Does VTEX Work in China? PIPL Cross-Border, ICP Filing & Data Residency
VTEX is a hosted, multi-tenant SaaS commerce platform running on Amazon Web Services with no mainland-China region, so the customer PII, orders, and behavior your China store generates rest offshore — a PIPL cross-border transfer — while the public storefront needs an ICP filing and China payment runs through a licensed domestic path. A compliance-first look at the residency, ICP, and payment exposure.
Does VTEX work in China?
Your store's customer PII, orders, and behavior sit on VTEX's offshore AWS cloud with no mainland-China region, the storefront isn't ICP-filed, and China payment needs a licensed domestic path.
VTEX is a hosted, multi-tenant SaaS commerce platform; a China store's shopper profiles, orders, and clickstream rest in its US or EU regions, which makes running it for China customers a PIPL cross-border transfer (Articles 38–40). The public storefront carries an ICP-filing duty a foreign SaaS domain can't meet as-is, and accepting China wallets needs licensed domestic payment. The lawful lever is to keep store data in-country through a licensed in-country deployment (VTEX offers no self-host), ICP-file and deliver the storefront in-country, and route China payment through a licensed domestic path — not to make the offshore storefront reachable (21YunBox advisory on payment).
This is a risk map, not a ruling — settle the specifics with counsel. Our China team can map your exposure →
What VTEX's own documentation says about China
| Fact | Primary source |
|---|---|
| VTEX hosts your shoppers' PII on AWS, with no mainland-China region. Its data-residency documentation offers only two regions to hold Shopper Profile PII — us-east-1 in Virginia, USA and eu-west-1 in Ireland — so the customer data a China store generates rests offshore, not on the mainland. | VTEX Developer Docs — Data residency (developers.vtex.com), retrieved 2026-10-10 |
| VTEX is a hosted, multi-tenant SaaS platform — there is no self-hosted build. Its Profile System is "the VTEX module responsible for keeping Shopper Profile PII at rest," and region choice is a closed-beta add-on limited to offshore AWS regions, so you cannot place the store's customer data on mainland soil by self-hosting. | VTEX Developer Docs — Data residency (developers.vtex.com), retrieved 2026-10-10 |
| Running a China store on an offshore platform is a PIPL cross-border transfer. Sending your China customers' PII and orders abroad triggers PIPL Articles 38–40 — a clear notice, a separate consent (Articles 13 and 23), and an approved transfer mechanism, which for a high-volume handler can mean a CAC security assessment. | PIPL Articles 38–40, 13, 23 (China Personal Information Protection Law), retrieved 2026-10-10 |
| The storefront owes an ICP filing, and high-volume handlers face an in-country storage duty. A China-facing store is a public site that needs an ICP filing (备案), and a CII or high-volume handler must store data in-country under Cybersecurity Law Article 39 (formerly Article 37) — the 2025 amendment renumbered it from 37 effective January 1, 2026, substance unchanged. | China Cybersecurity Law Article 39 (formerly Article 37); ICP filing rules, retrieved 2026-10-10 |
Sources verified by the 21YunBox compliance team on 2026-10-10.
For a China-facing store, the question about VTEX is not whether the storefront renders or the catalog API answers — it is where your customers’ personal information, their orders, and their browsing behavior come to rest, whether the public storefront can be filed at all, and how a mainland shopper actually pays. VTEX is a hosted, multi-tenant digital-commerce platform (SaaS): you put your catalog, checkout, order records, and shopper profiles on VTEX’s cloud, which runs on Amazon Web Services and offers no mainland-China region. Three doors stand in front of a rollout: the customer PII and orders you generate in China sit offshore — a PIPL cross-border transfer; the storefront is a public internet service that owes an ICP filing; and accepting China’s mobile wallets runs through a licensed domestic payment path. For a high-volume or CII handler, an in-country storage duty applies as well. None of these turns on speed.
