Guide · Updated · 24 min read

Meta restricted a health store. The full story, and how to recover.

How Meta's health and wellness restrictions work, what happened to a real store in five weeks, and the plan we ran, step by step.

The short answer

Meta restricts the data that health and wellness websites can send it. It classifies the whole domain, then limits what it accepts in three levels: first it strips links and custom details, then it blocks standard events such as Purchase and Lead, and at the worst level it blocks every event, sometimes only in certain regions. At the first two levels a store can keep Meta learning by sending neutral, clean events from a server. At the full level no tool gets through. Speed decides most of the outcome: what you stop sending in the days after the warning matters more than anything you try after the block.

DataCops is the tracking solution for ad-funded businesses. For health and wellness advertisers, its Health mode sends Meta only what it needs to count a sale, with nothing about the condition, the product or the page, so a store stops feeding the restriction and keeps a clean signal wherever Meta still accepts one.

How DataCops handles a health store:

  • A fixed allowlist. Every conversion passes through one cleaning step. Paths, query strings, the referrer, page titles, product and content names, cart items and form answers never leave the site.
  • Neutral event names. A purchase reaches Meta as P_1, a lead as L_1, a booking as S_1. The name says nothing about the service.
  • Server-side, with matching kept. The click ID and hashed email and phone still go, so Meta can match a sale without learning what was bought.
  • Detection. When you connect an ad platform, DataCops reads your homepage and switches Health mode on when it is confident the site is a health business. It never switches it off.
  • Proof. The delivery log marks every cleaned send, so you can show what left your site and when.
  • Your own count. Click IDs stay on the server for up to 90 days, so you can count Meta-sourced sales even where Meta cannot.

Best for: supplement, maternity, telehealth, clinic, med spa, weight loss and mental health businesses that advertise on Meta, and any store that has just received the warning.

This guide does two jobs. It explains the whole category, so you understand what Meta is doing, why, and where your own business sits. And it walks through a case we handled ourselves in September and October 2026: a maternity clothing store that went from a warning email to a blocked account in five weeks. We have removed the store's name and anything that would identify it. Everything else is what happened, including what we got right, what was already too late, and the decision we had to make when the news got worse.

If you are reading this because the warning has just arrived, jump to the day the warning arrives and come back later. If you are already blocked, start with the three levels, because your level decides everything that follows.

What are Meta's health and wellness restrictions?

They are limits on the data a website or app can send to Meta once Meta decides that the site belongs to a sensitive category. Health and wellness is the largest of those categories, and the one most advertisers run into.

The unit Meta classifies is the data source: your website domain or your app. It does not judge one ad or one pixel. Once a domain is in a restricted category, everything that comes from it is treated the same way, whether it arrives from the browser pixel or from the Conversions API on your server. Stape, which sells server-side tracking, says it plainly in its own write-up: the Conversions API does not bypass the data sharing rules. A server is not a way around the restriction. It is only a better place to clean the data before it leaves.

Behind the restrictions sit Meta's own terms. The Meta Business Tools Terms tell businesses not to send Meta data that includes or is based on health information. Meta's Business Help Center lists what it counts as sensitive health information: diseases, conditions and injuries; sexual and reproductive health; mental health; medical devices and health trackers; procedures, treatments and testing; medications and supplements; and places that point to treatment. Meta also says it runs a filter designed to stop data it sees as potentially sensitive from reaching its ad ranking and optimisation systems.

The restriction is the heavy version of that filter. Instead of dropping one suspicious field, Meta limits what the whole source is allowed to send.

Why does Meta do this?

Because health data is the kind of data that gets companies into serious trouble, and ad platforms run on data about people. In 2023 the US Federal Trade Commission took action against GoodRx and against BetterHelp over health information that reached advertising platforms, Facebook among them. Those cases were about the businesses that sent the data, but they made every ad platform look hard at what it was receiving.

Meta's response, rolled out from early 2025 according to the vendors who track it, was to classify data sources automatically and restrict the ones in sensitive categories. It does not ask whether you meant to send health information. It looks at what arrives and at what your site says, and it decides.

Keep that frame for the rest of this guide. Meta is not punishing you, and nobody is reviewing your intentions. A system is reading your data and asking one question: does this tell us something about a person's health? Everything that works is a way of making sure the honest answer is no, because you have stopped sending what it was reacting to.

Meta does not judge what you sell. It judges what your data says about the person who bought it.

