Why 21YunBox Pricing Contact Log in
Talk to an expert Test your site in China

Does Tipalti Work in China? Supplier Data, PIPL & the Payment-License Door

Tipalti is reachable from mainland China, but reachability was never the question. It names the United States, Israel, the UK and Germany as its data locations — the US primary, with no mainland-China region — so the supplier bank details, tax IDs and KYC files your China entity feeds in come to rest offshore: a PIPL cross-border transfer of sensitive financial data. A compliance-first look at the residency door, the non-bank payment-license door, and the lawful in-country path.

Does Tipalti work in China?

Tipalti is reachable from mainland China, but that was never the question — it stores its data in the United States, Israel, the United Kingdom and Germany (the US primary), with no mainland-China region, so the supplier and payee records your China entity feeds in come to rest offshore.

Tipalti is the system of record for who you pay: it holds “bank account number, IBAN, SWIFT code,” “Social Security Numbers or EU Tax Identification Number” and KYC identity documents — financial-account numbers and ID documents are sensitive personal information under PIPL Article 28. Feeding a mainland supplier's or contractor's details into an offshore-hosted platform is a cross-border transfer under PIPL (Articles 38–40: notice, a separate consent, a transfer mechanism), with an in-country storage duty for some handlers under the Cybersecurity Law Article 39 (formerly Article 37). A second door sits on top: paying a supplier in the mainland moves money into China, a licensed activity under State Council Order No. 768 that runs on cross-border rails and licensed onshore partners — not a China payment license Tipalti holds.

None of this makes Tipalti “blocked” — it maps where the real exposure sits. 21YunBox is a compliant overlay, not a payment institution: we map your residency and payment-license exposure, keep the China-resident records in-country, and deliver any China-facing surface on ICP-filed infrastructure. Treat the specifics as a risk to settle with counsel. Our China team can map your exposure →

What Tipalti's own documentation says about China

FactPrimary source
Tipalti stores customer data offshore, with the United States as its primary location. Its privacy policy states Tipalti and its service providers “manage, store and process personal data in the United States, Israel, the United Kingdom, Germany,” and that “The primary storage location for Tipalti Customer data is the United States.” Mainland China is not among the named locations, and for GDPR data Tipalti relies on “the Standard Contractual Clauses approved by the European Commission for transfers to the United States.” Tipalti Privacy Policy, section 3 “Data Location” (tipalti.com/legal/privacy-policy), retrieved 2026-10-10
Tipalti holds supplier bank-account and tax-identity data plus KYC documents. Its privacy policy lists payee “bank account number, IBAN, SWIFT code,” “VAT ID, Social Security Numbers or EU Tax Identification Number,” and supplemental KYC documentation such as “a copy of … government-issued identification card, personal bank statements.” Under PIPL Article 28, financial-account information and identity documents are sensitive personal information. Tipalti Privacy Policy, section 1 “Information We Collect” (tipalti.com/legal/privacy-policy), retrieved 2026-10-10
Sending a China payee's data offshore is a PIPL cross-border transfer of sensitive data. PIPL Articles 38–40 require a handler to give notice, obtain a separate consent, and use one transfer mechanism — a CAC security assessment, the CAC standard contract, or certification — before personal information leaves China; and for critical information infrastructure operators and handlers above the state volume threshold, personal information collected in China must be stored in China (Article 40). Financial-account data is sensitive personal information (Article 28), which carries a higher bar. Personal Information Protection Law of the PRC, Arts. 28 & 38–40, retrieved 2026-10-10
Paying suppliers in China touches a licensed activity, and payment data carries a residency duty. Under State Council Order No. 768 (Regulations on the Supervision and Administration of Non-Bank Payment Institutions, in force May 1, 2024), providing payment services for domestic transactions requires an onshore licensed path, and transaction processing, settlement and data storage for domestic transactions must be completed within China (Article 19). The Cybersecurity Law sets the same in-country storage duty for critical information infrastructure at Article 39 (formerly Article 37, renumbered by the 2025 amendment in force January 1, 2026). State Council Order No. 768, Art. 19; PRC Cybersecurity Law Art. 39 (formerly Art. 37), retrieved 2026-10-10

Sources verified by the 21YunBox compliance team on 2026-10-10.

