cross-border transfer (数据出境) under PIPL (Articles 38–40): notice, a separate consent, and one transfer mechanism. Profiling and automatically tailoring what each visitor sees is automated decision-making under PIPL Article 24, which adds transparency, fairness, and opt-out duties, and a data-export security assessment may apply above thresholds. For a critical information infrastructure operator, Cybersecurity Law Article 39 (formerly Article 37) sets an in-country storage duty an offshore region cannot meet.
The lawful path Keep the China profile and behavioral data in a China-resident store on a consented footing, send the personalization layer only what may lawfully leave, keep it for your other markets, and deliver the China-facing site that emits the events in-country on ICP-filed infrastructure. 21YunBox maps, localizes, and delivers; it never uses or suggests circumvention.

Availability: reachable — but where do the visitor profiles live?

Ninetailed’s China position is set in documentation, not by a load-time test. Its personalization SDK and Experience API are callable from the mainland, and after the fold-in those same capabilities run inside Contentful, which publishes exactly where the data rests: hosting in the United States and the European Union, and nothing in between. Put together, the picture is unambiguous — your account, and every visitor profile in it, sits in one of two offshore regions.

So “does the SDK reach it from Shanghai?” is the wrong test. It reaches. The real question is where your China-collected profiles sit and whether they were allowed to leave the country at all. For that reason this page publishes no first-party China latency or reachability figure for Ninetailed: speed is not the axis for a decision that turns on residency and consent. One operational note worth naming: cross-border calls from the mainland to an offshore endpoint can be inconsistent, and the temptation is to force them through a network workaround. 21YunBox neither uses nor suggests any such circumvention — it is both a compliance risk and beside the point. The productive question is how to keep the China data on a lawful footing.

Offshore visitor profiles are a cross-border transfer under PIPL

Here is the gate most teams miss. An account hosted in the US or EU region is, by definition, outside the mainland. The behavioral events, visitor profiles, and device or user identifiers it holds for your users in China are personal information, and loading them into an offshore environment is a cross-border transfer of personal information under China’s Personal Information Protection Law. PIPL puts the duty on the handler — you, the site owner, not the personalization vendor acting as processor: Articles 38–40 require notice, a separate consent distinct from any general agreement to use your site, and one transfer mechanism — a CAC security assessment, the CAC standard contract, or certification.

Above certain thresholds, or where the data counts as “important data,” that transfer may also require China’s data-export security assessment (数据出境安全评估) before anything leaves. And if your organization is a critical information infrastructure operator, the Cybersecurity Law’s Article 39 (formerly Article 37 — the data-localization provision was renumbered by the 2025 amendment that took effect on January 1, 2026, with its substance unchanged) requires that personal information generated in China be stored in China — an in-country storage duty that a US- or EU-hosted profile store simply cannot satisfy. None of this turns on how quickly an event is ingested; it turns on whether the data had a lawful basis to be there. Which of these bite your specific product is a risk to confirm with counsel against what you actually collect and store.

Personalization is automated decision-making — PIPL Article 24

Residency is only half of it. A personalization engine works by observing what identifiable people do — the pages they open, the campaigns they arrive from, the segments they fall into — assembling that into a profile, and then deciding automatically which experience each visitor is shown. Under PIPL, two separate duties attach before any of that is lawful in China. First, the tracking itself is processing of personal information and needs its own basis: informed consent obtained before the SDK begins building a profile, with a clear notice of what is gathered and why — and the cross-border transfer to an offshore account then needs a further, separate consent on top. Second, deciding what a visitor sees from their profile is automated decision-making under PIPL Article 24, which requires the decision-making to be transparent and its results fair, bars unreasonable differential treatment, and gives individuals the right to refuse decisions made solely by automated means and to opt out of profiling-based marketing or push.

The product gives you controls that help here — consent management and a privacy plugin in its SDK suite, and the ability to send only pseudonymous signals. Those can genuinely reduce exposure, but they do not discharge the consent, notice, and Article 24 duties, which sit with you as the handler. Whether your identifiers count as “personal information,” whether any field is sensitive, and what your consent and automated-decision notice must say are questions to settle with counsel.

