Skip to content
KStart free
AI InfrastructureDefenseQuantumAll studies →

GCT US Equity

GigaCloud Technology IncConsumer Discretionary · Retail-Catalog & Mail-Order Houses · CIK 1857816 · FY ends Dec 31
$49.65
-0.21 (-0.42%)
USD · as of 2026-08-21 · marketstack

GCT · 10-K · period ended 2023-12-31

← all GCT documents
filed 2024-03-27 · EDGAR original ↗

Our rendering of the filing — original pagination and typography are not reproduced, and tables are reduced to their short label cells (the figures live on FA). Nothing is summarized: every line below is the filing's own text.

blocks 358639 of 2,462628k characters rendered

Item 1A. Risk Factors

Our operations and financial results are subject to various risks and uncertainties, including those described below. We caution you that the following important factors, among others, could cause our actual results to differ materially from those expressed in forward-looking statements made by us or on our behalf in filings with the SEC, press releases, communications with investors and oral statements. Any or all of our forward-looking statements in this annual report on Form 10-K and in any other public statements we make can be affected by known or unknown risks and uncertainties. Many factors mentioned in the discussion below will be important in determining future results. Consequently, no forward-looking statement can be guaranteed. Actual future results may differ materially from those anticipated in forward-looking statements. We undertake no obligation to update any forward-looking statements, whether as a result of new information, future events or otherwise. We undertake no obligation to update any forward-looking statements, whether as a result of new information, future events or otherwise. You are advised, however, to consult any further disclosure we make in our reports filed with the SEC.

Risks Related to Our Business and Industry

Uncertainties in economic conditions and their impact on the ecommerce industry, particularly for large parcel merchandise, could adversely impact our operating results.

We generate a significant portion of our revenues by offering global end-to-end B2B ecommerce solutions for large parcel merchandise via our GigaCloud Marketplace and by selling our own inventory through the GigaCloud Marketplace, to and through off-platform ecommerce websites such as Rakuten in Japan, and Amazon, Walmart, Home Depot, Overstock and Wayfair in the U.S. and OTTO in Germany.. Our business and growth are therefore highly dependent on the viability and prospects of the ecommerce industry, particularly for the large parcel merchandise market.

Any uncertainties relating to the growth, profitability and regulatory regime of the ecommerce industry for large parcel merchandise in the U.S. and other jurisdictions in which we operate could have a significant impact on us. The

22

Table of Contents

development of the ecommerce industry is affected by a number of factors, most of which are beyond our control. These factors include:

•the consumption power and disposable income of ecommerce consumers, as well as changes in demographics and consumer tastes and preferences;

•the availability, reliability and security of ecommerce platforms;

•the selection, price and popularity of products offered on ecommerce platforms;

•the impact of the COVID-19 pandemic, or other pandemics or epidemics, to our business operations and the economy in the U.S. and elsewhere generally;

•the development of fulfillment, payment and other ancillary services associated with ecommerce; and

•changes in laws and regulations, as well as government policies, that govern the ecommerce industry in the U.S.

The ecommerce industry is highly sensitive to changes in macroeconomic conditions, and ecommerce spending tends to decline during recessionary periods. Many factors beyond our control, including inflation and deflation, fluctuations in currency exchange rates, volatility of stock and property markets, interest rates, tax rates and other government policies and changes in unemployment rates can adversely affect consumer confidence and spending behavior on ecommerce platforms, which could in turn materially and adversely affect our growth and profitability. In addition, unfavorable changes in politics, including military conflicts, political turmoil and social instability, may also adversely affect consumer confidence and spending, which could in turn negatively impact our growth and profitability.

Our historical growth rates and performance may not be sustainable or indicative of our future growth and financial results. We cannot guarantee that we will be able to maintain the growth rate we have experienced to date.

We have grown rapidly over the last few years. Our revenues increased from $414.2 million in 2021 to $490.1 million in 2022 and further increased to $703.8 million in 2023. GigaCloud Marketplace GMV increased from $414.2 million in 2021 to $518.2 million in 2022 and further to $794.4 million in 2023. However, our historical performance may not be indicative of our future growth or financial results. We cannot assure you that we will be able to grow at the same rate as we did in the past, or avoid any decline in the future. Our growth may slow or become negative, and revenues may decline for a number of possible reasons, some of which are beyond our control, including decreasing consumer spending, increasing competition, declining growth of our overall market or industry, the emergence of alternative business models and changes in rules, regulations, government policies or general economic conditions. In addition, our B2B ecommerce platform, GigaCloud Marketplace, from which we have generated 69.2%, 76.0% and 70.9% of our total revenues in 2021, 2022 and 2023, respectively, is a relatively new initiative and may not grow as quickly as we have anticipated. Our growth rate may also be slower than the previous years due to inflationary pressure and changes in the global economic conditions. It is difficult to evaluate our prospects, as we may not have sufficient experience in addressing the risks to which companies operating in rapidly evolving markets may be exposed. If our growth rate declines, our business, financial condition and results of operations may be materially and adversely affected.

We may not realize the expected benefits of our acquisitions of Noble House and Wondersign due to potential risk and uncertainties.

In October 2023, we completed the acquisition of Noble House which we are continuing to use, implement, and integrate with our existing business, and in November 2023, we also acquired all outstanding equity interest of Wondersign. Failure to successfully integrate our acquisitions in a timely manner may have a material adverse effect on our business, financial condition, results of operations and cash flows. The difficulties of combining acquired operations include, among other things:

•implementing integration process and management systems to ensure management philosophies, group-wide strategies and evaluation benchmarks can be effectively carried out;

•retaining new managerial and operational teams and customers and suppliers of acquired businesses;

•consolidating corporate technological and administrative functions;

•integrating internal control and other corporate governance matters;

•diverting management’s attention from other business concerns;

23

Table of Contents

•employee fatigue resulting from implementation efforts that could negatively impact our ability to hire or retain key personnel;

•costs to defend claims against Noble House that we do not owe, but could be required to pay in order to defend and preserve our rights;

•unexpected economic, political, or regulatory risks; or

•any other unforeseen costs, expenses, losses, disruptions, delays, or negative impacts.

We may not realize all of the anticipated benefits from our acquisitions, such as increased earnings, cost savings, and revenue enhancements, for various reasons, including difficulties integrating operations and personnel, higher and unexpected acquisition and operating costs, unknown liabilities, and fluctuations in markets. If benefits from our acquisitions do not meet the expectations of financial or industry analysts, we may also suffer a decline in the market price of our stock.

System interruptions that impair access to our GigaCloud Marketplace, or other performance failures in our technology infrastructure, could damage our reputation and results of operations.

The satisfactory performance, reliability and availability of our marketplace, software such as our artificial intelligence software, or AI software, data analytics tools, warehouse management system and other technology infrastructures are critical to our reputation and our ability to acquire and retain customers, as well as maintain adequate customer service levels.

For example, if one of our data centers fails or suffers an interruption or degradation of services, we could lose customer data and miss order fulfillment deadlines, which could harm our business. Our systems and operations, including our ability to fulfill customer orders through our logistics network, are also vulnerable to damage, breakdown, breach or interruption from inclement weather, fire, flood, power loss, telecommunications failure, terrorist attacks, labor disputes, employee error or malfeasance, theft or misuse, cyber-attacks, denial-of-service attacks, computer viruses, ransomware or other malware, data loss, acts of war, break-ins, earthquake and similar events. In the event of a data center failure, the failover to a back-up could take substantial time, during which time our sites could be completely shut down. Further, our back-up services may not effectively process spikes in demand, may process transactions more slowly and may not support all of our sites’ functionality.

We use complex AI software in our technology infrastructure, which we seek to continually update and improve. We may not always be successful in executing these upgrades and improvements, and the operation of our systems may be subject to failure. In particular, we may in the future experience slowdowns or interruptions in our marketplace or our warehouse management system when we are updating them, and new technologies or infrastructures may not be fully integrated with existing systems on a timely basis, or at all. Our revenues depend on the number of sellers and buyers who trade in our marketplace and the amount of GMV we can handle. Unavailability of our marketplace or our logistics algorithm would reduce the volume of GMV in our business operations.

We may experience periodic system interruptions from time to time. In addition, continued growth in our transaction volume, as well as surges in online traffic and orders associated with promotional activities or seasonal trends in our marketplace or on third-party ecommerce platforms, place additional demands on our technology infrastructure and could cause or exacerbate slowdowns or interruptions. Any substantial increase in the volume of traffic or the number of orders placed in our marketplace or the third-party ecommerce platforms may require us to further expand and upgrade our logistics network, precision logistics algorithm, warehouse management system and technology infrastructure. There can be no assurance that we will be able to accurately project the rate or timing of increases, if any, in the use of our marketplace, the third-party ecommerce platforms or expand and upgrade our systems and infrastructure to accommodate such increases on a timely basis. To remain competitive, we continue to enhance and improve the responsiveness, functionality and features of our marketplace, which is particularly challenging given the rapid rate at which new technologies, customer preferences and expectations and industry standards and practices are evolving in the ecommerce industry. Accordingly, we redesign and enhance various functions in our marketplace on a regular basis, and we may experience instability and performance issues as a result of these changes.

Any slowdown, interruption or performance failure of our marketplace and the underlying technology and logistics infrastructure could harm our business, reputation and our ability to acquire, retain and serve our customers, which could materially and adversely affect our results of operations.

24

Table of Contents

Our international operations are subject to a variety of legal, regulatory, political and economic risks.

We operate warehouses in five countries in the U.S., Japan, the U.K., Germany and Canada, with the U.S. being our largest market. Our international activities are significant to our revenues and profits, and we plan to further expand internationally. In certain international market segments, we have relatively little operating experience and may not benefit from any first-to-market advantages. It is costly to establish, develop and maintain international operations, and promote our brand internationally. Our international operations may not become profitable on a sustained basis.

In addition, our international sales and operations are subject to a number of risks, including:

•local economic, inflation and political conditions;

•government regulation (such as regulation of our product and service offerings and of competition); restrictive governmental actions (such as trade protection measures, including export duties and quotas and custom duties and tariffs); nationalization; and restrictions on foreign ownership;

•restrictions on sales or distribution of certain products or services and uncertainty regarding liability for products, services and content, including uncertainty as a result of less Internet-friendly legal systems, local laws, lack of legal precedent, and varying rules, regulations, and practices regarding the physical and digital distribution of media products and enforcement of intellectual property rights;

•business licensing or certification requirements;

•limitations on the repatriation and investment of funds and foreign currency exchange restrictions;

•limited fulfillment and technology infrastructure;

•impact of the COVID-19 pandemic, or other pandemics or epidemics, on our business operations and the global economy;

•shorter payable and longer inventory and receivable cycles and the resultant negative impact on cash flow;

•laws and regulations regarding consumer and data protection, privacy, network security, encryption, payments, advertising, and restrictions on pricing or discounts;

•lower levels of use of the Internet;

•lower levels of consumer spending and fewer opportunities for growth in the markets where we operate;

•difficulty in staffing, developing and managing global operations as a result of distance, language and cultural differences;

•different employee/employer relationships and the existence of works councils and labor unions;

•differing labor regulations where labor laws may be more advantageous to employees as compared to the U.S. and the other jurisdictions we operate in;

•compliance with the U.S. Foreign Corrupt Practices Act and other applicable U.S. and foreign laws prohibiting corrupt payments to government officials and other third parties;

•laws and policies of the U.S. and other jurisdictions affecting trade, foreign investment, loans and taxes; and

•geopolitical events, including pandemic, war and terrorism.

As international physical, ecommerce, and omni-channel retail and other services grow, competition will intensify, including through adoption of evolving business models. Local companies may have a substantial competitive advantage because of their greater understanding of, and focus on, the local customer, as well as their more established local brand names. The inability to hire, train, retain and manage sufficient required personnel may limit our international growth.

If we fail to maintain and expand our relationships with third-party platforms and sellers and buyers in our marketplace, our revenues and results of operations will be harmed.

Our business operations have relied on certain third-party ecommerce platforms, such as Rakuten in Japan, and Amazon, Walmart, Home Depot, Overstock and Wayfair in the U.S. and OTTO in Germany., and we still expect to be significantly influenced by these third-party ecommerce platforms in the foreseeable future.

25

Table of Contents

Such third-party ecommerce platforms have significant influence over how transactions take place on their ecommerce platforms, including how purchase orders are fulfilled by indicating to consumers the preferred express delivery companies for orders placed. We may have to accommodate the demands and requirements from various third-party ecommerce platforms such as packing standards and the selection of specified shippers. Such demands and requirements may increase our costs or weaken our connection with our end customers.

Furthermore, approximately 76.4%, 81.5% and 79.5% of our GMV was generated from our GigaCloud Marketplace in 2021, 2022 and 2023, respectively. As a result, our ability to maintain relationships with and attract new third-party merchants, who are sellers and buyers trading on large parcel merchandise, to our marketplace is critical to our business operations and growth prospects. However, we may not be able to maintain our relationships with third-party ecommerce platforms or sellers and buyers due to a number of factors, some of which are beyond our control. For example, if the transaction volume or active users in our marketplace drop significantly, our third-party merchants may experience sales declines or shortage in products. As a result, they may not be able to generate profits or procure products as they expected, and thus choose not to renew their agreements with us. In addition, we may also be unable to continuously offer attractive terms or economic benefits to our sellers and buyers. As a result, our sellers and buyers may not be effectively motivated to sell or order more products or maintain relationships with us.

