Does Stamped Work in China? Reviewer Data, Data Residency & PIPL Cross-Border Transfer
Stamped runs your reviews, ratings and loyalty program and, in its own Privacy Policy, says your information 'may be processed outside of the country where you live' — so the reviewer data your China shoppers submit is a cross-border transfer under PIPL, and the widget is fetched from offshore. A compliance-first look at the two doors.
Does Stamped work in China?
Whether you can use Stamped in China turns first on where the reviewer and loyalty data it gathers ends up — and whether its widget reaches your shoppers — not on raw speed. Stamped is a Shopify app for reviews, ratings, UGC and loyalty, so it collects personal information from your China shoppers — names, emails, review photos and the purchase history behind a rewards balance — and serves that content back from its own offshore infrastructure.
In its own Privacy Policy, Stamped says "Your information may be processed outside of the country where you live," lists the data it handles as "your name, email, address, telephone number, bank account details, payment information, support queries, community comments and so on," and gives its headquarters as Vancouver, Canada — naming no mainland-China location. So the data your China shoppers submit through Stamped is held offshore: a cross-border transfer of personal information PIPL governs, and because Stamped processes it on your behalf, the China duty sits with you, the merchant. Because the widget itself is fetched from offshore, a China-facing storefront can also load it late. The table below is Stamped's own wording and the rules it triggers.
This is a risk picture, not a verdict — what you owe turns on your data volumes, your role and how sensitive your review content is. Our China team can map your Stamped exposure with you →
What Stamped's own documentation says about China
| Fact | Primary source |
|---|---|
| In Stamped's own words: under International Data Transfers its Privacy Policy states that "Your information may be processed outside of the country where you live," and gives its headquarters as Vancouver, Canada. It names no mainland-China location, so the reviewer and loyalty data Stamped collects from your China shoppers — names, emails, review photos and purchase history — is processed and stored offshore. | Stamped — Privacy Policy, retrieved 2026-10-08 |
| In Stamped's own words, the personal data it handles includes "your name, email, address, telephone number, bank account details, payment information, support queries, community comments and so on." For a reviews, ratings and loyalty app that is exactly what your China shoppers hand over when they leave a review or join your rewards program — so what crosses the border is personal information, not anonymous counts. | Stamped — Privacy Policy, retrieved 2026-10-08 |
| Reviewer and loyalty data gathered in China and processed offshore is a cross-border transfer under PIPL. The handler — you, the merchant whose store collected it — must give notice, obtain separate consent, and satisfy one transfer mechanism: a CAC security assessment, the CAC standard contract, or certification. Review photos that show people are themselves personal information and can be sensitive, which tightens the consent and necessity tests rather than relaxing them. | PIPL Chapter III, Articles 38–43 |
| For a CIIO or large-volume handler, personal information collected in China must be stored inside the mainland (PIPL Article 40; Cybersecurity Law Article 39 (formerly Article 37)) — a residency duty an offshore app cannot meet. And the Shopify storefront the widget lives on is itself a public site: served to mainland visitors from inside China it turns on an ICP filing tied to a mainland host, which an offshore store does not provide. | PIPL Article 40; Cybersecurity Law Article 39 (formerly Article 37) |
Sources verified by the 21YunBox compliance team on 2026-10-08.
For a mainland-China storefront, the question that decides Stamped is not how good the review gallery or rewards widget looks — it is where the data behind them lives, and whether those widgets reach your shoppers at all. Stamped is a Shopify app for customer reviews, ratings, UGC and loyalty: it gathers personal information from your China shoppers — their names, emails, the photos they attach to a review, and the purchase history behind a rewards balance — and both stores and serves that content from its own infrastructure outside the mainland. Two consequences follow, and Stamped’s own Privacy Policy points to the first: the shopper data your China customers submit crosses the border, and the widget that renders it is fetched from offshore. The first is a compliance exposure; the second is a delivery one.