Which businesses does Meta treat as health?

Far more than clinics. The vendor reports we studied, and the cases we have seen, put these businesses in the exposed group. The third column matters most, because it tells you where to look first.

BusinessWhy Meta reads it as healthWhere the risky detail usually sits
Supplements and vitaminsSupplements are on Meta's own listProduct names, ingredient and benefit claims
Weight loss and GLP-1Treatments and body measuresDrug names in links and products, before-and-after language
Telehealth and online pharmacyConditions and prescriptionsCondition pages and intake forms
Clinics, dental and med spasProcedures and treatmentsBooking links with the treatment in the path
Mental health and therapyMental healthService names and form answers
Fertility, pregnancy and maternityReproductive healthProduct titles, image alt text, gender and date of birth
Sexual wellnessSexual healthProduct and collection names
Skincare for conditionsConditions such as acne or rosaceaClaims and collection names
Braces, supports, sleep and pain productsBody conditions and painClaims about relieving pain or pressure

The grey zones are where most surprises happen. A skincare brand selling a glow routine is usually fine, and the same brand with an acne collection may not be; we wrote about where skincare crosses the line. A clothing store is fine until the clothing is for pregnancy. A fitness brand is fine until a product promises to fix a back.

A simple test works better than any list: could someone reading your events guess something about a customer's body, condition or treatment? If the answer is yes, plan as if you are already on Meta's list.

How does Meta decide your site is health?

Meta does not publish its classifier, so nobody outside Meta can give you the complete list. What the vendor reports agree on, and what we saw ourselves, is that it reads from these places:

  • The text on your site. Product titles, collection names, headings, claims and the meta description.
  • Image alt text. The hidden descriptions behind images, which often hold whole product descriptions nobody remembers writing.
  • Links. Paths and query strings such as /ivf/book or ?treatment=botox.
  • Event names. A custom event called something like BookConsultationAnxiety names the service outright.
  • Event parameters. A product name or condition inside a parameter, even when the event name is neutral.
  • Names you create. Custom audiences and custom conversions named after a drug, a treatment or a condition.
  • Form answers. A symptom typed into a form that ends up in the payload.
  • Matching fields. Gender and date of birth from advanced matching, which can complete a picture the other fields only suggest.

The useful way to read this list is that the classifier does not need one obvious medical word. It can build the picture from small pieces: a product name in one event, a gender field in another, a word in an image description. That is why a store can be flagged without ever describing itself as health.

Our free Meta health restriction checker opens a landing page in a real browser and looks for the common ones: pixels added by other scripts, event names that name a treatment, health words in the link, and whether Meta's public settings already mark the pixel.

What are the three levels?

Meta does not restrict a source all at once. It uses three levels, and the level you are on decides what is still possible. Vendor guides and the notices we have read describe them the same way.

LevelWhat Meta doesWhat it means for you
Core setup (mild)Strips everything in the link after the domain, such as paths and UTM tags, and drops custom parameters like category, plan type or city.Standard events still arrive, with less detail. Most stores barely notice.
Standard events (moderate)Can block standard events such as Lead, Add to cart, Purchase and Schedule. Page views can still arrive.Campaigns lose the events they optimise for. Neutral custom events are the route that remains.
Full (severe)Can block every event from the data source, whatever its name, sometimes only in certain regions.No conversion signal in that region from any tool. Ads keep running without it.

At the core setup level, the main damage is to anything that relied on the link: audiences built from URL rules shrink, and reports lose detail. One vendor that specialises in privacy notes that once Meta applies this level you cannot switch it off; it stays until a review succeeds.

At the standard event level, the events your campaigns optimise for stop arriving. Meta can still see people land on pages, but it can no longer learn who buys, which is the thing that makes Meta ads work for a store.

At the full level nothing arrives from that source. Campaigns are not paused for you; they keep spending, without optimisation, retargeting or conversion measurement.

The detail most people miss is the region. The full level can apply to some regions and not others. In our case Meta's notice said visitors in Europe could be fully blocked while other locations had the standard event block. The notice did not say whether Europe included the UK, and we could not confirm it. If your buyers sit mostly in one region, that one line in the notice matters more than everything else on the page.

How does a restriction usually unfold?

Most restrictions follow the same path, and knowing it is half the defence.