Even if we are able to maintain our relationships with sellers and buyers and attract more sellers and buyers to our marketplace, we are subject to various risks in connection with third-party merchants. If any third-party seller does not control the quality of the products that it sells in our marketplace or delivers products that are defective or materially different from description, the reputation of our online marketplace could be materially and adversely affected and we could face claims to hold us liable for the losses. Moreover, despite our efforts to prevent it, some products sold by the sellers in our online marketplace may compete with the products we sell directly, which may cannibalize our sales under our self-operated business. In order for our online marketplace to be successful, we must continue to identify and attract sellers and buyers, and we may not be successful in this regard. The occurrence of any of the above could have a material and adverse effect on our business, financial condition and results of operations.

Risks associated with the manufacturers of the products we sell as our own inventory could materially and adversely affect our financial performance as well as our reputation and brand.

We source products from third-party suppliers and manufacturers which we sell as our own inventory through GigaCloud Marketplace and also through off-platform ecommerce. We depend on our ability to provide our customers with a wide range of products from qualified suppliers in a timely and efficient manner. Political and economic instability, global or regional adverse conditions, such as pandemics or other disease outbreaks or natural disasters, the financial stability of suppliers, suppliers’ ability to meet our standards, labor problems experienced by suppliers, the availability or cost of raw materials, merchandise quality issues, currency exchange rates, trade tariff developments, transport availability and cost, including import-related taxes, transport security, inflation, and other factors relating to our suppliers are beyond our control. As an example, the COVID-19 pandemic could adversely impact supplier facilities and operations due to extended holidays, factory closures and risks of labor shortages, among other things, which may materially and adversely affect our business, financial condition and results of operations.

Our agreements with most of our suppliers do not provide for the long-term availability of merchandise or the continuation of particular pricing practices, nor do they usually restrict such suppliers from selling products to other buyers. There can be no assurance that our current suppliers will continue to seek to sell us products on current terms or that we will be able to establish new or otherwise extend current supply relationships to ensure product acquisitions in a timely and efficient manner and on acceptable commercial terms. Our ability to develop and maintain relationships with reputable suppliers and offer high quality merchandise to our customers is critical to our success. If we are unable to develop and maintain relationships with suppliers that would allow us to offer a sufficient amount and variety of quality merchandise on acceptable commercial terms, our ability to satisfy our customers’ needs, and therefore our long-term growth prospects, may be materially and adversely affected.

Further, we rely on our suppliers’ representations of product quality, safety and compliance with applicable laws and standards. If our suppliers or other vendors violate applicable laws, regulations or our supplier code of conduct, or implement practices regarded as unethical, unsafe or hazardous to the environment, it could damage our reputation and negatively affect our operating results. Further, concerns regarding the safety and quality of products provided by our suppliers could cause our customers to avoid purchasing those products from us, or avoid purchasing products from us altogether, even if the basis for the concern is outside of our control. As such, any issue, or perceived issue, regarding the

26

Table of Contents

quality and safety of any items we sell, regardless of the cause, could adversely affect our brand, reputation, operations and financial results.

We also are unable to predict whether any of the countries in which our suppliers’ products are currently manufactured or may be manufactured in the future will be subject to new, different or additional trade restrictions imposed by the U.S. or foreign governments or the likelihood, type or effect of any such restrictions. Any event causing a disruption or delay of imports from suppliers with international manufacturing operations, including the imposition of additional import restrictions, restrictions on the transfer of funds or increased tariffs or quotas, could increase the cost or reduce the supply of merchandise available to our customers and materially and adversely affect our financial performance as well as our reputation and brand. Furthermore, some or all of our suppliers’ foreign operations may be adversely affected by political and financial instability, resulting in the disruption of trade from exporting countries, restrictions on the transfer of funds or other trade disruptions.

In addition, our business with foreign suppliers, particularly with respect to our international sites, may be affected by changes in the value of the U.S. dollar relative to other foreign currencies. For example, any movement by any other foreign currency against the U.S. dollar may result in higher costs to us for those goods. Declines in foreign currencies and currency exchange rates might negatively affect the profitability and business prospects of one or more of our foreign suppliers. This, in turn, might cause such foreign suppliers to demand higher prices for merchandise in their effort to offset any lost profits associated with any currency devaluation, delay merchandise shipments or discontinue selling to us altogether, any of which could ultimately reduce our revenues or increase our costs.

If we fail to manage our inventory effectively, our results of operations, financial condition and liquidity may be materially and adversely affected.

Our business model requires us to manage a large volume of inventory effectively. We procure products from third-party manufacturers and sell the products as our own inventory through our GigaCloud Marketplace and off-platform ecommerce. We depend on our demand forecasts for various kinds of products to make purchase decisions and to manage our inventory. Demand for products, however, can change significantly between the time inventory is ordered and the date by which we target to sell it. Demand may be affected by seasonality, new product launches, changes in product cycles and pricing, product defects, changes in consumer spending patterns, changes in consumer tastes with respect to our products and other factors, and our customers may not order products in the quantities that we expect. In addition, when we begin selling a new product, we may not be able to accurately forecast demand. The procurement of certain types of inventory may require significant lead time and prepayment, and they may not be returnable. If we are unable to anticipate or respond to changes in customer preferences or fail to bring products that satisfy new customer preferences to GigaCloud Marketplace and off-platform ecommerce in a timely manner, our results of operations, financial condition and liquidity could be adversely affected.

Our inventories was $81.4 million and $78.3 million as of December 31, 2021 and 2022, respectively, and further increased to $132.2 million as of December 31, 2023. Our annual inventory turnover days for our own inventory were 65 days in 2021, 71 days in 2022 and 77 days in 2023. Our inventory turnover days for a given period are equal to average balances of inventories calculated from the beginning and ending balances of the period divided by cost of product sales during the period and then multiplied by the number of days during the period. Shipping costs to procure our inventories, including ocean freight costs, are included in the balance of inventories and an increase in shipping costs may cause us to adjust our product prices upward, which may have affected consumer demand and further lengthened the inventory turnover days. We also acquired inventory from Noble House, which may further impact our inventory turnover days.

If we fail to manage our inventory effectively, we may be subject to a heightened risk of inventory obsolescence, a decline in inventory values, and significant inventory write-downs or write-offs. To reduce our inventory level, we usually choose to sell certain of our products at lower prices, which may lead to lower gross margins. High inventory levels may also require us to commit substantial capital resources, preventing us from using that capital for other important purposes. Any of the above may materially and adversely affect our results of operations and financial condition.

On the other hand, if we underestimate demand for our products, or if our suppliers fail to supply quality products in a timely manner, we may experience inventory shortages, which may result in missed sales, diminished brand loyalty and lost revenues, any of which could harm our business and reputation.

27

Table of Contents

We depend on our relationships with third parties, including third-party trucking and freight service companies, and changes in our relationships with these parties could adversely impact our revenues and profits.

We rely on third parties to operate certain elements of our business. For example, we rely on third-party national, regional and local trucking and freight service companies to deliver our large parcel merchandise. As a result, we may be subject to shipping delays or disruptions caused by inclement weather, natural disasters, system interruptions and technology failures, political instability, military conflicts, labor activism, health epidemics or bioterrorism. For example, following the initial conflict between Israel and Hamas in the Middle East, the Houthi movement in Yemen, launched a number of attacks on marine vessels traversing the Red Sea causing significant operational disruptions for certain third-party business partners. The conflict is ongoing, and should it escalate or expand, it could result in delays, increased shipping and freight costs, and potential disruptions to the arrival of our products. We are also subject to risks of breakage or other damage during delivery by any of these third parties. We also use and rely on other services from third parties, such as telecommunications services, customs, consolidation and shipping services, as well as warranty, installation, assembly and design services. We may be unable to maintain these relationships, and these services may also be subject to outages and interruptions that are not within our control. Third parties may in the future determine they no longer wish to do business with us or may decide to take other actions that could harm our business. We may also determine that we no longer want to do business with them. If parcels are not delivered in a timely fashion or are damaged during the delivery process by these third parties, or if we are not able to provide adequate customer support or other services or offerings, our customers could become dissatisfied and cease using our cross-border fulfillment services or stop trading products through our marketplace, which would adversely affect our operating results.

We may not be successful in optimizing our warehouses and fulfillment network.

As of December 31, 2023, we had 33 large scale warehouses spreading across the U.S., Japan, the U.K., Germany and Canada. Failures to adequately predict customer demand or otherwise optimize and operate our fulfillment network successfully from time to time result in excess or insufficient fulfillment capacity, increased costs and impairment charges, any of which could materially harm our business. As we continue to add warehouses and fulfillment capability, our fulfillment and logistics networks become increasingly complex and operating them becomes more challenging. There can be no assurance that we will be able to operate our networks effectively.

On March 9, 2024, one of our warehouses in Japan, suffered damages due to a warehouse fire. While we are still evaluating the impact caused by the warehouse fire, we estimated approximately $1.8 million in damages with respect to the cost of our inventory held at the warehouse. We have insurance coverage associated with the damages to the inventory and warehouse equipment. Furthermore, we have a total of four warehouses in Japan and we have shifted our warehouse operations in Japan to the other three warehouses to minimize any disruptions to our operations in Japan.

In addition, failure to optimize inventory in our fulfillment network increases our net shipping cost by requiring long-zone or partial shipments. We may be unable to adequately staff our warehousing network and customer service centers. As we maintain the inventory of other companies, the complexity of tracking inventory and operating our fulfillment network has further increased. Our failure to properly handle such inventory or the inability of the other businesses on whose behalf we perform inventory fulfillment services to accurately forecast product demand may result in our being unable to secure sufficient storage space or to optimize our warehouses and fulfillment network or cause other unexpected costs and other harm to our business and reputation.

Damage to our business reputation could have a material adverse effect on our growth strategy and our business, financial condition, results of operations and prospects.

Maintaining and enhancing our reputation is critical to expanding our base of customers, including attracting third-party ecommerce platforms to use our third-party logistics services and the sellers and buyers to trade in our marketplace. Our ability to maintain and enhance our reputation depends largely on our ability to maintain customer confidence in our service offerings, including by delivering parcels on time and without damage to end customers. If end customers do not have a satisfactory experience with our logistics services, our customers may seek out alternative logistics services from our competitors. Alternatively, if our sellers and buyers are not satisfied with the product selection or service offerings in our marketplace, they may not return to our marketplace in the future, or at all.

In addition, unfavorable publicity regarding, for example, reputational damage from short seller reports, our practices relating to privacy and data protection, product quality, delivery problems, competitive pressures, litigation or regulatory activity, could seriously harm our reputation. Such negative publicity also could have an adverse effect on the

28

Table of Contents

size, engagement and loyalty of our customer base and result in decreased total revenues, which could adversely affect our business, financial condition and results of operations. A significant portion of our customers’ experience also depends on third parties outside of our control, including trucking and freight service companies and other third-party delivery agents. If these third parties do not meet our or our customers’ expectations, our business reputation may suffer irreparable damage.

Customer complaints or negative publicity about our marketplace, products, delivery times, company practices, employees, customer data handling and security practices or customer support, especially on social media websites and in our marketplace, could rapidly and severely diminish buyers’ and sellers’ use of our marketplace and third-party ecommerce platforms’ confidence in us and result in harm to our reputation and brand.

Our efforts to launch new products or services may not be successful.

Our business success depends to some extent on our ability to expand our service offerings by launching new products and services and by expanding our existing offerings into new geographies. For example, we expanded into Germany for our third-party logistics services in 2018, and we launched GigaCloud Marketplace, our B2B marketplace, in 2019. In 2023, we completed two acquisitions as part of a strategic initiative for attracting more sellers and buyers on our GigaCloud Marketplace and expanding our solutions offerings. Launching new products and services or expanding internationally requires significant upfront investments, including investments in marketing, information technology, and additional personnel. Expanding our service offerings internationally is particularly challenging because it requires us to gain country-specific knowledge about consumers, regional competitors and local laws, purchase or lease warehouse, build local logistics capabilities and customize portions of our technology for local markets. We may not be able to generate satisfactory revenues from these efforts to offset these costs. Any lack of market acceptance of our efforts to launch new services or to expand our existing offerings could have a material adverse effect on our business, financial condition and results of operations. Further, as we continue to expand our fulfillment capability or add new businesses with different requirements, our logistics networks become increasingly complex and operating them becomes more challenging. There can be no assurance that we will be able to operate our networks effectively.

We have also entered and may continue to enter into new markets in which we have limited or no experience, which may not be successful or appealing to our customers. These activities may present new and difficult technological and logistical challenges, and resulting service disruptions, failures or other quality issues may cause customer dissatisfaction and harm our reputation and brand. Further, our current and potential competitors in new market segments may have greater brand recognition or financial resources, longer operating histories and larger customer bases than we do in these areas. As a result, we may not be successful enough in these newer areas to recoup our investments in them. If this occurs, our business, financial condition and results of operations may be materially and adversely affected.

The COVID-19 pandemic, and any future outbreaks or other public health emergencies, could materially affect our business, liquidity, financial condition and operating results.

The COVID-19 pandemic negatively impacted the global economy, disrupted consumer spending and global supply chains and created significant volatility and disruption of financial markets. The COVID-19 pandemic and the various responses to it globally created significant volatility, uncertainty and economic disruption. During the COVID-19 pandemic, authorities across the U.S. and the globe implemented varying degrees of restriction on social and commercial activity. While these restrictions were largely lifted in 2023, some regions have seen a resurgence of COVID-19 cases resulting in consideration of reinstitution of certain protective measures.