VTEX in China at a glance
| What decides it | In VTEX's own terms — and China's law |
|---|---|
| What it holds | VTEX is a hosted, multi-tenant digital-commerce platform (SaaS) for enterprise B2C and B2B stores. It holds your Shopper Profile PII — names, emails, phone numbers, and shipping addresses — together with order and transaction records, the product catalog, and session and browsing behavior. For a China store that data describes people in China, which makes it personal information under PIPL. |
| Where it runs | VTEX's cloud runs on Amazon Web Services, and its own data-residency documentation offers two regions to hold Shopper Profile PII — us-east-1 in Virginia and eu-west-1 in Ireland — with no mainland-China region. So the customer PII, orders, and behavior tied to your China shoppers come to rest offshore — a cross-border transfer under PIPL Articles 38–40 (数据出境): notice, a separate consent, and one transfer mechanism. |
| The ICP-filing door | A China-facing storefront is a public internet service, which carries an ICP filing (备案) duty. A foreign SaaS storefront served on VTEX's own domains and content-delivery network cannot be ICP-filed as it stands, so a compliant China store needs an in-country, ICP-filed delivery path for the public surface. |
| Payment and the storage duty | Accepting China's dominant mobile wallets runs through licensed domestic payment — a regulated non-bank-payment activity a foreign platform cannot provide directly — so a China checkout settles through a licensed domestic path (21YunBox is advisory here and holds no China payment license). In-country storage can also bite outright for a CII or high-volume handler under Cybersecurity Law Article 39 (formerly Article 37) — the 2025 Cybersecurity Law amendment, in force January 1, 2026, renumbered the data-localization article from 37 to 39, substance unchanged — and e-commerce handlers routinely cross the volume thresholds. |
| The lawful path | Reachability is not the axis. Map the PIPL cross-border, residency, ICP, and payment exposure; keep your China shoppers' PII and orders in-country through a licensed in-country commerce deployment; obtain the Article 13 and 23 consent; route China payment through a licensed domestic path; and deliver the storefront over ICP-filed, in-country infrastructure (the 21YunBox Optimizer), in front of the VTEX stack you already run. On payment 21YunBox is advisory. |
What you actually hold — customer PII, orders and behavior
A commerce platform is a concentration of exactly the data China regulates most closely. On VTEX, a China-facing store writes a Shopper Profile for each customer — name, email, phone number, and one or more shipping addresses — and ties it to the order history: what was bought, when, for how much, where it shipped, and the payment references behind it. Around that sit the catalog, the cart and session state, and the behavioral trail VTEX captures to power search, promotions, and personalization — the browsing and clickstream that, joined to a profile, describes an identifiable person. VTEX stores this on Amazon Web Services; its data-residency option (part of VTEX Shield, in closed beta) lets a store pick where its Profile System PII rests, but the only choices are us-east-1 in Virginia and eu-west-1 in Ireland — both offshore. VTEX is a proprietary SaaS platform, so there is no self-hosted build you could stand up on mainland soil; the records of your China customers are written offshore the moment they are created.
Three doors: cross-border customer data, an ICP-filed storefront, and licensed payment
The first door is cross-border data. Collected from and about people in China and written to a platform that runs offshore, your shoppers’ profiles, orders, and behavioral records are a cross-border transfer of personal information under PIPL Articles 38–40 (数据出境). The handler here is you — the business running the store, not only VTEX — and the law asks for a clear notice, a separate consent specific to the transfer (Articles 13 and 23), and one approved transfer mechanism, which for a high-volume handler can mean a CAC security assessment. E-commerce stores routinely process the personal information of large numbers of customers, so those volume thresholds are easy to cross.
The second door is the storefront itself. A China-facing store is a public internet service, and a public site served to users in the mainland carries an ICP filing (备案) duty. A foreign SaaS storefront on VTEX’s own domains and content-delivery network cannot be filed as it stands — the filing attaches to an in-country hosting arrangement and a domain that can be filed — so a compliant China store needs an in-country, ICP-filed delivery path for the public surface rather than the default offshore one.
