Does OneSignal Work in China? PIPL Cross-Border, Delivery & Data Residency
OneSignal is reachable from mainland China, so reachability is not the question. It runs no mainland-China region (its own docs place its primary data centers in the EU), so handing it your China users' device tokens, profiles, and message content to deliver is a PIPL cross-border transfer — and Android push must route through licensed in-country manufacturer channels, because FCM is unavailable in mainland China. A compliance-first look at OneSignal's data location, the cross-border and consent duties, and the lawful China path.
Does OneSignal work in China?
You hand OneSignal your China users' device push tokens, profiles, and message content to deliver to them — a cross-border transfer — and mainland Android push must route through licensed in-country manufacturer channels, because FCM is unavailable in mainland China.
OneSignal is a push and multichannel engagement platform: you upload device tokens (added, in its words, “by FCM or APNs”), user IDs, emails, phone numbers, tags and segments, plus the notification content, and it delivers and logs engagement from offshore infrastructure — its own docs place its primary data centers in the European Union, with no mainland-China region. Sending your China users' identifiers and content there is a PIPL cross-border transfer (Articles 38–40: notice, a separate consent, and one transfer mechanism); promotional push adds an Article 13/23 consent duty, and deciding who gets which message from a behavioral profile can touch Article 24. OneSignal has added Huawei's HMS channel, but FCM — which it relies on for other Android — depends on Google Play Services that mainland devices lack, and its docs do not show Xiaomi, OPPO, or vivo channels. The lawful lever is to keep delivery and recipient data in-country on a licensed path (manufacturer channels for Android, minimize, marketing consent), not to make the offshore SDK reachable.
Which duties apply, and in what combination, is a risk to settle with counsel. Our China team can map your exposure →
What OneSignal's own documentation says about China
| Fact | Primary source |
|---|---|
| OneSignal supports Huawei's HMS channel, because new Huawei devices can't use FCM. OneSignal's announcement states: “New Huawei devices will not support Google's Firebase Cloud Messaging (FCM) Channel, and HMS is required to send notifications to these users.” Its docs add that “Firebase/Google setup is not required for app builds released to the Huawei AppGallery,” and show no Xiaomi, OPPO, or vivo channels — so an FCM-only setup fails to reach most mainland Android. | OneSignal, “Announcing Huawei (HMS) Support” (onesignal.com), retrieved 2026-10-10 |
| OneSignal has no mainland-China region — its primary data centers are in the EU — and it retains your data. OneSignal's Data & Security documentation states “Our primary data centers are located in the European Union,” that it is “certified under the EU–U.S. Data Privacy Framework,” and that message data is “retained for 30 days before deletion”; user data is kept until deleted, with inactive user data purged after 18 months. None of it is in China. | OneSignal Documentation, “Data and Security FAQs” (documentation.onesignal.com), retrieved 2026-10-10 |
| Delivering your China users' tokens, profiles, and content offshore is a PIPL cross-border transfer. Device tokens, recipient profiles, message content, and engagement events for users in mainland China are personal information; processing or storing them outside China triggers PIPL Articles 38–40 — notice, a separate consent, and one transfer mechanism (a CAC security assessment, the CAC standard contract, or certification) — and promotional messaging adds the Article 13/23 consent and opt-out duty. | Personal Information Protection Law of the PRC, Articles 38–40 (cac.gov.cn), retrieved 2026-10-10 |
| A CIIO or high-volume handler also owes an in-country storage duty. For a critical information infrastructure operator, the Cybersecurity Law's Article 39 (formerly Article 37 — the 2025 amendment, in force January 1, 2026, renumbered it, substance unchanged) requires personal information collected in China to be stored in China; larger or sensitive transfers can add a data-export security assessment before anything leaves. | Cybersecurity Law of the PRC, Article 39 (formerly Article 37); PIPL cross-border provisions, retrieved 2026-10-10 |
Sources verified by the 21YunBox compliance team on 2026-10-10.
For a product that sends push notifications, in-app messages, email, or SMS to users in mainland China, the first question about OneSignal is usually whether its SDK and API can be reached. They can — this is not a service China blocks outright. So reachability is not where the China decision is made. It turns on what happens the moment you hand OneSignal your China users’ device push tokens, recipient profiles, and message content to deliver on your behalf. OneSignal is a customer-engagement and push-delivery platform: you upload device tokens, user IDs, emails, phone numbers, tags and segments, plus the notification body, and it delivers across channels and logs engagement from its own offshore infrastructure — its Data & Security documentation places its primary data centers in the European Union, and there is no mainland-China region. Two legs decide whether that is lawful: the cross-border transfer of your recipients’ personal information and content, and a China-specific delivery door — Android push cannot ride Google’s Firebase Cloud Messaging in the mainland, so it must route through licensed in-country manufacturer channels. Marketing-consent duties, Article 24 profiling where OneSignal decides who gets which message, and in-country storage for a critical information infrastructure operator sit on top.