For an accounts-payable and global mass-payments platform serving a China entity, the first question about Tipalti is not whether its dashboard loads from Shanghai. It does — delivery is not where this is decided. Tipalti is the system of record for who a company pays and how: vendor and supplier master data, bank-account numbers with IBAN and SWIFT codes, taxpayer identity (W-8 and W-9 forms, VAT and tax identification numbers), KYC identity documents, and the payment history tied to each payee. Almost all of it is personal information, and the financial-account and identity-document parts are sensitive personal information under Chinese law. Tipalti states that it stores and processes that data in the United States, Israel, the United Kingdom and Germany — the United States its primary location — with no mainland-China region among them. So the real axis is two doors: where those records are allowed to come to rest, and the fact that moving money into China is itself a licensed activity. Neither is measured in milliseconds.

Tipalti's Privacy Policy, section 3 'Data Location', stating that Tipalti and its service providers manage, store and process personal data in the United States, Israel, the United Kingdom and Germany, and that the primary storage location for Tipalti Customer data is the United States — mainland China not among the named locations
Tipalti's own Privacy Policy states: “The primary storage location for Tipalti Customer data is the United States.” Its named storage and processing locations are the United States, Israel, the United Kingdom and Germany — mainland China is not among them — so the supplier bank details, tax IDs and KYC files a China entity feeds in come to rest offshore, which is where the China decision actually turns. Source: tipalti.com — Privacy Policy

Tipalti in China at a glance

What decides it In Tipalti's own terms — and China's law
Where the records live Offshore. Tipalti's privacy policy says it and its service providers “manage, store and process personal data in the United States, Israel, the United Kingdom, Germany,” and that “The primary storage location for Tipalti Customer data is the United States.” There is no mainland-China region. For GDPR data it relies on “the Standard Contractual Clauses approved by the European Commission for transfers to the United States” — a cross-border posture by design.
What it holds, and why it's sensitive Vendor and payee master data. Tipalti lists “bank account number, IBAN, SWIFT code,” “VAT ID, Social Security Numbers or EU Tax Identification Number,” and supplemental KYC documentation such as “a copy of … government-issued identification card, personal bank statements.” Financial-account numbers and identity documents are sensitive personal information under PIPL Article 28, which carries a higher bar.
Your China payees' data crosses the border A mainland supplier's or contractor's bank details, tax identity and ID documents are personal information about a real person. Feeding them into an offshore-hosted platform is a cross-border transfer under PIPL (Articles 38–40): notice, a separate consent distinct from any payment agreement, and one transfer mechanism (a CAC security assessment, the CAC standard contract, or certification).
The in-country storage duty For a critical information infrastructure operator, or a handler above the state volume threshold, personal information collected in China must stay in China (PIPL Article 40; Cybersecurity Law Article 39 (formerly Article 37); and for payment data, Order No. 768). An offshore store in the US or the EU cannot satisfy an in-country storage duty, however the account is configured.
The second door, and why reachability is not the axis Paying a supplier in the mainland moves money into China — a licensed activity under State Council Order No. 768, run on cross-border rails and licensed onshore partners, not on a China payment license Tipalti holds. Any China-facing surface (a supplier portal or intake form) is a mainland internet service needing an ICP filing. The dashboard rendering is never the test.

No mainland region, so the supplier and payee records leave the country

Start with where the data rests, because that is where the decision actually turns. Tipalti’s privacy policy is explicit: it and its service providers “manage, store and process personal data in the United States, Israel, the United Kingdom, Germany, and other locations as reasonably necessary,” and “The primary storage location for Tipalti Customer data is the United States.” None of the named locations is mainland China. That is not a criticism of Tipalti’s security — it holds SOC attestations and encrypts data at rest — it is simply the fact that matters for China: the records come to rest abroad.