  1. A warning. Meta tells the advertiser by email and with a notice in Events Manager that the data source may belong to a restricted category.
  2. Quiet weeks. Nothing visible changes. Ads run, events arrive, and the warning starts to feel like noise.
  3. The block. Events the campaigns depend on stop arriving. This is usually the first moment anyone panics.
  4. The review. Someone presses the review button, because it is the obvious thing to do.
  5. A fast answer. The review is automated. If nothing has changed, the answer is no, and it can come with a tighter level.

The quiet weeks are the only time you can act before you lose the signal. In our case they lasted 31 days.

Our case: a maternity store, five weeks

The store sells maternity clothing on Shopify: dresses, leggings, nursing tops, and a few support products. Most of its customers live in the UK and Northern Europe, and Meta ads are where most of them meet the brand for the first time. The brand is strong and the creative is good. The founder runs it with a small team, and for part of the month that mattered, the founder was unwell.

On 1 September Meta sent the warning. It read like every other platform notice: serious in tone, vague in detail, with no deadline you could point to. Nothing changed in the ad account that day, so nothing was done.

On 2 October Meta blocked the store's standard events. Purchase and Add to cart stopped arriving in Events Manager. The ads kept running and kept spending, with no sales signal coming back.

On 6 October the review was requested. Meta rejected it the same day and added a block for visitors in Europe. The status in the notice read full_blocking_web_actions, with standard event blocking for other locations. Europe was exactly where most of the buyers were.

That is when the store came to us. By then the question was not how to avoid a restriction. It was how to keep a business running inside one.

The warning email is the deadline. The block is just the day you find out you missed it.

What we found when we opened the account

We went through the store, its events in Events Manager and its Shopify settings. We found six things. None of them was dramatic on its own. Together they explain why the review never had a chance.

1. Shopify's Meta channel was sending everything

Shopify's Facebook and Instagram channel is built to help advertisers by sending Meta as much as it can: what was viewed, added and bought, the link to the product page, and the customer's email, phone and name. For most stores that is exactly what you want. For this store, every event arrived carrying the name of a pregnancy-related product and the link to its page. We saw it on the events themselves, so this is not a theory.

This was the single biggest source, because it repeated on every event, all day, including all the days Meta was deciding what to do with the store.

2. Advanced matching added gender and date of birth

Advanced matching helps Meta recognise your customers. It can include gender and date of birth, and on a maternity store those two fields turn a suggestion into a near certainty. Turning them off takes two clicks. The match quality you give up is small, and on a restricted domain it is not worth keeping.

3. Hashing was not the protection it looked like

This one confused the founder, and it confuses most people. Shopify hashes the email and phone before sending, and the store's match quality was high. Surely the data was fine? Hashing protects the identity on the way to Meta. It does nothing about what the event says. A perfectly hashed email attached to an event naming a pregnancy product still tells Meta that a specific person bought a pregnancy product. The high match quality only meant Meta knew exactly who it was.

4. The titles, the description and one claim

Product titles used words like "pregnancy" and "postpartum" throughout, and so did the meta description, which is the first thing a crawler reads about a site. On one product page there was a sentence about easing pressure on the lower back, hips and abdomen. That is a health claim, whatever the product is, and it was the clearest piece of health language on the whole site.

5. The alt text nobody could see

This was the one the founder never knew about. The photos were fine. But behind every product image sits alt text, the description used by screen readers and search engines. Whoever set up the products had filled it with full product descriptions. The home page alone had 75 images whose alt text said "pregnant" or "postpartum".

Alt text is part of the page, so if Meta reads the page, it reads that too. The good news is that nothing visible had to change. The photos and the design stay; only the hidden words behind them do.

6. The review itself

The sixth problem was timing. The review was requested while all five problems above were still live.

Why was the review rejected the same day?

Because while Meta was reviewing the site, the site was still handing Meta the evidence. Every event still carried a product name and a link. Every page still carried the words. A review that re-scans the source found what the previous scan found.

Vendor reports describe the review as automated: one button in Events Manager, no way to attach evidence, a decision within days, and a 30 day wait before you can ask again after a rejection. One vendor that reviewed more than 125 ad accounts reports that it found no genuine health seller that had its category removed this way. We cannot confirm those figures from Meta, but what we saw has the same shape: no person, no conversation, and a very fast no.

So treat the review button for what it is. It is not an appeal to a person. It is a request to scan again, and it only helps if there is something clean to scan.

Clean first, then ask once.

The decision that mattered: where are the buyers?

Once we read the notice, the question was no longer how to fix tracking. It was where the buyers were, because the answer splits the plan in two.