OneSignal in China at a glance
| What decides it | In OneSignal's own terms — and China's law |
|---|---|
| What you hand it | OneSignal is a push and multichannel engagement platform (mobile and web push, in-app, email, SMS). To deliver, you hand it the recipient's device push token (added, in OneSignal's words, “by FCM or APNs”), user ID, email or phone number, tags and segments, and the notification content — plus whatever the body reveals, such as a name, an order, or a one-time passcode. For a recipient in the mainland, all of it is personal information. |
| Where it processes and stores it | Offshore. OneSignal's Data & Security documentation states its primary data centers are in the European Union, and it is certified under the EU–U.S. Data Privacy Framework for EU↔US transfers. There is no mainland-China region. It retains message data for 30 days and keeps user data until it is deleted, with inactive user data purged after 18 months. Sending your China users' identifiers and content there is a cross-border transfer (数据出境) under PIPL (Articles 38–40): notice, a separate consent, and one transfer mechanism. |
| How Android push is delivered | FCM relies on Google Play Services, which is unavailable in mainland China, so FCM push does not reliably reach mainland Android. Reaching those users lawfully means routing through each device maker's licensed in-country channel. OneSignal has added support for Huawei's HMS channel; its own docs do not show Xiaomi, OPPO, or vivo channels. Apple's APNs works in China, but the token and content still cross the border. |
| Consent, profiling, and residency | Promotional push or messaging needs a lawful basis and consent under PIPL Articles 13 and 23 and must honor opt-out. Where OneSignal's segments or Journeys decide who gets which message from a behavioral profile, that touches Article 24 (automated decision-making). For a critical information infrastructure operator or high-volume handler, the Cybersecurity Law's Article 39 (formerly Article 37) adds an in-country storage duty an offshore region cannot meet. |
| The lawful path | Reachability is not the axis. Keep China-user delivery and recipient data in-country, route Chinese Android push through licensed in-country manufacturer channels, minimize and pseudonymize what still leaves, obtain the Article 13/23 consent for anything promotional, and deliver the China-facing app in-country on ICP-filed infrastructure. 21YunBox maps, localizes, and delivers — advisory on any telecom or licensing question, which sits with a licensed local operator and your counsel. |
What you actually send — recipient identifiers, profiles and content
A push and engagement platform is not a passive pipe. To deliver a password-reset push, an order update, or a promotion to someone in Shanghai, you pass OneSignal that person’s device push token — which, in OneSignal’s own words, is a token “added to the device by FCM or APNs” — along with a user ID, often an email address or phone number if you also send email or SMS, the tags and segments you use to target them, and the full content of the message. Much of that is identifiable, and the body frequently carries a name, an order number, or a verification code tied to a real account.
OneSignal processes and delivers that from its own infrastructure. Its Data & Security documentation places its primary data centers in the European Union and names no mainland-China region; it is certified under the EU–U.S. Data Privacy Framework, which governs EU-to-US transfers — so the data moves between offshore locations, none of them in China. It also keeps the data: OneSignal documents that message data is retained for 30 days before deletion, while user data is kept until it is deleted, with inactive user data purged after 18 months. As an engagement platform, it does more than relay — it builds a persistent profile of each subscriber (tags, segments, country, language, last-active, engagement events) to decide targeting and personalization. The recipient tokens, the profiles, the content, and the delivery, open, and click events your China-facing messaging generates live on that offshore infrastructure for as long as OneSignal holds them. That retained, offshore personal information is what China’s law weighs — not how fast the API answers.
It’s a cross-border transfer — and Android delivery has its own door — under PIPL
Here is the gate most teams miss. The device tokens, recipient profiles, message content, and engagement events a OneSignal account holds for your users in China are personal information — and once they sit on infrastructure outside the mainland, you have made a cross-border transfer (数据出境) of that data out of China. The Personal Information Protection Law puts the duty on the handler — you, who triggers the messaging, not the vendor: Articles 38–40 require notice to the individual, a separate consent distinct from their agreement to receive your messages, and one transfer mechanism — a CAC security assessment, the CAC standard contract, or certification. Where the content is promotional rather than strictly transactional, Articles 13 and 23 add a lawful-basis-and-consent duty, and opt-out must be honored. And because OneSignal’s segments and Journeys can decide who receives which message from a behavioral profile, Article 24 (automated decision-making) can apply, with its own transparency and opt-out expectations.