So the moment your China entity onboards a mainland supplier and Tipalti ingests that payee’s bank-account number, tax identity and KYC documents, personal information about a person in China has moved to infrastructure outside the country. Under China’s Personal Information Protection Law that is a cross-border transfer, and PIPL puts the duty on the handler — you, alongside the platform. Articles 38–40 require notice, a separate consent distinct from any onboarding or payment agreement, and one lawful transfer mechanism: a CAC security assessment, the CAC standard contract, or certification. Above the state thresholds, or where the data set counts as “important data,” that export can also require China’s data-export security assessment before anything leaves. And a residency duty can sit on top: for a critical information infrastructure operator or a high-volume handler, personal information collected in China must be stored in China (PIPL Article 40). The same logic runs through the Cybersecurity Law, whose in-country storage duty for critical information infrastructure now sits at Article 39 (formerly Article 37 — renumbered by the 2025 Cybersecurity Law amendment, in force January 1, 2026, with its substance unchanged). An offshore store cannot meet an in-country storage duty.

Supplier bank details, tax IDs and KYC files are sensitive personal information

It is worth being precise about what Tipalti holds, because it is exactly the category Chinese law treats most carefully. Tipalti’s own privacy policy enumerates payee “bank account number, IBAN, SWIFT code,” “VAT ID, Social Security Numbers or EU Tax Identification Number,” and, through its Know Your Customer process, “a copy of … government-issued identification card, personal bank statements or other documentation serving as proof of identity.” Add the invoice and payment history tied to each payee and you have a detailed financial profile of real people and the entities they represent.

Under PIPL Article 28, sensitive personal information is information that, if leaked or misused, could readily harm a person’s dignity or safety — and it names financial accounts specifically. Bank-account numbers, routing details and the identity documents behind a KYC file are squarely within it. Processing sensitive personal information requires a specific purpose, strict necessity, and — for the cross-border leg — the separate consent and transfer mechanism above, at a higher bar than for ordinary data. The practical upshot: the single most useful thing an AP platform does, hold the exact details needed to pay someone, is also the thing that makes its China-facing use a sensitive-data question rather than a convenience one.

The second door: paying into China is a licensed activity

Residency is only the first door. Because Tipalti moves money, a second door applies on top. Advertising cross-border payouts to “200+ countries and territories,” Tipalti can of course pay a supplier located in mainland China — but paying into China is not the same as holding a license to run payments there. China regulates non-bank payment as a licensed activity under the Regulations on the Supervision and Administration of Non-Bank Payment Institutions (State Council Order No. 768, in force May 1, 2024): providing payment services for domestic transactions requires an onshore licensed path, and transaction processing, settlement and data storage for domestic transactions must be completed within China (Article 19). A foreign provider does not run domestic mainland payment from offshore on its own account; the money reaches a Chinese payee’s bank through cross-border rails and licensed onshore banking partners.

That is a door we help you map, not one we walk through. 21YunBox is not a licensed payment institution and holds no China payment license, so the license and the rails sit with a licensed onshore provider and your counsel. What we add on this leg is advisory: helping you see where your particular flow — which entity pays, whether any part of it amounts to providing domestic payment services to mainland users, which rails and partners it touches — sits against Order No. 768, so you know exactly what counsel and a licensed partner need to confirm. None of this means Tipalti is “blocked” in China; it means the payment leg has its own compliance surface, separate from residency.

Narrowing what crosses doesn’t close the door

The reasonable instinct is to reduce the exposure inside the tool — redact fields, limit which legal entities feed into Tipalti, choose a particular processing region, or keep some records in a self-managed system. Those levers are worth pulling: they shrink what personal information crosses the border and can lower the volume that triggers the heavier thresholds. But they change the magnitude, not the nature. As long as a mainland payee’s bank details and identity documents are stored or processed in the United States or the EU, a cross-border transfer is still happening and the residency question is still open; trimming the payload does not convert an offshore store into an in-country one, and it does not file the China-facing surface. Reachability is likewise beside the point — a dashboard that opens instantly can still rest the records in the wrong place and still leave the payment leg unlicensed.

