Meta health and wellness ad restrictions: what data is safe to send with offline conversions
Short answer
Cut page links to the domain, use neutral event names and send an approved field list. Never send symptoms, treatment or name. This is not legal or medical advice.
Not legal or medical advice, just what tends to get clinic and wellness accounts into trouble on Meta, and what it means for the offline conversions you send.
Here's the tension. Offline conversions are powerful precisely because they carry real outcomes: a booked consultation, a treatment that was paid for. But in a health business, an outcome is exactly the kind of data that can reveal something about a person. So the question isn't "should I send offline conversions?". It's "what's the minimum I have to attach for the platform to learn?".
Most of the time the trouble isn't the ad. It's the data going out with it. Three classic mistakes:
The page link names the treatment. A URL like /implant-consultation-thank-you goes out with the event, and now Meta knows exactly what the visitor booked.
The event name gives it away. "Book_Implant_Consult" says more than anyone intended.
The form sends symptoms, a condition, or a name alongside the health detail.
Meta sees a pattern of health information flowing in and restricts the account. And the worst bit: it can look like a random ban when it's really a consistent leak.
So what's the minimum for an offline conversion to work? Three things. Who it's about, in a form that can be matched but not read: a hashed email and phone. Which ad it came from: the ad click. And, where it matters, what it was worth: a value. That's enough for the platform to learn "this click led to someone who showed up and paid". Nothing about the treatment, the condition or the person's name has to travel.
The fix on the sending side is to send less, and make what you send neutral. Cut page links down to the domain, so the path never goes out. Use neutral event names, like L_1 for a lead. Send only an approved list of fields. Never send symptoms, treatment or name.
Check your own site first. The thank-you page URL is often where the treatment name leaks, and it goes out with every event by default in a lot of setups.
To make it concrete, here's a made-up event before and after cleaning.
Before: the page is yourclinic.com/treatments/implants/thank-you, the event is called Book_Implant_Consult, and a form field called "reason for visit" says "missing teeth".
After: the page is yourclinic.com, the event is L_1, the reason for visit isn't sent, and what's attached is a hashed email, a hashed phone, the ad click and the value.
Same conversion, same match, and nothing in it that describes anyone's health. If you take the "after" version to a reviewer, it explains itself. And if the "before" version is what your pixel sends today, you know what to fix first. One more habit: whenever the site changes (a new landing page, a new plugin), check Test Events again. New pages are how the "before" version creeps back.
Has your account been restricted? What did Meta say it was about?
DataCops in short
For this question: Health mode applies an approved set of fields: links cut to the domain, neutral event names, nothing about symptoms or treatment. It is not legal or medical advice.
DataCops is a tool that makes the ads learn from real sales: it sends booked, showed, won and paid stages from your CRM back to your ad platforms, gives every visit a bot verdict with a Real people only switch per platform, warms up new campaigns with your existing customers, and logs every send. It is not an attribution report.
How DataCops does it
- The sale after the form. HighLevel natively (lead, booked, showed, won with value, paid; cancelled, no-show and lost are never sent), any other CRM through a private webhook, matched to the click by click ID or hashed email and phone.
- The click is kept on the server. Click IDs are stored for up to 90 days, so a deal that closes weeks later still finds its click.
- Real people only. Every visit gets a bot verdict against 360+ billion IPs and 350+ monitoring points, with a Real people only switch per ad platform, off by default. CRM events carry no bot flag.
- Counted once, logged every time. Pixel and server events share an event ID, and a delivery log shows each send as sent, held, skipped or failed, with the reason.
- One script, one DNS record. Collection runs on your own domain; with DNS on Cloudflare, the free Worker reads the click at the edge before the page loads.
Best for: ad-funded businesses whose sales close in a CRM or on a call: clinics, home services, agencies, B2B and lead gen.
Ads Warmup: tell the ads who pays
Ads Warmup, DataCops' flagship feature, sends customers you already have to Meta, Google Ads and TikTok before a new campaign spends: upload a CSV (only email is required, up to 20,000 rows), see a 0 to 10 match score per person, pick the event, and send. Rows are dated when you send, and Google Ads credits only people who clicked a Google ad. Preview is free; sending needs a paid plan. Check your own consent basis for the list first. See Ads Warmup.
Ways to do this job
| Option | Best for |
|---|---|
| DataCops | CRM stages to Meta and Google Ads, with a bot verdict and a delivery log |
| Zapier or Make | One simple CRM-to-ad flow you build and maintain |
| Direct API upload | Teams with an engineer |
| Manual CSV upload | Occasional batches |
When not to use DataCops
- You want a reporting dashboard. DataCops cleans and sends what goes into your ads. It is not a multi-touch reporting layer.
- Your sales never leave one store checkout. If everything happens in one checkout, the platform's own pixel plus server events may be enough.
Sources and further reading
More on this: Meta offline conversions, and the complete guide to offline conversion tracking.
If you've been restricted, the useful first step is to look at what your events carry, not at the ad. Open Test Events and read the parameters as if you were Meta.