If most buyers are outside the fully blocked region, the current domain can carry a clean conversion signal today. Health mode sends a neutral order event from the server, Meta can still learn from it, and the campaigns can optimise for it.

If most buyers are inside the fully blocked region, the current domain cannot carry a conversion signal there, from DataCops or from anyone else. You can still run ads and still sell, but Meta cannot learn from those sales, and you need a plan that accepts that.

The store's own sales-by-country report answered it in a minute. Most buyers were in the UK and Northern Europe. So we ran both tracks at once: a clean signal for everywhere Meta still listens, and ads built to work without a signal where it does not.

What we did, step by step

This is the plan we ran with the founder and the store's agency, in order.

StepWhoWhat
1DataCops teamConnected Meta in the store's DataCops account, removed an old test code, and turned Health mode on.
2The founderTurned off data sharing in Shopify's Facebook and Instagram channel.
3The founderTurned off gender and date of birth in advanced matching.
4DataCops teamCreated a custom conversion in Events Manager from the neutral order event P_1, category Purchase, named Order.
5The agencyPointed new sales campaigns at the custom conversion, not at the blocked Purchase event.
6The founderStarted the word list: product titles, the meta description, the claim sentence and the image alt text, old text next to new.
7The agencyKept ads running: traffic and broad campaigns where no conversion signal is allowed.
8DataCops teamWatched the delivery log for the first P_1 to reach Meta.
9EveryoneSet a date about four weeks out for one review request, with clean data behind it.

The custom conversion is the heart of it. When Meta blocks the standard Purchase event, campaigns can optimise for a custom conversion instead, built on a custom event with a neutral name. Ours Privacy draws the line clearly: custom conversions built on standard events are affected by the block, while custom events with compliant names and clean payloads can still work. That is the route health advertisers use, and it only holds if the event underneath carries nothing sensitive. It does not help in a fully blocked region.

There was one idea we refused. Someone suggested sending ad traffic to a clean redirect domain that would bounce visitors on to the store. That is the one move that could cost the store its ad account, so it was off the table from the start.

Where the case stands: the clean-up is under way and the clean signal is going out where Meta allows it. The ending is not written yet. We will update this page with what Meta does, good or bad.

If Meta says no a second time

We told the founder the truth before it happened, because it is easier to hear early. If a clean review is rejected again, there is nothing more anyone can do on that domain. Meta does not explain its decision and does not negotiate it.

That is not the end of the business. The current domain keeps working for organic search, Instagram, email and returning customers, which already brought in a large share of sales. Meta ads can keep running without conversion data. And there is one last option, a separate domain, which has real risks and is covered honestly in does a new domain help?

What to do the day the warning arrives

This is the part of the guide that saves the most. If you act in the quiet weeks, you may never reach the block.

  1. Do not press review. Not today. A review pressed before anything changes is a wasted attempt and may start a 30 day wait.
  2. Stop the biggest leak. If you are on Shopify, turn off data sharing in the Facebook and Instagram channel. It sends product names and links on every event.
  3. Remove gender and date of birth from advanced matching in Events Manager.
  4. Read the notice properly. Note the category, the level and any region it names. Screenshot it.
  5. Check where your buyers are. Your sales by country tells you how much a regional block would hurt.
  6. Run the checker on your main landing pages to see what Meta can read.

What to do in the first two weeks

Make the word list

Go through product titles, collection names, the meta description, headings, claims and image alt text. Write the old text on the left and the new text on the right, so one person can work through it and another can check it. Change the words, not the brand: photos, products, reviews and design stay as they are.

Be honest about what you are

Cleaning the words lowers the risk. It does not disguise the business, and it should not try to. If every product you sell is about pregnancy, Meta may still classify you as health. The aim is to remove medical claims, condition language and the detail Meta does not want, not to pretend to be something else.

Clean what you send

Move sending to one place that cleans every event before it leaves: links cut to the homepage, no product or content names, no form answers, neutral event names, and only the fields needed for matching. With DataCops that is Health mode. With a server-side tag manager it is a set of rules someone on your team has to write and keep current.

Rename what you created

Custom audiences and custom conversions named after a drug, a treatment or a condition are part of what Meta reads. Give them plain names.

How to keep running Meta ads while restricted

What you can do depends on your level, so plan by level.

At the core setup level

Standard events still arrive, so keep optimising for purchases or leads. Clean the payload anyway, so you do not move down a level, and rebuild any audience that depended on URL rules, because those shrink once links are cut.