The extent of the impact of a recurring COVID-19 pandemic, or other public health emergencies, on our business will depend on future developments, which remain highly uncertain and difficult to predict, including the duration, severity and sustained geographic spread of the pandemic, additional waves of increased infections, the virulence and spread of different strains of the virus, and the extent to which associated prevention, containment, remediation and treatment efforts, including global vaccination programs and vaccine acceptance, are successful. Additionally, to the extent the COVID-19 pandemic or other outbreaks, epidemics, pandemics or public health crises adversely affects our business, results of operations or financial condition, it may heighten other risks described in this “Risk Factors” section.

We are subject to risks related to online transactions and payment methods.

We accept payments using a variety of methods, including credit card, debit card, third-party online payment platforms such as Alipay, Payoneer and others, credit accounts (including promotional financing) and customer invoicing.

29

Table of Contents

As we offer new payment options to our customers, we may be subject to additional regulations, compliance requirements and fraud. For certain payment methods, including credit and debit cards, we pay interchange and other fees, which may increase over time and raise our operating costs and lower profitability. We are also subject to payment card association operating rules and certification requirements, including the Payment Card Industry Data Security Standard and rules governing electronic fund transfers, which could change or be reinterpreted to make it difficult or impossible for us to comply. As our business changes, we may also be subject to different rules under existing standards, which may require new assessments that involve costs above what we currently pay for compliance. If we fail to comply with the rules or requirements of any provider of a payment method we accept, if the volume of fraud in our transactions limits or terminates our rights to use payment methods we currently accept, or if a data breach occurs relating to our payment systems, we may, among other things, be subject to fines or higher transaction fees and may lose, or face restrictions placed upon, our ability to accept credit card and debit card payments from customers or to facilitate other types of online payments. If any of these events were to occur, our business, financial condition and operating results could be materially and adversely affected.

We occasionally receive orders placed with fraudulent credit card data. We may suffer losses as a result of orders placed with fraudulent credit card data even if the associated financial institution approved payment of the orders. Under current credit card practices, we may be liable for fraudulent credit card transactions. We may also suffer losses from other online transaction fraud, including fraudulent returns or chargebacks. If we are unable to detect or control credit card or transaction fraud, our liability for these transactions could harm our business, financial condition and operating results.

Our failure or the failure of third-party service providers on which we rely to protect our marketplace, networks and systems against cybersecurity incidents, or otherwise to protect our confidential information, could damage our reputation and substantially harm our business and operating results.

We have access to confidential information in our day-to-day operations. We collect, maintain, transmit and store data about our customers, employees, contractors, suppliers, vendors and others, including personal information of the senders and recipients of the parcels, sensitive data, as well as other confidential and business proprietary information and trade secrets. The proper use and protection of confidential information are essential to maintaining customer trust in us and our services.

We are materially dependent upon our networks, information technology infrastructure and related technology systems to provide services to our customers and to manage our internal operations. Many of our customers require access to our services on a continuous basis and may be materially impaired by interruptions in our or our third-party service providers’ infrastructure. Our technology systems also process and store certain confidential information and data for the proper functioning of our network. Cybersecurity incidents and cyberattacks, including from diverse threat actors, such as state-sponsored organizations, opportunistic hackers and hacktivists, as well as through diverse attack vectors, such as AI, social engineering/phishing, malware (including ransomware), malfeasance by insiders, human or technological error, on our system might result in a compromise to the technology that we use to protect confidential information. We may not be able to prevent third parties, especially hackers or other individuals or entities engaging in similar activities, from illegally obtaining confidential information in our possession. Such individuals or entities may engage in various other illegal activities using such information. Further, as parcels move through our network from pickup to delivery, a large number of personnel handles the flow of parcels and have access to significant amounts of confidential information. Some of these personnel may misappropriate the confidential information despite the security policies and measures we have implemented. In addition, most of the delivery and pickup personnel are not our employees, which makes it more difficult for us to implement sufficient and effective control over them. Additionally, other disruptions can occur, such as infrastructure gaps, hardware and software vulnerabilities, inadequate or missing security controls, exposed or unprotected customer data and the accidental or intentional disclosure of source code or other confidential information by former or current employees. Any such incidents could (i) interfere with the delivery of services to our customers, (ii) impede our customers’ ability to do business, (iii) compromise the security of infrastructure, systems and data, (iv) lead to the dissemination to third parties of proprietary information or sensitive, personal, or confidential data about us, our employees or our customers, including personal information of individuals involved with our customers and their end users and (v) impact our ability to do business in the ordinary course. If a breach or other security incident were to occur, it could expose us to increased risk of claims and liability, including litigation (such as class actions), regulatory enforcement, notification obligations and indemnity obligations, as well as loss of existing or potential customers, harm to our brand and reputation, increases in our security costs (including spending material resources to investigate or correct the breach or incident and to prevent future cybersecurity incidents), disruption of normal business operations, the impairment or loss of industry certifications and government sanctions (including debarment). Moreover, containing and remediating any IT

30

Table of Contents

system failure, cybersecurity attack or vulnerability may require significant investment of resources. Any of the foregoing could have a material and adverse effect on our business, financial condition and results of operations.

Similar security risks exist with respect to our third-party vendors that we rely on for aspects of our IT support services, pickup and delivery services, and administrative functions, including the systems owned, operated or controlled by other unaffiliated operators to the extent we rely on such other systems to deliver services to our customers. Our ability to monitor our third-party service providers’ data security is limited. As a result, we are subject to the risk that cyber-attacks on, or other cybersecurity incidents affecting, our third-party service providers may adversely affect our business even if an attack or breach does not directly impact our systems. It is also possible that security breaches sustained by, or other cybersecurity incidents affecting, our competitors could result in negative publicity for our entire industry that indirectly harms our reputation and diminishes demand for our services. Practices regarding the collection, use, storage, transmission and security of personal information have recently come under increased public scrutiny. Any failure or perceived failure by us to prevent cybersecurity incidents or to comply with privacy policies or privacy-related legal obligations could cause our customers to lose trust in us and our services. Any perception that the confidentiality or privacy of information is unsafe or vulnerable when using our services could damage our reputation and substantially harm our business, financial condition and results of operations.

The secure processing, storage, maintenance and transmission of critical customer and business information are vital to our operations and our business strategy. Although we devote significant resources to protecting such information and take what we believe to be reasonable and appropriate measures, including having a formal and dedicated IT department and limiting the amount of any data we store to non-sensitive customer information, such as zip codes and business addresses, to protect sensitive information from compromises such as unauthorized access, disclosure, or modification or lack of availability, our information technology and infrastructure may still be vulnerable to attacks by hackers or viruses or breached due to employee or human error, malfeasance or other disruptions. We may be exposed to significant monetary damages. Saved as the foregoing, we have not taken additional measures to mitigate the risks against cybersecurity in our supply chain based on third-party products, software, services and business. Further, a cybersecurity incident could require us to expend substantial additional resources relating to the security of our information systems and to provide required breach notifications to affected parties, diverting resources from other projects and disrupting our businesses. There can be no assurance that our cybersecurity risk management program and processes, including our policies, controls or procedures, will be fully implemented, complied with or effective in protecting our systems and information.

Real or perceived errors, failures or bugs in our services, software or technology could adversely affect our business, financial condition and results of operations.

Undetected real or perceived errors, failures, bugs or defects may be present or occur in the future in our solutions, software or technology or the technology or software we license from third parties, including open source software. Despite testing by us, real or perceived errors, failures, bugs or defects may not be found until our customers use our services. Real or perceived errors, failures, bugs or defects in our solutions could result in negative publicity, loss of or delay in market acceptance of our services and harm to our reputation and brand, weakening of our competitive position, claims by customers for losses sustained by them or failure to meet the stated service level commitments in our customer agreements. In such an event, we may be required, or may choose, for customer relations or other reasons, to expend significant additional resources in order to help correct the problem. Any real or perceived errors, failures, bugs or defects in our services could also impair our ability to attract new customers, retain existing customers or expand the customers’ use of our services, which could adversely affect our business, financial condition and results of operations.

Our ability to raise capital in the future may be limited, and our failure to raise capital when needed could prevent us from growing.

We may require additional cash capital resources in order to fund future growth and the development of our businesses, including expansion of our ecommerce platform, our third-party logistics services and any investments or acquisitions we may decide to pursue. If our cash resources are insufficient to satisfy our cash requirements, we may seek to issue additional equity or debt securities or obtain new or expanded credit facilities. Our ability to obtain external financing in the future is subject to a variety of uncertainties, including our future financial condition, results of operations, cash flows, share price performance, liquidity of international capital and lending markets, governmental regulations over foreign investment and the ecommerce and logistics services industries. In addition, incurring indebtedness would subject us to increased debt service obligations and could result in operating and financing covenants that would restrict our operations. There can be no assurance that financing will be available in a timely manner or in amounts or on terms

31

Table of Contents

acceptable to us, or at all. Any failure to raise needed funds on terms favorable to us, or at all, could severely restrict our liquidity as well as have a material adverse effect on our business, financial condition and results of operations. Moreover, any issuance of equity or equity-linked securities could result in significant dilution to our existing shareholders.

Our business is highly competitive. Competition presents an ongoing threat to the success of our business.

Our business is rapidly evolving and intensely competitive, and we have many competitors in different industries. Our competition includes third-party logistics service providers, furniture stores, big box retailers, and online ecommerce platforms and marketplaces in the U.S., Asia and Europe. We compete with third-party logistics service providers based on a number of factors, including warehouse and infrastructure capacity, network stability, business model, operational capabilities, cost control and service quality. We also compete with other retailers and ecommerce platforms that offer large parcel merchandise for the variety and availability of products, number of users in the marketplace, flexibility in delivery options and freight rates.

Many of our current competitors have, and potential competitors may have, longer operating histories, greater brand recognition, larger fulfillment infrastructures, greater technical capabilities, faster and less costly shipping, significantly greater financial, marketing and other resources and larger customer bases than we do. These factors may allow our competitors to derive greater revenues and profits from their existing customer bases, acquire customers at lower costs or respond more quickly than we can to new or emerging technologies and changes in customer habits. These competitors may engage in more extensive research and development efforts, undertake more far-reaching marketing campaigns and adopt more aggressive pricing policies, which may allow them to build larger customer bases or generate revenues from their customer bases more effectively than we do.

We may be subject to product liability claims and other similar claims if people or property are harmed by the products we sell or sold through our platform.

Some of the products we sell may expose us to product liability and other claims and litigation (including class actions) or regulatory action relating to safety, personal injury, death or environmental or property damage. Some of our agreements with members of our supply chain may not indemnify us from product liability for a particular product, and some members of our supply chain may not have sufficient resources or insurance to satisfy their indemnity and defense obligations. Although we maintain product liability insurance, we cannot be certain that our coverage will be adequate for liabilities actually incurred or that insurance will continue to be available to us on economically reasonable terms, or at all.

Fluctuations in the price or availability of fuel and uncertainty in third-party transportation capacity may adversely affect our transportation costs and operational results.

Our transportation costs mainly consist of fuel costs and transportation expenses incurred in relation to the use of third-party transportation services. The availability and price of fuel and third-party transportation capacity are subject to political, economic and market factors that are outside of our control. In 2021 and 2022, we continued to increase the use of self-owned and operated, cost-efficient high capacity trucks to replace some, but not all, of our third-party outsourced trucks to further enhance transportation efficiency. In the event of a significant increase in fuel prices and third-party transportation service charges, our transportation expenses may rise, and our gross profit may decrease if we are unable to adopt effective cost control measures or pass on incremental costs to our customers. As a result, our business, financial condition and results of operations may be adversely affected.

We face risks associated with parcels handled and transported through our network and risks associated with transportation.

We handle a large volume of parcels across our cross-border fulfillment network, and face challenges with respect to the protection and inspection of these parcels. Parcels in our fulfillment network may be stolen, damaged or lost for various reasons, and we may face actual or alleged liability for such incidents. In addition, we may fail to detect unsafe or prohibited/restricted items. Further, the big and bulky parcels handled by us are prone to damages, and may injure their recipients, harm our personnel and result in property damage. Failure to prevent prohibited or restricted items from entering our network may result in administrative or criminal penalties as well as civil liability for personal injury and property damage.

The transportation of parcels involves inherent risks. We have multiple warehouse personnel involved in our logistics operations at all times, who are subject to risks associated with logistics and transportation safety, including

32

Table of Contents

transportation-related injuries and losses at our warehouses or during the course of transportation. For example, our personnel may be involved in traffic accidents from time to time, resulting in personal injury and loss or damage to parcels carried by them. In addition, frictions or disputes may occasionally arise from the direct interaction of our personnel with parcel senders and recipients, which may result in personal injury or property damage if such incidents escalate. The insurance policies carried by us may not fully cover the damages caused by transportation-related injuries or losses.

Any of the foregoing could disrupt our services, cause us to incur substantial expenses and divert the time and attention of our management. We may face claims and incur significant liabilities if found liable or partially liable for any injuries, damages or losses. Claims against us may exceed the amount of our insurance coverage or may not be covered by insurance at all. Government authorities may also impose significant fines on us or require us to adopt costly preventive measures. Furthermore, if our services are perceived to be unsafe by our end customers, ecommerce platforms and customers, our business volume may be significantly reduced, and our business, financial condition and results of operations may be materially and adversely affected.