Why turning on “EU data residency” isn’t the China fix

The obvious move is to flip on the EU data-residency option and keep the profiles in-region — but the only homes on offer are the US and the EU. Neither is in mainland China, so neither resolves a China residency duty; moving China profiles from the US default to the EU add-on merely relocates the cross-border transfer, it does not end it. Keeping China-collected profiles in-country means standing up a China-resident profile or event store for that data, on a consented footing, and sending the offshore personalization layer only what may lawfully leave. That split — what must stay, what may go — is the heart of the work, and it is a legal question before it is a technical one.

The lawful path — map, localize, deliver

There is a lawful way to run personalization for a China-facing site, and it has a shape. First, map: our China team works through your PIPL exposure on every front — the tracking, the profiling, the transfer, and the automated decision — pinning down which profile fields, events, and identifiers collected in China must stay in the country, what may lawfully leave, where a data-export security assessment or an Article 39 storage duty bites, and what your consent and Article 24 automated-decision notice have to cover. The legal conclusions are settled with counsel; we build the technical picture that feeds them.

Then localize: we stand up and integrate a China-resident profile or event store for the China visitor data, on a consented footing, so the personalization you depend on keeps working while that data stops leaving the country by default — and you keep the offshore personalization layer for the markets where it already serves you.

Then deliver: the China-facing site that emits those events and renders the tailored experience is itself a public service in the mainland, so it carries an ICP filing (备案) duty and needs compliant, in-country delivery. 21YunBox delivers it in-country — the 21YunBox Optimizer — in front of what you already run, with no rebuild and no re-platform. The result is China-facing personalization that runs legally and compliantly for your users in China. What we never do — and what no one lawfully can — is hand you a way around China’s data-export rules or around any network restriction: we localize what must stay and deliver in-country, and we never move personal information out of China by stealth.

Get a compliance assessment →


Related reading:

Frequently Asked Questions

Is Ninetailed still available, and does it work in China?
Ninetailed is now Contentful Personalization — the standalone Ninetailed app was sunsetted in March 2026 and existing customers were migrated into Contentful. Its personalization SDK and endpoints are callable from the mainland, so availability is not the obstacle. The real question for a China-facing site is data residency and consent: Contentful documents hosting only in the US and the EU, with no mainland-China region, so the visitor profiles you build from China users rest offshore. Cross-border calls to an offshore endpoint can be inconsistent, but that is an operational matter, not the decision — and the answer is never a network workaround. Treat the specifics as a risk to confirm with counsel.
Is sending China visitor profiles to Ninetailed / Contentful Personalization a cross-border transfer?
If your account is in the US or EU region — anywhere outside the mainland — then the events, profiles, and identifiers it holds for your China users are stored offshore, a cross-border transfer (数据出境) under PIPL. That means notice, a separate consent, and one transfer mechanism (a CAC security assessment, the CAC standard contract, or certification), and it may be subject to China's data-export security assessment. Deciding what each visitor sees from their profile is automated decision-making under PIPL Article 24, with transparency, fairness, and opt-out duties, and consent is owed before the profile is built. For a critical information infrastructure operator, the Cybersecurity Law's Article 39 (formerly Article 37) adds an in-country storage duty an offshore region cannot meet. Confirm your exact obligations with counsel.
Can 21YunBox help make our Ninetailed / Personalization setup work in China?
Yes. Our China team maps your exposure on every front — the tracking, the profiling, the cross-border transfer, and the Article 24 automated decision — then localizes the China profile and behavioral data onto a China-resident store on a consented footing, sending the personalization layer only what may lawfully leave, and delivers your China-facing site in-country on ICP-filed infrastructure, in front of what you already run. It is not a route around China's data-export rules, and it never uses or suggests circumvention. Get in touch to work through your specific case.

ARTICLES RELATED TO NINETAILED

CATEGORIES

Analytics

Make Your Site Work inside the Great Firewall of China

Enter your information, and our staff will assist you in getting a 21YunBox account for China.

Make Your Site Work Within the Great Firewall of China
Make Your Site Work Within the Great Firewall of China

By clicking 'Get Started', I also agree to 21YunBox's Terms of Service and Privacy Policy.