The third door is payment, and it is regulated in its own right. Accepting the mobile wallets that dominate China checkout runs through licensed domestic payment — a non-bank payment activity that a foreign commerce platform cannot provide directly — so the China payment leg settles through a licensed domestic path, with VTEX’s own payment framework integrating to it rather than replacing it. China’s E-Commerce Law and consumer-protection rules add platform duties on top. On this leg 21YunBox is advisory: we hold no China payment license. And where you are a CII operator or a high-volume handler, in-country storage can be required outright under Cybersecurity Law Article 39 (formerly Article 37). None of these doors is opened by how quickly the page paints.
Reaching the storefront isn’t the question — a compliant in-country store is
It is tempting to read a China rollout as a connectivity task — point the storefront at the mainland and tune the delivery — but connectivity was never the deciding variable. A store can serve its pages quickly and still be unlawful: the profiles and orders would still rest in Virginia or Ireland, the public storefront would still be unfiled, and the checkout would still need a licensed domestic rail. The lawful shape is different in kind. Keep your China shoppers’ PII and orders on an in-country path — a licensed in-country commerce deployment, since VTEX offers no self-hosted build to place on mainland soil — minimize and pseudonymize what you collect, obtain the Article 13 and 23 consent, and settle the China payment leg on a licensed domestic path; then deliver the public storefront over an ICP-filed, in-country path, in front of the VTEX stack you already run. Localize means keeping the store data on an in-country path — never a tunnel that ships the same records offshore under another name. Because the specifics — whether you are a CII operator, which volume thresholds you cross, which transfer mechanism fits, and how the renumbered Cybersecurity Law Article 39 (formerly Article 37) bears on you — turn on facts only your team and your counsel hold, treat this page as a map of the exposure, not a ruling: settle the specifics with qualified counsel against what you actually run.
The lawful path — map, localize, deliver
Running a store for Chinese customers the lawful way has a shape, and it keeps VTEX where it already runs. 21YunBox is a compliant overlay, not a migration, and for an enterprise platform like VTEX we are a partner to it, not a competitor. We map your exposure first — reading the PIPL cross-border, consent, data-residency, ICP, and payment obligations against your entity, your order and customer volumes, and who your shoppers actually are, so you know exactly what counsel and a licensed local partner need to confirm. We localize what must stay on mainland soil — standing up consented, in-country processing and storage for the shopper profiles and orders that cannot lawfully sit offshore, and routing the China payment leg through a licensed domestic path. And we deliver the public storefront — product pages, checkout, account, and the forms behind them — over ICP-filed, in-country infrastructure (the 21YunBox Optimizer), in front of the VTEX stack you already run, with no rebuild and no second codebase. On the payment leg our role is advisory: 21YunBox holds no China payment license. The result is a commerce stack that runs legally and compliantly for your users in China. 21YunBox never uses or suggests circumvention of any kind.
Related reading:
- Cross-border data transfers under PIPL
- China’s Cybersecurity Law — data localization (Article 39, formerly Article 37)
- How to get an ICP filing for China
- China’s data export security assessment measures
Frequently Asked Questions
Can we get an ICP filing for our VTEX storefront?
Is it a problem that VTEX stores our customers' data outside China?
Can 21YunBox help make our VTEX store work in China?
ARTICLES RELATED TO VTEX
- China Implements Stricter Regulations on Internet Comment Services
- Does reCAPTCHA Work in China? Reachability, Google's Servers & PIPL
- China Cross-Border Data Transfer: What the Regulation Actually Says
- Tips for Businesses Looking to Sell Products in China: How to Start and Where to Start
- What is data privacy?
- Baidu Tieba - build brand reputation and improve search engine optimization in China!
- Why has my app been deleted from Chinese app stores, and how can I fix it?
- 15 Tips on How to Make a Website Load Faster
- Baidu vs Google
- Baidu Wangpan Guide
- How To Create A Little Red Book Brand Account And Store?
- How To Sell Products to China via WeChat?
- How to Publish My Mobile App in China: A Comprehensive Guide
- How to register a .cn domain?
- Trademark registration in China