Significant merchandise refunds and product warranty claims could have a material adverse effect on our business.

We allow our customers to claim refunds or product warranties for our 1P sales subject to our return policy. See “Item 1. Business—Logistics Network and Value-added Services—Warranties and Refunds.” If merchandise returns and product warranty claims are significant, our business, financial condition and results of operations could be harmed. Further, we modify our policies relating to returns and warranties from time to time, which may result in customer dissatisfaction or an increase in the number of product returns. Many of our products are large and require special handling and delivery. From time to time our products are damaged in transit, which can increase return rates and harm our reputation and brand.

Our business may be affected by increase in rental expenses or the termination of leases of our warehouses.

We lease properties to operate all of our warehouses, offices, ports and other pickup and delivery outlets. We may be subjected to increase in rental expenses. We may also not be able to successfully extend or renew such leases upon expiration, on commercially reasonable terms or at all, and may be forced to relocate the affected operations. Such relocation may disrupt our operations and result in significant relocation expenses, which could adversely affect our business, financial condition and results of operations. We may not be able to locate desirable alternative sites for our facilities as our business continues to grow and failure in relocating our operations when required could adversely affect our business and operations. In addition, we compete with other businesses for premises at certain locations or of desirable sizes. Even if we are able to extend or renew the respective leases, rental payments may significantly increase as a result of the high demand for the leased properties.

Our business requires significant capital investments and a high level of working capital to sustain our operations and business growth.

We require significant capital investments in our business which consist of leasing and setting up warehouse facilities, technology, sorting and other types of equipment. These investments support both our existing business and anticipated growth. Forecasting projected volume involves many factors which are subject to uncertainty, such as general economic trends, changes in governmental regulation and competition. If we do not accurately forecast our future capital investment needs, we could have excess capacity or insufficient capacity, either of which would negatively affect our revenues and profitability. In addition to forecasting our capital investment requirements, we adjust other elements of our operations and cost structure in response to adverse economic conditions; however, these adjustments may not be sufficient to allow us to maintain our operating margins.

Our strategic investments or acquisitions may be unsuccessful.

We may acquire other assets, technologies, products and businesses that are complementary to our existing business or otherwise. We may also enter into strategic partnerships or cooperation agreements with other businesses to expand our marketplace. Negotiating these transactions can be time-consuming, challenging and expensive, and our ability to close these transactions may often be subject to regulatory approvals that are beyond our control. In addition, investments and acquisitions could result in the use of substantial amounts of cash, potentially dilutive issuances of equity securities, significant amortization expenses related to intangible assets, significant diversion of management attention and exposure to potential unknown liabilities of the acquired business. Moreover, the cost of identifying and consummating investments and acquisitions and integrating the acquired businesses into ours may be significant, and the integration of

33

Table of Contents

acquired businesses may be disruptive to our existing business operations. Consequently, these transactions, even if undertaken and announced, may not close. For one or more of those transactions, we may issue additional equity securities that would dilute our shareholders’ ownership interest, use cash that we may need in the future to operate our business, incur debt on terms unfavorable to us or that we are unable to repay, incur expenses or substantial liabilities, encounter difficulties retaining key employees of the acquired company or integrating diverse software codes or business cultures, encounter difficulties in assimilating acquired operations, encounter diversion of management’s attention to other business concerns, and become subject to adverse tax considerations, substantial depreciation, impairment losses, or deferred compensation charges. If our investments and acquisitions are not successful, our business, financial condition, results of operations and prospects may be materially and adversely affected.

We rely on the performance of members of management and highly skilled IT personnel, and if we are unable to attract, develop, motivate and retain well-qualified employees, our business could be harmed.

Our success depends in part on our continued ability to attract, retain and motivate highly qualified management and other key personnel. We are highly dependent upon our senior management, particularly our chief executive officer, as well as our vice presidents and other members of our senior management team. Although we have executed employment agreements or offer letters with each member of our senior management team, these agreements are terminable at will with or without notice and, therefore, we may not be able to retain their services as expected. We do not currently maintain “key person” life insurance on the lives of our executives or any of our employees. This lack of insurance means that we may not have adequate compensation for the loss of the services of these individuals.

The increasing scale of our business also requires us to hire and retain a wide range of capable and experienced personnel and technology talents who can adapt to a dynamic, competitive and challenging business environment. Competition for talents is intense, and the availability of suitable and qualified candidates is limited in the jurisdictions in which we operate. Competition for talents, together with inflation, could cause us to offer higher compensation and other benefits to attract and retain them, which further increase our labor cost. Even if we were to offer higher compensation and other benefits, these individuals may not choose to join or continue to work for us. Any failure to attract or retain key management and personnel could severely disrupt our business and growth.

We will need to expand and effectively manage our managerial, operational, financial and other resources in order to successfully pursue our business strategies. We may not be successful in maintaining our unique company culture and continuing to attract or retain qualified management and personnel in the future. If we are not able to attract, integrate, retain and motivate necessary personnel to accomplish our business objectives, we may experience constraints that will significantly impede the achievement of our development objectives, our ability to raise additional capital and our ability to implement our business strategy.

We may not be able to prevent others from unauthorized use of our intellectual property, which could harm our business and competitive position.

We rely on a wide portfolio of intellectual property to operate our businesses and we may not be able to effectively protect these intellectual property and proprietary rights against infringement, misappropriation or other violations, or efforts to safeguard our intellectual property may be costly.

We rely on a combination of trademark, copyright and trade secret protection laws in the U.S., the PRC and other jurisdictions, as well as confidentiality procedures and contractual provisions, to protect our intellectual property rights. We enter into confidentiality agreements with our employees and any third parties who may access our proprietary information, and we rigorously control access to our technology and information. However, we cannot guarantee that we have entered into confidentiality agreements with each party that may have or have had access to our trade secrets or proprietary information. Such agreements may be breached by counterparties, who may disclose our proprietary information, including our trade secrets, or claim ownership in intellectual property that we believe is owned by us, and there may not be adequate remedies available to us for any such breach. In addition, we do not enter into intellectual property assignment agreements in the ordinary course, and we rely on the intellectual property rights we obtain from our employees by operation of law. The intellectual property rights we obtain by operation of law may not extend to all intellectual property rights developed by our employees and contractors, and individuals not subject to invention assignment agreements may make adverse ownership claims to our current and future intellectual property rights. We therefore may not possess ownership rights in all intellectual property rights that we regard as our own or that are necessary for the conduct of our business.

34

Table of Contents

Intellectual property protection may not be sufficient in the regions in which we operate. Our trademarks or other intellectual property rights may be challenged by others through administrative process or litigation, and our pending trademark applications may not be allowed. In addition, policing any unauthorized use of our intellectual property is difficult, time-consuming and costly, and the steps we have taken may be inadequate to prevent the misappropriation of our intellectual property. In the event that we resort to litigation to enforce our intellectual property rights, such litigation could result in substantial costs and a diversion of our managerial and financial resources. We can provide no assurance that we will prevail in such litigation and some courts in the U.S. and certain foreign jurisdictions are less willing or unwilling to protect trade secrets. Furthermore, it is often difficult to maintain and enforce intellectual property rights in the PRC. Statutory laws and regulations in the PRC are subject to judicial interpretation and enforcement and may not be applied consistently due to the lack of clear guidance on statutory interpretation. Confidentiality and non-compete agreements may be breached by counterparties, and there may not be adequate remedies available to us for any such breach. Accordingly, we may not be able to effectively protect our intellectual property rights or the intellectual properties licensed from third parties, or to enforce our contractual rights in the PRC and other jurisdictions in which we operate.

In addition, our trade secrets may be leaked or otherwise become available to, or be independently discovered by, our competitors. If any of our trade secrets were to be lawfully obtained or independently developed by a competitor or other third parties, we would have no right to prevent them from using that technology or information to compete with us. Any failure in protecting or enforcing our intellectual property rights could have a material adverse effect on our business, financial condition and results of operations.

We may not be able to protect and enforce our trademarks and trade names, or build name recognition in our markets of interest thereby harming our competitive position.

The registered or unregistered trademarks or trade names that we own have from time to time been and may continue to be challenged, infringed, circumvented, declared generic, lapsed or determined to be infringing on or dilutive of other marks. We may not be able to protect our rights in these trademarks and trade names, which we need in order to build name recognition. In addition, third parties have filed, and may in the future file, for registration of trademarks similar or identical to our trademarks, thereby impeding our ability to build brand identity and possibly leading to market confusion. If they succeed in registering or developing common law rights in such trademarks, and if we are not successful in challenging such rights, we may not be able to use these trademarks to develop brand recognition of our technologies, products or services. In addition, there could be potential trade name or trademark infringement claims brought by owners of other registered trademarks or trademarks that incorporate variations of our registered or unregistered trademarks or trade names. Further, we may in the future enter into agreements with owners of such third-party trade names or trademarks to avoid potential trademark litigation which may limit our ability to use our trade names or trademarks in certain fields of business.

We have not yet registered certain of our trademarks in all of our potential markets, although we have registered “GIGACLOUD TECHNOLOGY” and “大健云仓” in mainland China and Hong Kong. We also acquired valuable intangible assets from the acquisitions of Noble House and Wondersign. If we apply to register these trademarks in other countries and/or other trademarks in the U.S. and other countries, our applications may not be allowed for registration in a timely fashion or at all; further, our registered trademarks may not be maintained or enforced. In addition, third parties may file first for our trademarks in certain countries. If they succeed in registering such trademarks, and if we are not successful in challenging such third-party rights, we may not be able to use these trademarks to market our products and technologies in those countries. If we do not secure registrations for our trademarks, we may encounter more difficulties in enforcing them against third parties than we otherwise would. If we are unable to establish name recognition based on our trademarks and trade names, we may not be able to compete effectively, which could harm our business, financial condition, results of operations and prospects. In addition, over the long term, if we are unable to establish name recognition based on our trademarks, then our marketing abilities may be materially and adversely impacted.

We may be accused of infringing, misappropriating or otherwise violating the intellectual property rights of third parties.

The ecommerce industry is characterized by vigorous protection and pursuit of intellectual property rights, which has resulted in protracted and expensive litigation for many companies. We may be subject to claims and litigation by third parties that we infringe, misappropriate or otherwise violate their intellectual property rights. Furthermore, under our current marketplace, the products offered in our marketplace are supplied by third-party merchants, who are separately responsible for sourcing the products that are sold in our marketplace. We have been and may continue to be subject to allegations, and may in the future be subject to lawsuits, claiming that products listed or sold through our marketplace by third-party merchants are counterfeit, unauthorized, illegal, or otherwise infringe, misappropriate or violate third-party

35

Table of Contents

copyrights, trademarks, patents or other intellectual property rights, or that content posted on our user interface contains misleading information on description of products and comparable prices in the U.S., China or any other jurisdictions in which we have operations. The costs of supporting such litigation and disputes are considerable, and there can be no assurances that favorable outcomes will be obtained. Further, the application and interpretation of China’s intellectual property laws and the procedures and standards for granting intellectual property rights in China are still evolving and are uncertain, and we cannot assure you that PRC courts or regulatory authorities would agree with our analysis. As our business expands and the number of competitors in our market increases and overlaps occur, we expect that infringement claims may increase in number and significance. Any claims or proceedings against us, whether meritorious or not, could be time-consuming, result in considerable litigation costs, require significant amounts of management time or result in the diversion of significant operational resources, any of which could materially and adversely affect our business, financial condition and results of operations.

Legal claims regarding intellectual property rights are subject to inherent uncertainties due to the oftentimes complex issues involved, and we cannot be certain that we will be successful in defending ourselves against such claims. In addition, whereas we currently do not own or in-license any patents, some of our larger competitors have extensive portfolios of issued patents. Many potential litigants, including patent holding companies, have the ability to dedicate substantially greater resources to enforce their intellectual property rights and to defend claims that may be brought against them. Furthermore, a successful claimant could secure a judgment that requires us to pay substantial damages or prevents us from conducting our business as we have historically done or may desire to do in the future. We may also be required to seek a license and pay royalties for the use of such intellectual property, which may not be available on commercially acceptable terms, or at all. Alternatively, we may be required to develop non-infringing technology or intellectual property, which could require significant effort and expense and may ultimately not be successful.

We have received in the past, and we may receive in the future, communications alleging that certain items posted on or sold through our marketplace infringe, misappropriate or otherwise violate third-party copyrights, designs, marks and trade names or other intellectual property rights or other proprietary rights. Brand and content owners and other proprietary rights owners have actively asserted their purported rights against online companies. In addition to litigation from rights owners, we may be subject to regulatory, civil or criminal proceedings and penalties if governmental authorities believe we have aided and abetted in the sale of counterfeit or infringing products. Such claims, whether or not meritorious, may result in the expenditure of significant financial, managerial and operational resources, injunctions against us or the payment of damages by us. We may need to obtain licenses from third parties who allege that we have violated their rights, but such licenses may not be available on terms acceptable to us, or at all. These risks have been amplified by the increase in third parties whose sole or primary business is to assert such claims.

Furthermore, we use open source software in connection with our GigaCloud Marketplace. Companies that incorporate open source software into their products and services have, from time to time, faced claims challenging the ownership of open source software and compliance with open source license terms. As a result, we could be subject to suits by parties claiming ownership of what we believe to be open source software or noncompliance with open source licensing terms. Additionally, the use and distribution of open source software can lead to greater risks than the use of third-party commercial software, and some open source projects have known vulnerabilities and open source software does not come with warranties or other contractual protections regarding infringement claims or the quality of the code. Some open source software licenses require users who distribute open source software as part of their software to publicly disclose all or part of the source code to such software and make available any derivative works of the open source code on unfavorable terms or at no cost. While we monitor our use of open source software and try to ensure that none is used in a manner that would require us to disclose our source code or that would otherwise breach the terms of an open source license, such use could inadvertently occur, or could be claimed to have occurred, in part because open source license terms are often ambiguous. These claims could also result in litigation, which could be costly to defend, and if portions of our software are determined to be subject to an open source license or if the license terms for the open source software that we incorporate change, we could be required to publicly release or disclose our source code or pay damages for breach of contract or cease offering the implicated services unless and until we can re-engineer all or a portion of our software, including GigaCloud Marketplace, in a manner that avoids infringement or otherwise change our business, any of which could reduce or eliminate the value of our services and adversely affect our business. The re-engineering process could require us to expend significant additional research and development resources, and we may not be able to complete the re-engineering process successfully. Further, we could be required to seek licenses from third parties to continue using certain software or offering certain of our services or to discontinue the use of such software or the sale of our affected services in the event we could not obtain such licenses, which may not be available to us on commercially reasonable terms or at all. Any of the foregoing could be harmful to our business, financial condition and results of operations.

36

Table of Contents

We are subject to legal and regulatory proceedings from time to time in the ordinary course of our business.

We are, and may in the future be, subject to claims, lawsuits including class actions and individual lawsuits, government investigations, and other proceedings relating to intellectual property, consumer protection, privacy, labor and employment, import and export practices, competition, securities, tax, marketing and communications practices, commercial disputes, and other matters. The number and significance of our legal disputes and inquiries have increased as we have grown larger, as our business has expanded in scope and geographic reach, and as our services have increased in complexity.

Moreover, becoming a public company may have raised our public profile, which may result in increased litigation as well as increased public awareness of any such litigation. There is substantial uncertainty regarding the scope and application of many of the laws and regulations to which we are subject, which increases the risk that we will be subject to claims alleging violations of those laws and regulations. In the future, we may also be accused of having, or be found to have, infringed, misappropriated or otherwise violated third-party intellectual property rights.

Regardless of the outcome, legal proceedings can have a material and adverse impact on us due to their costs, diversion of our resources, and other factors. We may decide to settle legal disputes on terms that are unfavorable to us. Furthermore, if any litigation to which we are a party is resolved adversely, we may be subject to an unfavorable judgment that we may not choose to appeal or that may not be reversed upon appeal. In addition, the terms of any settlement or judgment in connection with any legal claims, lawsuits, or proceedings may require us to cease some or all of our operations, or pay substantial amounts to the other party and could materially and adversely affect our business, financial condition and results of operations.

For information about a currently pending legal proceeding, see “Items 3. Legal Proceedings.”

Our insurance coverage may not be sufficient to cover all the risks which our operations are exposed to and therefore we are susceptible to significant liabilities.

We have limited insurance coverage. We do not maintain business interruption insurance, cybersecurity insurance or general third-party liability insurance, nor do we maintain key-man life insurance. Although we maintain certain general liability insurance for our warehouses, we cannot assure you that our insurance coverage is sufficient to prevent us from any loss or that we will be able to successfully claim our losses under our current insurance policies on a timely basis, or at all. If we incur any loss that is not covered by our insurance policies, or the compensated amount is significantly less than our actual loss, our business, financial condition and results of operations could be materially and adversely affected.

Trade restrictions could materially and adversely affect our business, financial condition and results of operations.

We are focused on facilitating B2B ecommerce transactions for large parcel merchandise. Our cross-border logistics services may be affected by trade restrictions implemented by countries or territories in which our customers are located or in which our customers’ products are manufactured or sold.

For example, we are subject to risks relating to changes in trade policies, tariff regulations, embargoes or other trade restrictions adverse to our customers’ business. Actions by governments that result in restrictions on movement of parcels or otherwise could also impede our ability to carry out our cross-border ecommerce solutions and logistics services. In addition, international trade and political issues, tensions and conflicts may cause delays and interruptions to cross-border transportation and result in limitations on our insurance coverage. If we are unable to connect our global customers to each other in our marketplace or provide solutions to transporting parcels to and from countries with trade restrictions in a timely manner or at all, our business, financial condition and results of operations could be materially and adversely affected.

Any lack of requisite approvals, licenses or permits applicable to our business operations may harm our business.

We may not be able to obtain all the licenses and approvals that may be deemed necessary to operate our business. Because we operate in multiple jurisdictions, the relevant laws and regulations, as well as their interpretations, could be different from those in the U.S. This can make it difficult to know which licenses and approvals are necessary, or the processes for obtaining them. For these same reasons, we also cannot be certain that we will be able to maintain the licenses and approvals that we have previously obtained, or that once they expire we will be able to renew them. We cannot

37

Table of Contents

be sure that our interpretations of the rules and their exemptions have always been or will be consistent with those of the local regulators.

As we expand our businesses, we may be required to obtain new licenses and will be subject to additional laws and regulations in the markets we plan to operate in. If we fail to obtain, maintain or renew any required licenses or approvals or make any necessary filings or are found to need licenses or approvals that we believed were not necessary or we were exempted from obtaining, we may be subject to various penalties, such as confiscation of the revenues or assets that were generated through the unlicensed business activities, imposition of fines, suspension or cancellation of the applicable license, written reprimands, termination of third-party arrangements, criminal prosecution and the discontinuation or restriction of our operations. Any such penalties may disrupt our business operations and materially and adversely affect our business, financial condition and results of operations.

We have granted and expect to continue to grant share-based awards in the future under our share incentive plans, which may result in increased share-based compensation expenses.

We adopted the 2008 share incentive plan in 2008, together with the amendments thereto, the “2008 Plan,” for the purpose of granting share-based compensation awards to employees, directors and consultants to incentivize their performance and align their interests with ours. As of December 31, 2023, the maximum aggregate number of shares which may be issued pursuant to all awards under the 2008 Plan was 2,513,743 ordinary shares. We are authorized to grant options, share appreciation rights, share awards of restricted shares and non-restricted shares and other types of awards as the administrator of the 2008 Plan decides.

In March 2017, our shareholders and board of directors approved and adopted the 2017 share incentive plan, together with the amendments thereto, the “2017 Plan.” As of December 31, 2023, the maximum aggregate number of shares which may be issued pursuant to all awards under the 2017 Plan was 7,180,928 ordinary shares, subject to an annual increase on the first day of each fiscal year beginning January 1, 2023 and ending on and including January 1, 2027 according to a formula set forth in the 2017 Plan. We are authorized to grant options, share appreciation rights, dividend equivalent rights, restricted shares, restricted share units or other rights or benefits under the 2017 Plan.

We account for compensation costs for all share options using a fair value-based method and recognize expenses in our consolidated statements of comprehensive income in accordance with U.S. generally accepted accounting principles, or U.S. GAAP. As of December 31, 2023, awards to purchase an aggregate of 6,852,035 ordinary shares under the 2008 Plan and the 2017 Plan were granted, excluding awards that were forfeited, repurchased, cancelled, lapsed, settled or otherwise expired after the relevant grant dates. As a result of these grants, we incurred share-based compensation of $9.7 million, $9.2 million and $2.5 million in 2021, 2022 and 2023, respectively. We will incur additional share-based compensation expenses in the future as we continue to grant share-based incentives. We believe the granting of share-based compensation is of significant importance to our ability to attract and retain key personnel and employees, and we will continue to grant share-based compensation to employees in the future. As a result, our expenses associated with share-based compensation may increase, which may have an adverse effect on our results of operations.

We could be held liable if our GigaCloud Marketplace is used for fraudulent, illegal or improper purposes such as money laundering.

Although we have taken and continue to take measures, our GigaCloud Marketplace is susceptible to potentially illegal or improper uses, which could damage our reputation and subject us to liability. These may include the use of our marketplace in connection with fraudulent sales of merchandise and other intellectual property piracy, money laundering, bank fraud and prohibited sales of restricted products. Criminals are using increasingly sophisticated methods to engage in illegal activities such as counterfeiting and fraud, and incidents of fraud could increase in the future. We could be subject to fraud claims if confidential information obtained from our users is used for unauthorized purposes.

Our risk management policies and procedures may not be fully effective in identifying, monitoring and managing these risks. We are not able to monitor in each case the sources of funds for our digital financial services platform users, or the ways in which they are used. An increase in fraudulent transactions or publicity regarding payment disputes could harm our reputation and reduce customers’ confidence in our marketplace and solutions.

Natural disasters, pandemics, epidemics, acts of war, terrorist attacks and other events could materially and adversely affect our business.

38

Table of Contents

Severe weather conditions and other natural or man-made disasters, including storms, floods, fires, earthquakes, epidemics, pandemics, conflicts, unrest, terrorist attacks, war, labor unrest, and/or other political instability (including, without limitation, the ongoing conflicts between Russia and Ukraine and Israel and Hamas), may disrupt our business and result in decreased revenues. For example, following the initial conflict between Israel and Hamas, the Houthi movement in Yemen launched a number of attacks on marine vessels traversing the Red Sea causing disruptions for operations across the impacted region. In addition, these types of events could negatively impact ocean transportation and consumer spending in the impacted regions or, depending upon the severity, globally. Customers may reduce their demand for logistics services or shipments, or our costs to operate our business may increase, either of which could have a material adverse effect on us. On March 9, 2024, one of our warehouses in Japan suffered damages due to a warehouse fire. Although we have insurance coverage associated with the damages to the inventory and warehouse equipment and we can still utilize our other three warehouses in Japan with alternative plans to minimize any disruptions to our operations in such warehouse with fire, we may still have some impacts in our warehouse operations. Any such events affecting one of our major facilities could result in a significant interruption in or disruption of our business, financial condition and results of operations.

Government regulation of the Internet and ecommerce in the U.S. and globally is evolving, and unfavorable changes or failure by us to comply with these regulations could substantially harm our business and results of operations.

We are subject to general business regulations and laws as well as regulations and laws specifically governing the Internet and ecommerce in the U.S. and globally. Existing and future regulations and laws could impede the growth of the Internet, ecommerce or mobile commerce. These regulations and laws may involve taxes, tariffs, privacy and data security, anti-spam, content protection, electronic contracts and communications, consumer protection, Internet neutrality and gift cards. It is not clear how existing laws governing issues such as property ownership, sales and other taxes and consumer privacy apply to the Internet as the vast majority of these laws were adopted prior to the advent of the Internet and do not contemplate or address the unique issues raised by the Internet or ecommerce. It is possible that general business regulations and laws, or those specifically governing the Internet or ecommerce, may be interpreted and applied in a manner that is inconsistent from one jurisdiction to another and may conflict with other rules or our practices. We cannot be sure that our practices have complied, comply or will comply fully with all such laws and regulations. Any failure or perceived failure by us to comply with any of these laws or regulations could result in damage to our reputation, a loss in business and proceedings or actions against us by governmental entities or others. Any such proceeding or action could hurt our reputation, force us to spend significant amounts in defense of these proceedings, distract our management, increase our costs of doing business, decrease the use of our sites by consumers and suppliers and may result in the imposition of monetary liability. We may also be contractually liable to indemnify and hold harmless third parties from the costs or consequences of non-compliance with any such laws or regulations. Adverse legal or regulatory developments could substantially harm our business. Further, if we enter into new market segments or geographical areas and expand the products and services we offer, we may be subject to additional laws and regulatory requirements or prohibited from conducting our business, or certain aspects of it, in certain jurisdictions. We will incur additional costs complying with these additional obligations and any failure or perceived failure to comply would adversely affect our business and reputation.

Increasing focus with respect to environmental, social and governance matters may impose additional costs on us or expose us to additional risks. Failure to comply with the laws and regulations on environmental, social and governance matters may subject us to penalties and adversely affect our business, financial condition and results of operations.

The governments globally and public advocacy groups have been increasingly focused on environment, social and governance, or ESG, issues in recent years, making our business more sensitive to ESG issues and changes in governmental policies and laws and regulations associated with environment protection and other ESG-related matters. Investor advocacy groups, certain institutional investors, investment funds and other influential investors are also increasingly focused on ESG practices and in recent years have placed increasing importance on the implications and social cost of their investments. Regardless of the industry, increased focus from investors and the governments globally on ESG and similar matters may hinder access to capital, as investors may decide to reallocate capital or to not commit capital as a result of their assessment of a company’s ESG practices. In addition, there is also uncertainty regarding potential laws, regulations and policies related to ESG and global environmental sustainability matters, including disclosure obligations and reporting on such matters. Any ESG concern or issue and changes in the legal or regulatory environment affecting ESG and sustainability disclosure, responsible sourcing, supply chain transparency, or environmental protection, among others, could increase our regulatory compliance costs. If we do not adapt to or comply with the evolving expectations and standards on ESG matters from investors and the governments globally or are perceived to have not responded appropriately to the growing concern for ESG issues, regardless of whether there is a legal requirement to do so, we may

39

Table of Contents

suffer from reputational damage and the business, financial condition and the price of our Class A ordinary shares could be materially and adversely affected.

We are subject to U.S., PRC and certain foreign export and import controls, sanctions, embargoes, anti-corruption laws and anti-money laundering laws and regulations. Compliance with these legal standards could impair our ability to compete in the global markets. We could face criminal liability and other serious consequences for violations, which could harm our business.

We are subject to export control and import laws and regulations, including the U.S. Export Administration Regulations, U.S. Customs regulations, and various economic and trade sanctions regulations administered by the U.S. Treasury Department’s Office of Foreign Assets Controls, and anti-corruption and anti-money laundering laws and regulations, including the U.S. Foreign Corrupt Practices Act of 1977, as amended, the U.S. domestic bribery statute contained in 18 U.S.C. § 201, the U.S. Travel Act, the USA PATRIOT Act, and other state and national anti-bribery and anti-money laundering laws in the countries in which we conduct activities. We are also subject to anti-bribery laws in the PRC that generally prohibit companies and their intermediaries from making payments to government officials for the purpose of obtaining or retaining business or securing any other improper advantage. State and national anti-corruption laws are interpreted broadly and prohibit companies and their employees and agents from authorizing, promising, offering, providing, soliciting or receiving, directly or indirectly, improper payments or anything else of value to recipients in the public or private sector. We may engage third-party carriers outside of the U.S. to deliver our parcels internationally and/or other third-party agents to obtain necessary permits, licenses, patent registrations and other regulatory approvals in new geographic areas which we are expanding into. We can be held liable for the corrupt or other illegal activities of our employees, agents and third-party carriers, even if we do not explicitly authorize or have actual knowledge of such activities. Any violations of the laws and regulations described above may result in substantial civil and criminal fines and penalties, imprisonment, the loss of export or import privileges, debarment, tax reassessments, breach of contract and fraud litigation, reputational harm and other consequences.

We are subject to stringent and changing privacy laws, regulations and standards as well as contractual obligations related to data privacy and security. Our actual or perceived failure to comply with such obligations could harm our reputation, subject us to significant fines and liability, or otherwise adversely affect our business or prospects.

We are, and may increasingly become, subject to various laws and regulations, as well as contractual obligations, relating to data privacy and security in the jurisdictions in which we operate. The regulatory environment related to data privacy and security is increasingly rigorous, with new and constantly changing requirements applicable to our business, and enforcement practices are likely to remain uncertain for the foreseeable future. These laws and regulations may be interpreted and applied differently over time and from jurisdiction to jurisdiction, and it is possible that they will be interpreted and applied in ways that may have a material adverse effect on our business, financial condition, results of operations and prospects.

In the U.S., various federal and state regulators have adopted, or are considering adopting, laws and regulations concerning personal information and data security. Certain state laws may be more stringent or broader in scope, or offer greater individual rights, with respect to personal information than federal, international or other state laws, and such laws may differ from each other, all of which may complicate compliance efforts. For example, the CCPA which provides privacy rights for California residents and imposes obligations on companies that process their personal information, came into effect on January 1, 2020. Among other things, the CCPA requires covered companies to provide new disclosures to California consumers about their data collection, use and sharing practices and provide such consumers new data protection and privacy rights, including the ability to opt out of certain sales of personal information. The CCPA provides for civil penalties for violations, as well as a private right of action for certain data breaches that result in the loss of personal information. This private right of action may increase the likelihood of, and risks associated with, data breach litigation. On November 3, 2020, California voters approved a new privacy law, the California Privacy Rights Act, or the CPRA, which significantly modifies the CCPA, including by expanding consumers’ rights with respect to certain personal information and creating a new state agency to oversee implementation and enforcement efforts. The CCPA has prompted a wave of new data privacy laws in other states that share similarities with the CCPA, and similar laws have been proposed in additional states and at the federal level.

In the PRC, the PRC regulatory and enforcement regime with regard to cybersecurity, data security and data protection is constantly evolving and can be subject to significant change, making the extent of our obligations in that regard uncertain. In November 2016, the Standing Committee of the National People’s Congress of the PRC, or the Standing Committee of the NPC, promulgated the PRC Cybersecurity Law, which took effect on June 1, 2017. The PRC Cybersecurity Law provides that network operators shall take technical and other necessary measures as required by laws,

40

Table of Contents

regulations, and mandatory requirements to safeguard the operation of networks, respond to network security incidents effectively, prevent illegal and criminal activities, and maintain the integrity, confidentiality and usability of network data. In June 2021, the Standing Committee of the NPC promulgated the PRC Data Security Law, which took effect on September 1, 2021. The PRC Data Security Law sets forth data security protection obligations for entities and individuals handling personal data, including that no entity or individual may acquire such data by stealing or other illegal means, and the collection and use of such data should be for the purpose and within the limit that is prescribed by applicable laws and regulations. The PRC Data Security Law also provides that the government will establish a security review procedure for data-related activities that affect or may affect national security. In July 2021, the PRC State Council promulgated the Regulations on Security Protection of Critical Information Infrastructure, which took effect on September 1, 2021. Pursuant to these regulations, critical information infrastructure means key network facilities or information systems of critical industries or sectors, such as public communication and information service, energy, transportation, water conservancy, finance, public services, e-government affairs and national defense science, technology and industry, the damage, malfunction or data leakage of which may seriously endanger national security, people’s livelihood and public interests. Furthermore, in July 2021, the General Office of the Central Committee of the Communist Party of China and the General Office of the State Council jointly promulgated the Opinions on Strictly Cracking Down on Illegal Securities Activities in Accordance with the Law, or the Opinions on Strictly Cracking Down on Illegal Securities Activities, according to which, among other things, relevant governmental authorities are required to improve laws and regulations related to data security, cross-border data transmission, and management of confidential information. In August 2021, the Standing Committee of the NPC promulgated the PRC Personal Information Protection Law, which integrates the scattered rules with respect to personal information rights and privacy protection and took effect on November 1, 2021. The PRC Personal Information Protection Law applies to the processing of personal information within mainland China as well as certain personal information processing activities outside of mainland China, including those for the provision of products and services to natural persons within mainland China or for the analysis and assessment of acts of natural persons within mainland China. Furthermore, the PRC Personal Information Protection Law steps up the protection for personal information and imposes additional requirements in terms of its processing. As the interpretation and implementation of the PRC Personal Information Protection Law remain uncertain, we cannot assure you that we will be deemed to fully comply with the PRC Personal Information Protection Law in all respects, and regulatory authorities may order us to rectify or terminate our current practice of collecting and processing personal information.

On December 28, 2021, the Cyberspace Administration of China, or the CAC, together with other authorities, jointly promulgated the Measures for Cybersecurity Review, which became effective on February 15, 2022 and simultaneously superseded and replaced the cybersecurity review measures that had been in effect since June 2020. According to the Measures for Cybersecurity Review, critical information infrastructure operators that procure internet products and services and network platform operators engaging in data processing activities should be subject to cybersecurity review if their activities affect or may affect national security. The Measures for Cybersecurity Review also expand the cybersecurity review to network platform operators possessing personal information of more than one million users if such operators seek to list on a foreign stock exchange. In addition, relevant PRC regulatory authorities may initiate cybersecurity review if they determine that an operator’s network products or services or data processing activities affect or may affect national security.

On November 14, 2021, the CAC published the Regulations on the Administration of Network Data Security (Draft for Comments), or the Draft Network Data Security Regulations, for public comments until December 13, 2021. The Draft Network Data Security Regulations provide that data processors refer to individuals or organizations that, during their data processing activities such as data collection, storage, utilization, processing, transmission, provision, publication and deletion, have autonomy over the purpose and the manner of data processing. In accordance with the Draft Network Data Security Regulations, a data processor must apply for a cybersecurity review for certain activities, including, among other things, (i) merger, reorganization or division of such internet platform operator that has acquired a large number of data resources related to national security, economic development or public interests, which affects or may affect national security and (ii) any other data processing activity that affects or may affect national security. However, there have been no clarifications from the relevant authorities as of the date of this annual report as to the standards for determining whether an activity is one that “affects or may affect national security.” In addition, the Draft Network Data Security Regulations stipulate that data processors that process “important data” or are listed overseas must conduct an annual data security assessment, either by itself or through a data security service provider, and must submit the assessment report of a given year to the relevant municipal cybersecurity department by the end of January of the following year. As of the date of this annual report, the Draft Network Data Security Regulations have been released for public comment only, and its final provisions and adoption are subject to uncertainties.

41

Table of Contents

As of the date of this annual report, we have not been involved in any formal investigations on cybersecurity or data security initiated by related governmental regulatory authorities, and we have not received any inquiry, notice, warning or sanction in such respect. However, as the Measures for Cybersecurity Review were newly adopted, and the Draft Network Data Security Regulations have not been adopted, there remains uncertainty in the interpretation and enforcement of such PRC cybersecurity and data security laws and regulations. Thus, we cannot assure you whether we would be subject to a cybersecurity review requirement, and if so, that we would be able to pass such review. If the authorized PRC regulatory body subsequently determines that we are required to go through such cybersecurity review or if any other PRC government authorities promulgate any interpretation or implementation rules that would require us to go through a cybersecurity review, we may fail to complete such cybersecurity review procedures in a timely manner, or at all. Any failure or delay in the completion of the cybersecurity review procedures or any other non-compliance with the related laws and regulations may result in fines or other penalties, including suspension of business and website closure as well as reputational damage or legal proceedings or actions against us, which may have a material adverse effect on our business, financial condition or results of operations.

On July 7, 2022, the CAC issued the Measures for Security Assessment of Cross-border Data Transfer, which took effect on September 1, 2022. According to these measures, in addition to the requirement to conduct self-assessment on the risks of the outbound data transfer, to provide data abroad under any of the following circumstances, a data processor must apply to the national cyberspace department for data security assessment through the provincial-level cyberspace administration authority: (i) outbound transfer of important data by a data processor; (ii) outbound transfer of personal information by a critical information infrastructure operator or a personal information processor who has processed the personal information of more than one million people; (iii) outbound transfer of personal information by a personal information processor who has made outbound transfers of the personal information of 100,000 people cumulatively or the sensitive personal information of 10,000 people cumulatively since January 1 of the previous year; and (iv) other circumstances where an application for the security assessment of an outbound data transfer is required as prescribed by the national cyberspace administration authority.

On September 12, 2022, the CAC issued the Notice on Seeking Public Comments on the Decision to Amend the Cybersecurity Law of the People’s Republic of China (Draft for Comments), or the Draft Decision to Amend the Cybersecurity Law. According to the Draft Decision to Amend the Cybersecurity Law, the violations of the Cybersecurity Law might be subject to more severe punishment if the Draft Decision to Amend the Cybersecurity Law is implemented in its current form. Specifically, the Draft Decision to Amend the Cybersecurity Law enhanced the punishment against violations of the network operation security obligation, the critical information infrastructure operation security obligation, and the network information security obligation by increasing the upper limits of the fines and imposing additional punishment. The Draft Decision to Amend the Cybersecurity Law also enhanced the punishment against personal information infringement by referencing to the punishment under applicable laws which would include relevant punishment under the PRC Personal Information Protection Law.

Furthermore, in the EU and the U.K., the collection and use of personal data are governed by the provisions of the GDPR in addition to other applicable laws and regulations. The GDPR imposes strict obligations with respect to, and restrictions on, the collection, use, retention, protection, disclosure, transfer and processing of personal data. The GDPR regulates cross-border transfers of personal data out of the EEA and the U.K., including the U.S. Case law from the Court of Justice of the European Union, or the CJEU, states that reliance on the standard contractual clauses - a standard form of contract approved by the European Commission as an adequate personal data transfer mechanism - alone may not necessarily be sufficient in all circumstances and that transfers must be assessed on a case-by-case basis. We expect the existing legal complexity and uncertainty regarding international personal data transfers to continue. As the regulatory guidance and enforcement landscape in relation to data transfers continue to develop, we could suffer additional costs, complaints and/or regulatory investigations or fines; we may have to stop using certain tools and vendors and make other operational changes; we will have to implement revised standard contractual clauses for existing arrangements within required time frames; and/or it could otherwise affect the manner in which we provide our services, and could adversely affect our business, operations and financial condition. The GDPR authorizes fines for certain violations of up to 4% of the total global annual turnover of the preceding financial year or €20 million/GBP 17.5 million, whichever is greater. Such fines are in addition to any civil litigation claims by data subjects. Other jurisdictions outside the EU are similarly introducing or enhancing privacy and data security laws, rules and regulations, which could increase our compliance costs and the risks associated with non-compliance. In Hong Kong, the Personal Data (Privacy) Ordinance (Chapter 486 of the Laws of Hong Kong), or the PDPO, applies to data users, such as our business, that control the collection, holding, processing or use of personal data in Hong Kong. We are subject to the general requirements under the PDPO, including the need to obtain the prescribed consent of the data subject and to take all practicable steps to protect the personal data held by data users against unauthorized or accidental access, loss or use. Breaches of the PDPO may lead to a variety of

42

Table of Contents

civil and criminal sanctions, including fines and imprisonment. In addition, data subjects have a right to bring proceedings in court to seek compensation for damage. We cannot guarantee that we are, or will be, in compliance with all applicable international regulations as they are enforced now or as they evolve.