Android delivery is a second, China-specific door — and it is a lawful in-country routing requirement, not an obstacle to work around. Firebase Cloud Messaging depends on Google Play Services, which is unavailable on mainland Android devices, so FCM push is unreliable or undeliverable to most mainland users, and Google operates no mainland-China region. Reaching those users means routing through each manufacturer’s own licensed in-country push channel (Huawei’s HMS, and the Xiaomi / OPPO / vivo / Honor channels), each requiring a registered app and credentials with that vendor. OneSignal has added Huawei HMS support, which covers Huawei handsets; its documentation does not show the other mainland OEM channels, so an FCM-only configuration silently fails to reach most Chinese Android users. Apple’s APNs does work in China, but a push through it still carries the token and content across the border.
Residency can bite on top of consent. Above certain volumes, or where the data is “important data,” the transfer may require China’s data-export security assessment (数据出境安全评估) before anything leaves. And if your organization is a critical information infrastructure operator, the Cybersecurity Law’s Article 39 (formerly Article 37 — the 2025 Cybersecurity Law amendment, in force since January 1, 2026, renumbered the data-localization article from 37 to 39, with its substance unchanged) requires personal information collected and generated in China to be stored in China. That is an in-country storage duty an offshore OneSignal account cannot satisfy. None of this turns on how quickly a notification arrives; it turns on whether your recipients’ data had a lawful basis to leave the country, and whether it had to stay.
Reaching the SDK isn’t the question — lawful in-country delivery is
So the decision is not whether the OneSignal SDK can be reached from the mainland, and the lawful answer is not to make an offshore endpoint more reachable. It is to keep the China leg in-country: route Chinese Android push through the licensed in-country manufacturer channels, keep the recipient tokens, profiles, and message content your China users generate on an in-country path, minimize and pseudonymize what still crosses the border, obtain the Article 13/23 consent for anything promotional, and honor any Article 24 right to a non-profiled option. This is a governed, in-country delivery path — never a tunnel that ships the data offshore anyway. Which of these duties apply to your specific program, and in what combination, is a risk to settle with counsel against what you actually send, store, and retain — this page is a risk map, not a verdict.
The lawful path — map, localize, deliver
There is a lawful way to run OneSignal for a China-facing product, and it has a shape. First, map: our China team inventories which recipient identifiers (device tokens, user IDs, email, phone), profile attributes, and message content flow to OneSignal, what personal information they carry, where OneSignal processes and stores them and what it retains (message data 30 days, user data until deletion), how your Chinese Android push is actually delivered today (FCM that silently fails versus licensed manufacturer channels), the consent basis for anything promotional, and any Article 24 profiling. Settle the legal conclusions with counsel; we frame the technical picture that feeds them.
Then localize: keep China-user delivery and recipient data in-country — route Chinese Android push through the licensed in-country manufacturer channels (and keep APNs tokens and content governed), run the China leg of your push and messaging through an in-country path, minimize and pseudonymize the recipient data that still leaves, and hold the Article 13/23 consent and any Article 24 opt-out — while you keep OneSignal for the markets where it already serves you, or route China traffic through a licensed in-country engagement alternative. Localize means keeping the delivery and the recipient data on an in-country, licensed path.
Then deliver: the China-facing app or site that triggers those notifications — the sign-up, the receipt, the order update — is itself a public service in the mainland, so it carries an ICP filing (备案) duty and needs compliant, in-country delivery. 21YunBox delivers it in-country — the 21YunBox Optimizer — in front of the stack you already run, with no rebuild and no re-platform. The result is a China-facing messaging program that runs legally and compliantly for your users in China. 21YunBox never uses or suggests circumvention of any kind. What we do is localize the China leg onto a lawful, in-country licensed path and deliver in-country — we never route your recipients’ personal information out of China by stealth, and we are a compliant overlay and partner to the services you already use, not a competitor to them.
Related reading:
- Cross-border data transfers under PIPL
- China’s Cybersecurity Law (data localization, Article 39)
- China’s data-export security assessment
- How to get an ICP filing for China