Stamped in China at a glance
| What decides it | What it means for a mainland-China storefront |
|---|---|
| Where it runs | Stamped runs the reviews, ratings and loyalty widgets and stores the data they collect on its own cloud infrastructure outside mainland China; its Privacy Policy names Vancouver, Canada as its headquarters and no mainland region. |
| What it collects | Reviewer and loyalty personal information — a shopper's name and email, the photos and text they submit as a review, and the purchase history behind a rewards balance. |
| Stamped's role | Stamped processes that shopper data on the merchant's behalf, so under PIPL the personal-information handler duty is the merchant's, not Stamped's. |
| Where that data goes | In Stamped's own words, your information “may be processed outside of the country where you live” — offshore, with no mainland-China location named: a cross-border transfer under PIPL. |
| Reaching shoppers | The widget's script and media are fetched from offshore, so on a China-facing storefront they can arrive late or render only in part. Reachability is the delivery half; where the data lives is the compliance half. |
The reviews and loyalty widgets are served from offshore
Stamped renders your reviews, star ratings and rewards panel by loading its script and media from its own hosts, which sit outside mainland China. An asset fetched across the border is a weak link on a China-facing page: it can arrive late, render only in part, or hold back the product page it sits on, because each request has to leave the country and come back. We publish no first-party China measurement for Stamped, so we put no number on it here and make no claim about any single visit — the structural point is simply that an offshore widget is delivery risk you carry on every China page view. That is the delivery half of the question. It is real, but it is not what decides whether you may use Stamped. That turns on where the data goes.
Your shoppers’ review and loyalty data leaves China — and the duty is yours
The content Stamped gathers is personal information: a shopper’s name and email, the photos and text they attach to a review, and the purchase history that sits behind a loyalty balance. In its own Privacy Policy Stamped lists the data it handles as “your name, email, address, telephone number, bank account details, payment information, support queries, community comments and so on,” and states that “your information may be processed outside of the country where you live.” Its headquarters are in Vancouver, Canada, and it names no mainland-China location. So personal data gathered from your China shoppers is held offshore, and — because Stamped processes it on your behalf as the merchant — the China obligations fall on you.
Under China’s Personal Information Protection Law, sending that data out of the country is a cross-border transfer: you must give notice, obtain separate consent, and clear one transfer mechanism — a CAC security assessment, the CAC standard contract, or certification. Review photos that show people are themselves personal information and can be sensitive, which raises the bar on consent and necessity rather than lowering it. And if you are a critical information infrastructure operator or a large-volume handler, personal information collected in China has to be stored in the mainland (PIPL Article 40; Cybersecurity Law Article 39 (formerly Article 37)) — a residency duty an offshore app cannot meet.
And the storefront itself has an ICP question
Separately from Stamped, the Shopify store its widgets live on is a public-facing site. Served to mainland visitors from inside China, that turns on an ICP filing (ICP 备案) bound to a hosting resource physically in the mainland — footing an offshore Shopify storefront does not have. Stamped does not change that one way or the other; it is worth flagging only because a China launch usually has to answer the storefront’s licensing question and the shopper-data question at the same time.
This is a risk map rather than a verdict: whether separate consent, a transfer mechanism, in-country storage, an ICP filing, or some mix applies depends on what you collect, how much of it, how sensitive it is, and who your shoppers are — settle it with counsel before a China launch.
Where 21YunBox fits — a compliant overlay, not a migration
You keep Stamped, and you keep your Shopify store. We add the piece an offshore app cannot: compliant, ICP-filed delivery from inside the mainland, set in front of your existing storefront so the reviews, ratings and loyalty widgets reach China shoppers from in-country — no rebuild, no second store, and no move off Stamped or Shopify. Our China team maps your PIPL cross-border and data-residency exposure against your entity, your data volumes and how sensitive your review content is, then stands up the in-country delivery and, where the law requires it, the in-country storage a lawful China presence needs.
Related reading:
