Guide Posted by the DataCops team

Facebook pixel sending health data: how page URLs and event names give it away

Short answer

The pixel passes along the page URL, title and event name, and you cannot tell it what to leave out. Moving to the server and cleaning each event lets you decide what leaves.

The Meta pixel is a very obedient piece of code. That's the problem.

A browser pixel passes along whatever it finds on the page. You can't tell it "send the booking, but leave out what the booking is for". It sends what it sees, faithfully, every time. So let's look at what it typically sees on a clinic site, because most people have never looked.

The address bar. Something like yourclinic.com/treatments/acne-scarring/book. That whole path is sent with the event. The visitor's condition is spelled out in the link.

The page title. "Weight Loss Programme: Book a Consultation". Sent.

The button or form text. Sometimes sent, depending on how the pixel is set up.

The event name. If someone set up a custom event, it's often named after the service: Book_Implant_Consult, Scalp_Treatment_Lead. That reads as health information the moment it leaves your site.

Any of those can be enough for Meta to hold back or drop the event. And because the pixel is doing exactly what it was built to do, nothing looks broken on your side. That's what makes it so hard to diagnose.

There's a mental model that helps. Think of every event as a postcard. The pixel writes on it whatever it can find: where the person was, what the page said, what the button was called. Then it posts it. You never see the postcard. And nobody asked whether the postcard should say what someone is being treated for.

How do you see the postcard? Open Events Manager, go to Test Events, and trigger a booking on your own site. Read the parameters as if you were seeing them for the first time. The URL parameter is usually the eye-opener.

Why does it keep coming back after you fix it? Because the pixel is on every page, and every page is a chance. A new landing page for a new treatment. A plugin update that adds the page title. A marketer who creates a custom event with a helpful name. None of these feel like privacy decisions, so nobody reviews them.

What to do about it, in a sensible order. Move the sending from the browser to your server, so you decide what goes. Cut the link down to the domain, so no treatment path travels. Use neutral event names, so the name reveals nothing. Send hashed email and phone, and keep anything else that could describe a person's health out of the event. And keep a record of what you sent, so the next review is a lookup, not a hunt.

Let me walk one booking event field by field and give each a rough risk rating, so you can see where the danger sits.

Page URL: high. It's the most descriptive field and the one most often carrying a treatment name.

Page title: high. Often more descriptive than the URL, and easy to overlook.

Event name: high if named after a service, low if neutral.

Referrer, meaning the page they came from: medium. A collection or category page can carry a condition.

Hashed email and phone: low. They identify a person, and they're what matching needs.

The ad click ID: low. It identifies a click.

IP address and user agent: low to medium. Standard for matching, and not descriptive of health.

Custom fields and form values: high if they're clinical, and the hardest to justify.

Notice the pattern. The high-risk fields are the descriptive ones, and the low-risk fields are the ones matching actually uses. That's why you can clean without losing the signal: the parts that cause trouble aren't the parts that do the work.

What did your Test Events show that surprised you?

For reference, DataCops cuts the link to the domain and renames the event before it leaves, and the delivery log lets you open a purchase and check the product name isn't in it.

DataCops in short

For this question: Server-side sending with Health mode means the page URL and title are cleaned on the way out, so you decide what Meta receives instead of the pixel passing everything along.

DataCops is a tool that keeps condition details out of what your ad platforms see: Health mode cuts page links to the domain, uses neutral event names and leaves out anything that describes a condition, while a bot verdict on every visit and a delivery log show what left and what was real.

How DataCops does it

  • Health mode. Page links are cut to the domain, event names are neutral, and anything that describes a condition is left out before an event leaves.
  • A log of exactly what left. A delivery log row per conversion, sent, held, skipped or failed, with the reason, which is the record you want when explaining yourself to a reviewer.
  • Real people only. Every visit gets a bot verdict against 360+ billion IPs and 350+ monitoring points, with a Real people only switch per ad platform, off by default.
  • One script, one DNS record. Collection runs on your own domain, and conversions go server-side to Meta, Google Ads, TikTok and LinkedIn, counted once against the pixel.
  • The booking after the form. HighLevel natively, any CRM by webhook, sent as neutral events so a booked consultation still teaches the ads who converts.

Best for: clinics, telehealth and wellness brands, and agencies running health ads, who want conversions to keep counting without condition details in the data.

Ads Warmup: tell the ads who pays

Ads Warmup, DataCops' flagship feature, sends customers you already have to Meta, Google Ads and TikTok before a new campaign spends: upload a CSV (only email is required, up to 20,000 rows), see a 0 to 10 match score per person, pick the event, and send. Rows are dated when you send, and Google Ads credits only people who clicked a Google ad. Preview is free; sending needs a paid plan. Check your own consent basis for the list first. See Ads Warmup.

Ways to do this job

OptionBest for
DataCopsHealth mode, neutral events and a delivery log, server-side to four ad platforms
Manual event cleanup in your site and tag managerTeams with an engineer who will maintain it
Turning conversion tracking offAccounts that cannot risk any event

When not to use DataCops

  • You need legal or compliance advice. DataCops is not legal advice and does not make an ad account compliant. Your own advisers decide what you may send.
  • You need a regulated setup with a signed agreement. That is the Enterprise plan: talk to the team.

More on this: Meta health and wellness restrictions, and the complete guide to offline conversion tracking.

1 comment

Comments (1)

DataCops team author · 30 Sep 2026

If you only fix one thing today, fix the URL. It's the easiest to spot, the easiest to leak, and the easiest to cut.

1
Replies from DataCops account holders are coming soon. Until then, questions about your own setup can go to the team.

More threads

See what your own setup is missing

Send CRM sales back to the ad click that started them, logged per send.

Setup in 5 minutes. No credit card.

Live traffic quality

Updated just now

Visits · last 24h

487
Real users
35873.5%
Bots · auto-filtered
12926.5%

Without filtering, 26.5% of your reported traffic is bot noise inflating dashboards and draining ad spend.

Don't trust your analytics!

Make confident, data-driven decisions withactionable ad spend insights.

Setup in 2 minutes
No credit card