At the standard event level

Send the conversion as a custom event with a neutral name and a clean payload, from your server. Build a custom conversion on it in Events Manager, choose the matching category, give it a plain name, and point your campaigns at it. Expect a learning period after the switch; one vendor reports two to three weeks for delivery to settle.

At the full level, or in a fully blocked region

There is no conversion signal to optimise for, so stop pretending there is. Use traffic or engagement goals, broad targeting, and let the creative do the work. Strong creative and a clear landing page carry more weight than ever. Catalogue ads can still show products to broad audiences, but retargeting by product will not have the events it needs.

One thing applies at every level: the store has to keep selling while Meta is learning less. That is where your own measurement comes in.

How to count the sales Meta cannot see

A block on Meta's side does not stop you counting your own sales, and that is the idea to hold on to. Your store records every order. Shopify is the source of truth, not Meta's report.

  • Keep the click. DataCops stores the Meta click ID on the server for up to 90 days, so an order can be tied to a Meta ad even when Meta never hears about the sale.
  • Judge on store revenue by source. Use your own numbers, not only Meta's attribution, to decide what to scale.
  • Ask buyers. A one-line "how did you hear about us" after checkout fills gaps no pixel can.
  • Test by region. A geo test compares places with ads and places without, which needs no pixel at all.
  • Start new campaigns warm. Ads Warmup sends a list of past customers, with their consent, to give a new campaign real buyers to learn from.

When should you ask Meta for a review?

When there is something clean to look at, and not before. In practice that means the word list is done, Shopify's sharing is off, every event is going out clean, and about four weeks of clean data have built up. Check the delivery log to confirm what has actually been sent, then ask once.

Before you press the button, decide what you will do if the answer is no. Making that decision calmly, in advance, is much better than making it the day the rejection lands.

What never to do

These are the mistakes we see most, and the reason each one hurts.

  • Pressing review before cleaning. Meta re-scans the same data, says no, and you may wait 30 days to try again.
  • Renaming events and leaving the payload. As one guide puts it, renaming Purchase changes the label Meta sees, not the payload underneath it.
  • Leaving Shopify's Maximum data sharing on. It keeps sending product names and links while you try to clean up.
  • Hoping a new pixel fixes it. Meta classifies the domain, so a new pixel on the same domain sends from the same restricted source.
  • Naming audiences or conversions after a drug or condition. Meta reads those names too.
  • Sending form answers to Meta. A symptom typed into a form is health information the moment it leaves your site.
  • Sending ad traffic through a clean redirect domain. Meta sees one page and the customer sees another. That is the practice most likely to get an ad account closed.
  • Showing Meta a different page than customers see, or hiding pages from the crawler. Same risk, same reason.
  • Betting the business on the review. Plan for no, and be pleasantly surprised.

Does a new domain help?

Sometimes, and it is the most misunderstood option in this whole topic. A new domain is a new data source, and Meta judges data sources one by one. But it only helps if what Meta reads there is genuinely clean, and it carries real risk.

There are two versions. One is a separate store with a narrower, clean range: in our case that would mean maternity fashion only, with the support products and anything that makes a claim staying on the original store. The other is a second domain on the same Shopify store. The second is simpler, but if the content is the same, the classification will likely follow, because Meta reads the same titles, alt text and claims on both.

Whichever version, the rules are the same. Run the checker on the new site before a single ad points at it. Use a new pixel and dataset with Health mode on from day one. Keep the original domain for organic search, Instagram, email and returning customers. Never send ad traffic from one domain to the other through a redirect. And accept that Meta can still link the two through the same ad account, business portfolio or payment method, so we cannot promise a new domain stays clean.

If, months later, the new domain has run clean and you want to retire the old one, that is a site migration with its own risk, because Meta may carry the old classification across. It is a decision for much later, not part of the rescue.

Which tracking setup should a health store use?

Every setup that works does the same thing: it sends Meta less, on purpose, from one place that cleans every event. The difference is who does the cleaning and how easy it is to get wrong. Each row describes what the vendor's own material says; check their pages before you choose.