Many countries have adopted, or are in the process of adopting, regulations governing the use of cookies and similar tracking technologies, and individuals may be required to “opt-in” to their placement for the purposes of marketing. We are also subject to evolving EU and U.K. privacy laws on cookies, tracking technologies and e-marketing. In the EU and the U.K. under national laws derived from the ePrivacy Directive , informed consent is required for the placement of a cookie on a user’s device and for direct electronic marketing which prohibits pre-checked consents and imposes a requirement to ensure separate consents are sought for each type of cookie or similar technology. Recent guidance, court cases and regulatory and consumer group-led action are driving increased attention to compliance with these rules. Increased enforcement of these strict requirements could lead to substantial costs, require significant system changes, limit the effectiveness of our marketing activities, divert the attention of our technology personnel, adversely affect our margins, increase costs and subject us to additional liabilities. Widespread adoption of regulations that significantly restrict our ability to use performance marketing technology could adversely affect our ability to market effectively to current and prospective hosts and guests, and thus materially and adversely affect our business, results of operations and financial condition. In light of the complex and evolving nature of EU, EU Member State and U.K. privacy laws on cookies and tracking technologies, there can be no assurances that we will be successful in our efforts to comply with such laws.

All of these evolving compliance and operational requirements impose significant costs, such as costs related to organizational changes, implementing additional protection technologies, training employees and engaging consultants, which are likely to increase over time. In addition, such requirements may require us to modify our data processing practices and policies, distract management or divert resources from other initiatives and projects, all of which could have a material adverse effect on our business, financial condition, results of operations and prospects. Any failure or perceived failure by us to comply with any applicable laws and regulations, or similar laws and regulations in the jurisdictions in which we operate relating to data privacy and security could result in damage to our reputation, as well as proceedings or litigation by governmental agencies or other third parties, including class action privacy litigation in certain jurisdictions, which would subject us to significant fines, sanctions, awards, injunctions, penalties or judgments. Any of the foregoing could have a material adverse effect on our business, results of operations, financial condition and prospects.

We are subject to, and likely will be subject in the future, to further stringent and changing laws, regulations and standards relating to the provision of platforms, services and goods online. With regard to the current legislation in this area, our actual or perceived failure to comply with such obligations could harm our reputation, subject us to significant fines and liability, or otherwise adversely affect our business or prospects. We may also need to spend significant time and resources on understanding upcoming legislation in this area and considering and implementing changes to our websites, processes, policies and procedures in order to become compliant with current and future legislation.

We are, and are likely increasingly to become, subject to various laws and regulations, as well as contractual obligations, relating to the provision of goods and services online, online platforms, e-commerce and online contracts, online advertising and the online provision of information and the regulation of online content, in the context of both the B2B and B2C aspects of our business. There is a body of legislation in this area with which we are already required to comply, including the E-Commerce Directive 2000/31/EC, the Consumer Rights Directive 2011/83/EU, as amended by the Directive on better enforcement and modernization of EU consumer protection (EU) 2019/2161 (and member state implementing legislation in each case) and the Electronic Commerce (Amendment etc.) (EU Exit) Regulations 2019, among others. In addition to the current legislative framework, this is an area of current legislative focus for a number of jurisdictions, including the EU and the U.K. For example, on November 16, 2022, the DSA came into force in the EU. The majority of the substantive provisions of the DSA took effect on February 17, 2024. The DSA governs, among other things, the potential liability for illegal services or content on the platform, obligations around traceability of business users, and requires enhanced transparency measures, including in relation to any recommendation systems (including the main parameters used by such systems and any available options for recipients to modify or influence them). In particular, obligations to diligence the services offered on the platform could require significant additional resource.In addition, on October 26, 2023, the Online Safety Act was enacted into law. The Online Safety Act establishes a new regulatory regime to address illegal and harmful content online, including fines and other sanctions in the event of non-compliance. Other jurisdictions, including France, Germany, Singapore and Australia, have each already passed legislation addressing online harms. As such, this regulatory landscape is changing rapidly and becoming increasingly vigorous. The extent of the obligations (at least in certain jurisdictions) and enforcement practices are likely to remain uncertain for the foreseeable future. These laws and regulations may be interpreted and applied differently over time and from jurisdiction to

43

Table of Contents

jurisdiction, and it is possible that they will be interpreted and applied in ways that may have a material adverse effect on our business, financial condition, results of operations and prospects.

Furthermore, following the expiration of the specified period, there will be increasing scope for divergence in application, interpretation and enforcement of the data protection law as between the U.K. and the EU. Other jurisdictions outside the EU are similarly introducing or enhancing privacy and data security laws, rules and regulations, which could increase our compliance costs and the risks associated with non-compliance. We cannot guarantee that we are, or will be, in compliance with all applicable international regulations as they are enforced now or as they evolve.

All of these evolving compliance and operational requirements impose significant costs, such as costs related to organizational changes, implementing additional protection technologies, training employees and engaging consultants, which are likely to increase over time. In addition, such requirements may require us to modify our online and e-commerce practices and policies, distract management or divert resources from other initiatives and projects, all of which could have a material adverse effect on our business, financial condition, results of operations and prospects. Any failure or perceived failure by us to comply with any applicable federal, state or similar foreign laws and regulations in this area could result in damage to our reputation, as well as proceedings or litigation by governmental agencies or other third parties, including class action litigation in certain jurisdictions, which could subject us to significant fines, sanctions, awards, injunctions, penalties or judgments. Any of the foregoing could have a material adverse effect on our business, results of operations, financial condition and prospects.

Risks Related to Our Corporate Structure

You may face difficulties in protecting your interests, and your ability to protect your rights through U.S. courts may be limited, because we are incorporated under Cayman Islands law.

We are an exempted company incorporated under the laws of the Cayman Islands. Our corporate affairs are governed by our memorandum and articles of association, the Companies Act (As Revised) of the Cayman Islands, which we refer to as the Companies Act below, and the common law of the Cayman Islands. The rights of shareholders to take action against our directors, actions by our minority shareholders and the fiduciary duties of our directors to us under Cayman Islands law are to a large extent governed by the common law of the Cayman Islands. The common law of the Cayman Islands is derived in part from comparatively limited judicial precedent in the Cayman Islands as well as from the common law of England, the decisions of whose courts are of persuasive authority, but are not binding, on a court in the Cayman Islands. The rights of our shareholders and the fiduciary duties of our directors under Cayman Islands law are not as clearly established as they would be under statutes or judicial precedent in some jurisdictions in the U.S. In particular, the Cayman Islands have a less developed body of securities laws than the U.S. Some U.S. states, such as Delaware, have more fully developed and judicially interpreted bodies of corporate law than the Cayman Islands. In addition, Cayman Islands companies may not have standing to initiate a shareholder derivative action in a federal court of the U.S.

Shareholders of Cayman Islands exempted companies like us have no general rights under Cayman Islands law to inspect corporate records (other than the memorandum and articles of association and any special resolutions passed by such companies, and the registers of mortgages and charges of such companies) or to obtain copies of lists of shareholders of these companies. Our directors have discretion under our articles of association to determine whether or not, and under what conditions, our corporate records may be inspected by our shareholders, but are not obliged to make them available to our shareholders. This may make it more difficult for you to obtain the information needed to establish any facts necessary for a shareholder motion or to solicit proxies from other shareholders in connection with a proxy contest.

As a result of all of the above, our public shareholders may have more difficulties in protecting their interests in the face of actions taken by our management, our board of directors or controlling shareholders than they would as public shareholders of a company incorporated in the U.S.

Risks Related to Doing Business in China

We could be adversely affected by political tensions between the U.S. and the PRC.

During 2018 and 2019, both the PRC and the U.S. each imposed tariffs that have adversely affected trade between the two countries. Although the U.S. and the PRC reached a Phase One trade deal in January 2020, there was no Phase Two trade deal implemented and most of the tariffs imposed remain in place, while uncertainty persists in the trade relationship between the two countries that impacts the global trade landscape. Although most of third-party suppliers for

44

Table of Contents

our 1P inventory are located in Southeast Asian countries and our 3P sellers are typically responsible for any export taxes and tariffs, we are unable to predict whether any of the countries in which our suppliers’ products are currently manufactured or may be manufactured in the future will be subject to new, different or additional trade restrictions imposed by the U.S. or foreign governments or the likelihood, type or effect of any such restrictions.

Political tensions between the U.S. and the PRC have escalated due to, among other things, trade disputes, the COVID-19 outbreak, sanctions imposed by the U.S. Department of Treasury on certain officials of the Hong Kong Special Administrative Region and the central government of the PRC, U.S. export restrictions regarding China, restrictions on U.S. investments in designated “Communist Chinese Military Companies,” and the executive orders issued by former U.S. President Donald J. Trump that seek to prohibit certain transactions with ByteDance Ltd., Tencent Holdings Ltd., developers of certain software applications and the respective subsidiaries of such companies, as well as the Rules on Counteracting Unjustified Extra-territorial Application of Foreign Legislation and Other Measures promulgated by China’s Ministry of Commerce, or MOFCOM, on January 9, 2021, which will apply to situations where the extra-territorial application of foreign legislation and other measures, in violation of international law and the basic principles of international relations, unjustifiably prohibits or restricts the citizens, legal persons or other organizations of China from engaging in normal economic, trade and related activities with a third State (or region) or its citizens, legal persons or other organizations. Rising political tensions could reduce levels of trades, investments, technological exchanges and other economic activities between the two major economies, which would have a material adverse effect on global economic conditions and the stability of global financial markets. Any of these factors could have a material adverse effect on our business, prospects, financial condition and results of operations. Furthermore, there have been recent media reports on deliberations within the U.S. government regarding potentially limiting or restricting companies with operations in the PRC from accessing U.S. capital markets. If any such deliberations were to materialize, the resulting legislation may have a material and adverse impact on the stock performance of issuers with operations in the PRC listing in the U.S. It is unclear if this proposed legislation would be enacted.

A substantial part of our revenues is derived from the U.S., and we are required to comply with the U.S. laws and regulations. However, we may be affected by future changes in the U.S. export control and other laws and regulations. If we were unable to transfer our parcels to and out of the U.S., our business, results of operations and financial condition would be materially and adversely affected.

Changes in the political and economic policies of the PRC government may materially and adversely affect our business, financial condition and results of operations and may result in our inability to sustain our growth and expansion strategies.

Our PRC Subsidiaries primarily perform cost functions and internal operational functions. Accordingly, our business, financial condition and results of operations are affected to an extent by economic, political and legal developments in the PRC.

The PRC economy differs from the economies of most developed countries in many respects, including the extent of government involvement, level of development, growth rate, control of foreign exchange and allocation of resources. Although the PRC government has implemented measures emphasizing the utilization of market forces for economic reform, the reduction of state ownership of productive assets and the establishment of improved corporate governance in business enterprises, the PRC government continues to play a significant role in regulating industry development by imposing industrial policies. While the PRC economy has experienced significant growth in the past decades, growth has been uneven, both geographically and among various sectors of the economy. The PRC government has implemented various measures to encourage economic growth and guide the allocation of resources. Some of these measures may benefit the overall PRC economy, but may also have a negative effect on us. Our financial condition and results of operations could be materially and adversely affected by government control over capital investments or changes in tax regulations that are applicable to us. In addition, the PRC government has implemented in the past certain measures to control the pace of economic growth. These measures may cause decreased economic activity, which in turn could lead to a reduction in demand for any of our potential products, and consequently have a material adverse effect on our businesses, financial condition and results of operations.

There are uncertainties regarding the PRC legal system.

A portion of our business operations is conducted in the PRC as our PRC Subsidiaries primarily perform cost functions and internal operational functions in the PRC and is governed by PRC laws, rules and regulations. Our PRC Subsidiaries are subject to laws, rules and regulations applicable to foreign investment in the PRC. The PRC legal system is

45

Table of Contents

a civil law system based on written statutes. Unlike the common law system, prior court decisions may be cited for reference but have limited precedential value.

In 1979, the PRC government began to promulgate a comprehensive system of laws, rules and regulations governing economic matters in general. The overall effect of legislation over the past four decades has significantly enhanced the protections afforded to various forms of foreign investment in the PRC. However, the PRC's legal system is developing, and recently enacted laws, rules and regulations may not sufficiently cover all aspects of economic activities in the PRC or may be subject to interpretation by PRC regulatory agencies. In particular, because these laws, rules and regulations are relatively new, and because of the limited number of published decisions and the nonbinding nature of such decisions, and because the PRC laws, rules and regulations sometimes give the relevant regulator discretion in how to enforce them, the interpretation and enforcement of these laws, rules and regulations involve uncertainties. In addition, the PRC legal system is based in part on government policies and mainland China is geographically large and divided into various provinces and municipalities. As such, different policies and rules may have different application and interpretations in different area of mainland China, and it is possible that we may not be aware of our violation of these policies and rules until after the occurrence of the violation.

Any administrative and court proceedings in the PRC may result in substantial costs and diversion of resources and management attention. Since PRC administrative and court authorities have discretion in interpreting and implementing statutory and contractual terms, it may be difficult to evaluate the outcome of administrative and court proceedings and the level of legal protection we enjoy . These uncertainties may impede our ability to enforce the contracts we have entered into and could materially and adversely affect our business, financial condition and results of operations.

We operate our GigaCloud Marketplace through our Hong Kong Subsidiary. If the PRC government were to extend its oversight into companies in Hong Kong, our Hong Kong Subsidiary may be subject to additional regulations which could have a material effect on our business operations.