Which of these actually bite your operation turns on your entity, your data volumes, your role under Chinese law, and who your payees are — and this page is a map of that exposure, not a ruling on it. Treat each door as a risk to settle with qualified counsel against what you truly collect, store and pay, before your China flow depends on it.

The lawful path — map, localize, deliver

There is a lawful shape for running Tipalti behind a China operation, and it does not rip Tipalti out. First, map. Our China compliance team reads your PIPL, data-residency and payment-license obligations against your actual setup — which mainland supplier and payee records you collect, your data volumes, whether your systems or role bring you within the critical-information-infrastructure or high-volume thresholds, and what your notice-and-separate-consent flow must cover. The legal conclusions are settled with your counsel; we build the technical and architectural picture that feeds that decision.

Then localize. Where the China leg must stay in-country, we keep the China-resident vendor and payee records — the bank details, tax identity and KYC files tied to mainland people — on a consented, in-country footing, stored and processed inside the mainland where the law requires it, while Tipalti keeps doing what it does for the rest of your payables. The point is not to replace your AP platform but to put the China-resident records where they belong.

Then deliver. Any China-facing surface the flow needs — a supplier onboarding portal, an intake form, a status page your mainland payees load — is a public mainland internet service, so it needs an ICP filing and compliant in-country delivery. 21YunBox delivers it in-country — the 21YunBox Optimizer — in front of the stack you already run, with no rebuild and no re-platform. Two boundaries, stated plainly: on the payment-license leg our role is advisory — 21YunBox is not a licensed payment institution, so the license and the payment rails sit with a licensed onshore provider and your counsel, not with us; and on everything else we are a compliant overlay and a partner to Tipalti, not a competitor. What we never do — what no one lawfully can — is route you around China’s data-export rules or any network restriction: we map the path, localize the records that must stay, and deliver the surface in-country. 21YunBox never uses or suggests circumvention of any kind. The result is a China-facing operation that runs legally and compliantly for your users in China.

Get a compliance assessment →


Related reading:

Frequently Asked Questions

Tipalti's dashboard loads fine from China — so is it compliant to use for my China suppliers?
Reachability is not the compliance axis. Tipalti states its data is stored in the United States, Israel, the United Kingdom and Germany, with the US its primary location and no mainland-China region. So when your China entity feeds in a mainland supplier's bank-account number, tax identity and KYC documents, those records come to rest offshore — a cross-border transfer of sensitive personal information under PIPL (Articles 38–40, with Article 28 for sensitive data). Whether an in-country storage duty also applies depends on your role and volumes. The dashboard opening says nothing about any of that.
Does Tipalti hold a China payment license to pay suppliers in the mainland?
No. Tipalti advertises cross-border payouts to “200+ countries and territories,” and paying a China-based supplier moves money into the mainland on cross-border rails and licensed onshore banking partners — not on a China payment license Tipalti holds. Providing domestic payment services to mainland users is a licensed activity under State Council Order No. 768, so whether any part of your flow crosses into licensed territory is a question for counsel and a licensed onshore provider. 21YunBox is not a licensed payment institution; our role on the payment-license leg is advisory. This does not mean Tipalti is “blocked.”
What's the lawful way to run Tipalti for China payees, and what does 21YunBox do?
Keep Tipalti where it serves you for what may lawfully cross the border, and keep the China-resident vendor and payee records on a consented, in-country footing where the law requires it. 21YunBox maps your PIPL, data-residency and payment-license exposure, localizes the records that must stay in the mainland, and delivers any China-facing surface — a supplier portal or intake form — in-country on ICP-filed infrastructure, in front of the stack you already run. We are a compliant overlay, not a migration, and not a payment institution; the payment license and rails sit with a licensed onshore provider and your counsel. We never use or suggest circumvention of any kind. Settle the specifics with counsel.

ARTICLES RELATED TO TIPALTI

Make Your Site Work inside the Great Firewall of China

Enter your information, and our staff will assist you in getting a 21YunBox account for China.

Make Your Site Work Within the Great Firewall of China
Make Your Site Work Within the Great Firewall of China

By clicking 'Get Started', I also agree to 21YunBox's Terms of Service and Privacy Policy.