SetupWhat reaches Meta by defaultWho does the cleaningBest for
Shopify's Facebook and Instagram appStandard events with product names and page links, plus customer details; with Maximum sharing, also through the Conversions APINo health cleaning stepStores outside sensitive categories
Server-side tag manager (for example Stape)Whatever you configureYou write and maintain the rules that strip links, parameters and namesTeams with a tracking specialist who will keep the rules up to date
Health-focused data platforms (for example Ours Privacy, CustomerLabs)Per their own articles: anonymised links, hashed identifiers, swapped event namesThe platform, configured by youRegulated healthcare teams that need a wider privacy programme
DataCops Health modeClick ID, hashed email and phone, value, currency, IDs, time and the homepage address onlyA fixed allowlist, on by detection or by your switch, with every send loggedHealth, wellness and supplement stores and clinics that advertise on Meta without a tracking engineer

Our position is simple. If your store or clinic sits anywhere near health and Meta is a main channel, the safest setup is one where cleaning is automatic, cannot be forgotten when someone adds a form field, and leaves a record you can point to. That is what DataCops Health mode was built for. If you have a tracking specialist who will maintain the rules, a server-side tag manager can reach the same result with more work.

How DataCops Health mode works, and why it is built that way

Health mode is one switch per website. When it is on, every conversion DataCops sends to an ad platform goes through the same cleaning step first.

An allowlist, not a blocklist

Most cleaning setups are blocklists: a list of words or fields to remove. A blocklist only catches what someone thought of. The next new form field, page or app slips through. Health mode works the other way round. It keeps a fixed list of the fields an ad platform needs and drops everything else, so a field nobody planned for cannot leak.

What still goes to Meta

The ad click ID such as fbclid; email, phone and your own customer ID, hashed before they leave; the value, currency, order ID, event ID and event time; the network details and consent signals that matching and consent rules need; and your homepage address only. A link like clinic.com/ivf/book?step=2 goes as clinic.com.

What never leaves your site

Page paths, query strings, the referrer, page titles, product and content names, cart items and every form answer.

Neutral names

What happenedName Meta receives
LeadL_1
Schedule (booking)S_1
PurchaseP_1
Complete registrationR_1
ContactC_1
ApplicationA_1
Showed (appointment attended)V_1
Anything else, such as add to cartE_1

It switches itself on, never off

Health mode is off by default. When you connect an ad platform, DataCops reads your homepage and an AI model decides whether the site is a health or wellness business. Only a confident answer turns Health mode on; a lower score shows as unsure so you can decide. Detection can turn it on but never off, and if you set it yourself, DataCops never changes your choice. The reasons shown in your dashboard are words that really appear on your homepage.

Your own tools keep the full record

Cleaning applies to ad platforms only. Your CRM, your email tool and your webhook still receive the full lead or order, because they are your own systems.

Proof

Every cleaned send is marked in the delivery log, so you can show exactly what left your site and when. That is useful for your own checks, and it was the first thing we watched in the case above.

The rest of the install supports a store working with a weaker signal: every visit gets a bot verdict with a Real people only switch per ad platform (off by default); collection runs on your own domain with one script and one DNS record; with DNS on Cloudflare the free Worker reads the click at the edge, capturing and never blocking; a signed server-set cookie lasts up to 400 days where enabled; and a first-party consent manager on IAB TCF v2.2 comes from the same script. On Shopify, the DataCops Shopify app sends paid orders from Shopify's server, and Health mode cleans them like any other conversion. The full product page is Meta health and wellness restrictions.

When DataCops is not the answer

  • Your domain is fully blocked everywhere you sell. No tool can send conversion events from it. DataCops still helps you count sales yourself, but it cannot restore Meta's signal.
  • You need product-level retargeting. Health mode removes product and content names, so retargeting by product will not get what it needs. That is the trade-off of sending less.
  • You need a full regulated privacy programme. An ad tracking tool is one part of that, not the whole of it. Talk to a privacy specialist.
  • You want a restriction lifted. Only Meta can do that.

What this case taught us

1. The warning is the deadline

Thirty-one quiet days separated the warning from the block. Everything that could have prevented the block was possible in those days and much harder after them.

2. Meta reads data, not intent

The founder never thought of the store as a health business. Meta did not ask. It read product names, alt text and matching fields, and reached its own conclusion.

3. The leak is usually a default

Nobody chose to send Meta pregnancy data. Shopify's channel and advanced matching did it by default, on every event. Most restrictions start with a setting nobody looked at.

4. Hashing is not cleaning

Hashing hides who someone is on the way to Meta. It does not hide what they bought. A clean event needs both.

5. The words you cannot see count the most

Seventy-five images of hidden text did more harm than anything visible on the site.