We launched our GigaCloud Marketplace under our Hong Kong Subsidiary, GigaCloud Technology (HongKong) Limited (formerly known as Giga Cloud Logistics (Hong Kong) Limited), in 2019. Our PRC Subsidiaries perform cost functions and internal operational functions, but our PRC Subsidiaries do not generate revenue in mainland China, except for the revenue generated from inter-group related party transactions. Accordingly, the laws and regulations of the PRC have an impact on the operational and procurement aspects of our business. Pursuant to the Basic Law of the Hong Kong Special Administrative Region, or the Basic Law, which is a national law of the PRC and the constitutional document for Hong Kong, national laws of the PRC shall not be applied in Hong Kong except for those listed in Annex III of the Basic Law (which shall be confined to laws relating to defense and foreign affairs as well as other matters outside the autonomy of Hong Kong). Whilst the National People’s Congress of the PRC, or the NPC, has the power to amend the Basic Law, the Basic Law also expressly provides that no amendment to the Basic Law shall contravene the established basic policies of the PRC regarding Hong Kong. As a result, national laws of the PRC not listed in Annex III of the Basic Law, including the PRC Data Security Law and the Measures for Cybersecurity Review, do not apply to our businesses in Hong Kong, other than those provisions of the PRC laws which apply to activities conducted outside of mainland China.

As of the date of this annual report, our Hong Kong Subsidiary has not received any inquiry or notice or any objection from any PRC authority in connection with our operations in Hong Kong. In light of recent statements and regulatory actions by the PRC government related to the PRC’s extension of authority into Hong Kong, there is risk that the PRC government may influence our operations in Hong Kong, as our operations in Hong Kong are subject to political and economic influence from the PRC government. Our Hong Kong Subsidiary may be subject to such direct influence from the PRC government in the future due to changes in laws or other unforeseeable reasons. If certain PRC laws and regulations, including existing laws and regulations and those enacted or promulgated in the future, were to become applicable to our Hong Kong Subsidiary in the future, the application of such laws and regulations may have a material adverse impact on our business operations in Hong Kong. For example, if the PRC Data Security Law were to apply to our Hong Kong Subsidiary, our Hong Kong Subsidiary may be subject to more data security and privacy obligations imposed by the PRC government, and our Hong Kong Subsidiary may be required to obtain licenses for the operation of our ecommerce platform GigaCloud Marketplace and be subject to regulations restricting or prohibiting foreign ownership. Further, the rules and regulations and the enforcement thereof in China can change quickly. In light of recent statements and regulatory actions by the PRC government related to the PRC’s extension of authority into Hong Kong, there is also risk that the PRC government may influence our operations in mainland China and Hong Kong and that our Hong Kong Subsidiary and PRC Subsidiaries may be subject to such direct influence in the future due to changes in laws or other unforeseeable reasons. Any such actions by the PRC government to exert more oversight and control over offerings that are conducted overseas and/or foreign investment in mainland China- and Hong Kong-based issuers could significantly change

46

Table of Contents

our Hong Kong Subsidiary’s ability to conduct its business and operate our GigaCloud Marketplace in its current form, which could result in a material change in our operations, significantly limit or completely hinder our ability to offer or continue to offer securities to investors and cause the value of our securities to significantly decline or in extreme cases, become worthless.

Implementation of the Law of the PRC on Safeguarding National Security in Hong Kong involves uncertainty, and the recent policy pronouncements by the PRC government regarding business activities of U.S.-listed PRC businesses may negatively impact GigaCloud Group’s existing and future operations in Hong Kong.

On June 30, 2020, the Standing Committee of the NPC promulgated the Law of the PRC on Safeguarding National Security in Hong Kong. The interpretation of the Law of the PRC on Safeguarding National Security in Hong Kong involves a degree of uncertainty.

Recently, the PRC government announced that it would step up supervision of overseas-listed PRC businesses. Under the new measures, the PRC government will enhance regulation of cross-border data transmission and security, crack down on illegal activity in the securities market and punish fraudulent securities issuance, market manipulation and insider trading. The PRC government will also check sources of funding for securities investment and control leverage ratios. The PRC government has also opened a probe into several U.S.-listed technology companies focusing on anti-monopoly, financial technology regulation and more recently, with the passage of the PRC Data Security Law, how companies collect, store, process and transfer personal data. Currently these laws (other than the Law of the PRC on Safeguarding National Security in Hong Kong) are expected to apply to mainland China domestic businesses, rather than businesses in Hong Kong, which operate under a different set of laws from mainland China. However, there can be no assurance that the government of Hong Kong will not enact similar laws and regulations applicable to companies operating in Hong Kong.

GigaCloud Group is a pioneer of global end-to-end B2B ecommerce solutions for large parcel merchandise and our global marketplace seamlessly connects manufacturers, primarily in Asia, with resellers, primarily in the U.S., Asia and Europe. We also operate warehouses in five countries across the U.S., Japan, the U.K., Germany and Canada. Although none of our business activities appears to be within the current targeted areas of concern mentioned above by the PRC government, in light of the recent statements and regulatory actions by the PRC government related to the PRC's extension of authority into Hong Kong, there are risks and uncertainties which we cannot foresee for the time being. For example, the government of Hong Kong may enact similar laws and regulations as those in the PRC, which may seek to exert control over offerings conducted overseas by Hong Kong companies. If any or all of the foregoing were to occur, it could lead to a material adverse change in GigaCloud Group’s operations and limit or hinder our ability to offer securities to overseas investors or remain listed in the U.S., which could cause the value of our securities to significantly decline or become worthless.

If the approval, filing or other administration requirements of the China Securities Regulatory Commission, or the CSRC, the CAC, or other PRC governmental authorities are applicable to our offshore securities offerings, we cannot assure you that we will be able to obtain such approvals or complete such filings. In addition, complex regulatory procedures applicable to foreign investors conducting acquisitions in China could make it difficult for us to grow through acquisitions.

On August 8, 2006, six PRC regulatory agencies, including the MOFCOM, the State-Owned Assets Supervision and Administration Commission, the State Taxation Administration of PRC, or the SAT, the State Administration for Industry and Commerce, currently known as the State Administration for Market Regulation, or the SAMR, the CSRC, and the State Administration of Foreign Exchange, or the SAFE, jointly adopted the Regulations on Mergers and Acquisitions of Domestic Enterprises by Foreign Investors, or the M&A Rules, which came into effect on September 8, 2006 and were amended on June 22, 2009. The M&A Rules include, among other things, provisions that purport to require that an offshore special purpose vehicle that is controlled by PRC domestic companies or individuals and that has been formed for the purpose of an overseas listing of securities through acquisitions of PRC domestic companies or assets to obtain the approval of the CSRC prior to the listing and trading of such special purpose vehicle’s securities on an overseas stock exchange. The interpretation and application of the M&A Rules remain unclear, and our offshore offerings may ultimately require approval of the CSRC under the M&A Rules. If the CSRC approval under the M&A Rules is required, it is uncertain whether we can or how long it will take us to obtain the approval and, even if we obtain such CSRC approval, the approval could be rescinded. Any failure to obtain or delay in obtaining the CSRC approval for any of our offshore offerings under the M&A Rules, or a rescission of such approval if obtained by us, would subject us to

47

Table of Contents

sanctions imposed by the CSRC or other PRC regulatory authorities that may materially and adversely affect our business, financial condition, and results of operations.

On February 17, 2023, the CSRC promulgated the Trial Measures for Overseas Listing and the Guidelines for Overseas Listing, or the Filing Rules, which became effective on March 31, 2023. According to the Filing Rules, a PRC domestic company that seeks to offer and list securities in overseas markets are required to fulfill the filing and reporting requirements with the CSRC if it meets both of the following criteria: (i) any of the operating revenue, total profits, total assets or net assets of the PRC Subsidiaries accounts for more than 50% of the corresponding item in its audited consolidated financial statements for the most recent fiscal year ; and (ii) the main parts of its operating activities are conducted in mainland China, or the principal operation premises are located in mainland China, or the majority of senior management personnel in charge of its business operations and management are PRC citizens or have habitual residences located in mainland China. While we do not believe we satisfy either of the criteria, the Filing Rules further stipulate that the applicability of the Filing Rules shall be determined on a substance-over-form basis. Given that the Filing Rules were recently promulgated, there are uncertainties as to the implementation and interpretation, and how they will affect our future offerings and other financing activities. Particularly, if we are subject to the Filing Rules, we will be required to submit post-issuance filings with respect to our follow-on offerings, issuance of convertible and exchangeable bonds, and other equivalent offering activities. In addition, if we are subject to the Filing Rules but fail to complete such filings with the CSRC in a timely manner or at all, our ability to raise capital through future offering or financing activities will be impacted.

On December 28, 2021, the CAC, together with other authorities, jointly promulgated the Measures for Cybersecurity Review, which became effective on February 15, 2022 and simultaneously superseded and replaced the cybersecurity review measures that had been in effect since June 2020. According to the Measures for Cybersecurity Review, network platform operators possessing personal information of more than one million users if such operators seek to list on a foreign stock exchange will be subject to the cybersecurity review. In addition, relevant PRC regulatory authorities may initiate cybersecurity review if they determine that an operator’s network products or services or data processing activities affect or may affect national security.

On November 14, 2021, the CAC published the Draft Network Data Security Regulations for public comments. In accordance with the Draft Network Data Security Regulations, data processors that process “important data” or are listed overseas must conduct an annual data security assessment, either by itself or through a data security service provider, and must submit the assessment report of a given year to the relevant municipal cybersecurity department by the end of January of the following year. As of the date of this annual report, the Draft Network Data Security Regulations have been released for public comment only, and its final provisions and adoption are subject to uncertainties.

As of the date of this annual report, we have not been involved in any formal investigations on cybersecurity or data security initiated by related governmental regulatory authorities, and we have not received any inquiry, notice, warning or sanction in such respect. However, as the Measures for Cybersecurity Review were newly adopted, and the Draft Network Data Security Regulations have not been adopted, there remains uncertainty in the interpretation and enforcement of such PRC cybersecurity and data security laws and regulations. Thus, we cannot assure you whether we would be subject to a cybersecurity review requirement, and if so, that we would be able to pass such review. If the authorized PRC regulatory body subsequently determines that we are required to go through such cybersecurity review or if any other PRC government authorities promulgate any interpretation or implementation rules that would require us to go through a cybersecurity review, we may fail to complete such cybersecurity review procedures in a timely manner, or at all. Any failure or delay in the completion of the cybersecurity review procedures or any other non-compliance with the related laws and regulations may result in fines or other penalties, including suspension of business and website closure as well as reputational damage or legal proceedings or actions against us, which may have a material adverse effect on our business, financial condition or results of operations.

Given that the Measures for Cybersecurity Review and the Filing Rules, were newly adopted, and the Draft Network Data Security Regulations has not been adopted, it remains unclear how these laws and regulations will be interpreted, amended and implemented by the relevant PRC governmental authorities, and there remains uncertain in PRC governmental authorities' regulation of overseas listings in general and whether we are required to obtain any specific regulatory approvals or to fulfill any record-filing requirements. As of the date of this annual report, we have not received any inquiry or notice or any objection from the CSRC, the CAC or any other PRC authorities that have jurisdiction over our operations in mainland China and Hong Kong. However, there remains uncertainty regarding the interpretation and enforcement of those newly enacted PRC laws.

48

Table of Contents

These regulations also established additional procedures and requirements that are expected to make merger and acquisition activities in the PRC by foreign investors more time-consuming and complex. For example, the M&A Rules require that the MOFCOM be notified in advance of any change-of-control transaction in which a foreign investor takes control of a PRC domestic enterprise if (i) any important industry is concerned, (ii) such transaction involves factors that have or may have impact on the national economic security, or (iii) such transaction will lead to a change in control of a domestic enterprise which holds a famous trademark or PRC time-honored brand. The approval from the MOFCOM shall be obtained in circumstances where overseas companies legitimately established or controlled by PRC enterprises or residents acquire affiliated domestic companies. Mergers, acquisitions or contractual arrangements must also be notified in advance to the anti-monopoly authority under the PRC State Council when the threshold under the Provisions on Thresholds for Prior Notification of Concentrations of Undertakings issued by the PRC State Council in August 2008 and amended respectively in September 2018 and January 2024, is triggered. In addition, the security review rules issued by the MOFCOM that became effective in September 2011 specify that mergers and acquisitions by foreign investors that raise “national defense and security” concerns and mergers and acquisitions through which foreign investors may acquire de facto control over domestic enterprises that raise “national security” concerns are subject to strict review by the MOFCOM, and the rules prohibit any activities attempting to bypass a security review, including by structuring the transaction through a proxy or contractual control arrangement.

Source: SEC EDGAR (public domain) · 10-K for the period ended 2023-12-31, filed 2024-03-27 · accession 0001857816-24-000066

Filing HTML rendered to line-structured narrative text by the shipped reducer (datafeeds.edgar_fulltext.visible_text, keep_table_headers=True): scripts and inline-XBRL headers are dropped, and table content is reduced to its short label cells — numeric table data is not rendered and is therefore not counted. The same rendering is used for every year, so a year-over-year comparison is like for like.

The text is our rendering of the filing, not a facsimile: original pagination, typography and tables are not reproduced, and the numbers live in the financial statements (FA).

The outline locates item HEADINGS in this document. Only Items 1A and 7 have certified boundaries elsewhere in the terminal (the redline and the narrative-overlap number); every span here runs from one heading found to the next heading found.

How the outline was chosen. It is the longest chain of item headings that runs forward through both the document and the standard item order: 23 headings are on that chain and 17 further heading-shaped lines are not — the table-of-contents echo of every item, cross-references and exhibit-list mentions. Each entry's length is measured from its heading to the next heading on the chain.