6. A review is a re-scan

Pressed too early, it produced a same-day rejection and a tighter block. Clean first, then ask once.

7. Region decides the strategy

The level on the notice mattered less than the region next to it. Where the buyers are decided whether the store could keep a signal at all.

8. Send less, on purpose

A fixed allowlist is the only cleaning that does not depend on someone remembering every new field.

9. Keep your own count

When Meta stopped seeing sales, the store's own data and the stored click were what kept decisions grounded.

10. Never depend on one channel

The store will survive this because organic search, Instagram and returning customers were already a real share of sales. A store without them would be in a far worse place.

The checklist

  1. Treat the warning as the deadline. Act on day one.
  2. Turn off Shopify's Meta data sharing and remove gender and date of birth from advanced matching.
  3. Read the notice: category, level and region.
  4. Check where your buyers are.
  5. Make the word list: titles, description, claims, alt text, audience and conversion names.
  6. Send everything through one place that cleans it, with neutral names and the homepage address only.
  7. Optimise for a custom conversion on a clean custom event where standard events are blocked.
  8. Run traffic and broad campaigns where nothing gets through.
  9. Count sales yourself with the stored click and store revenue by source.
  10. Ask for one review, after about four weeks of clean data, with a plan for no.
  11. Never redirect ad traffic, never show Meta a different page, never hide pages.

Sources

FAQ

What is the best tracking setup for a health or wellness brand on Meta?

One that sends Meta only what it needs to count a sale, from your server, with neutral event names and nothing about the product, page or condition. DataCops Health mode does this with a fixed list of allowed fields, detects health sites on its own, and logs every send. A server-side tag manager can do the same if a specialist builds and maintains the rules.

Does the Conversions API get around Meta's health restrictions?

No. The restrictions apply to the data source, and they cover events from the browser pixel and from the Conversions API alike. Server-side sending helps because it gives you one place to clean the data before it leaves, not because Meta treats it differently.

Can I still optimise for purchases if Meta blocks standard events?

Often, yes, through a different route. Send the order as a custom event with a neutral name and a clean payload, build a custom conversion on it in Events Manager, and optimise the campaign for that. It does not work at the full restriction level, where every event from the domain is blocked.

Why is my maternity, supplement or skincare store flagged as health?

Because Meta judges what your data says about the buyer, not what you think you sell. Pregnancy counts as reproductive health, supplements are on Meta's own list, and skincare for conditions like acne reads as a condition. Product names, page links, image alt text and matching fields can all carry the signal.

Should I turn off Shopify's Facebook and Instagram data sharing?

If your store is health-adjacent and Meta has warned you, yes, while you clean up. The channel sends standard events with product names and links on every event. Turn it off and let a setup that cleans the data send to Meta instead.

Does a new pixel on the same website fix a restriction?

Unlikely. Meta classifies the data source, which is your domain or app, so a new pixel on the same domain sends events from the same restricted source.

How long does a Meta data source review take?

Vendors report a few days, with no way to attach evidence and a 30 day wait after a rejection. In our case it was rejected the same day. Prepare for it as a single attempt, after the clean-up, not as a button to press when events stop.

Can DataCops remove a Meta restriction?

No. Only Meta can, and it does not explain or negotiate its decisions. DataCops stops your site sending the detail that feeds the restriction, keeps a clean signal where Meta still accepts one, and gives you a log of exactly what was sent.

Is moving to a new domain allowed?

A real business can run a separate store on another domain. It only helps if what Meta reads there is genuinely clean, and Meta can still link domains through the same ad account, business portfolio or payment method. Never redirect ad traffic from a clean domain to a restricted one.

What should I do first when Meta sends the warning?

Do not press review. Turn off Shopify's Meta data sharing, remove gender and date of birth from advanced matching, and start a list of every place your site and events mention a condition, a treatment or a body. Then clean, wait for clean data, and ask once.

Is this a real customer?

Yes. We removed the store's name and anything that identifies it. The dates, the findings and the decisions are real, and the outcome is not written yet.

Is this legal advice?

No. This is how the restrictions behave and what we have done in practice. Check your own obligations with a lawyer where they apply to you.

Get ahead of the warning

Health mode sends Meta a clean, neutral signal and keeps your own count.

Setup in 5 minutes. No credit card.

Live traffic quality

Updated just now

Visits · last 24h

487
Real users
35873.5%
Bots · auto-filtered
12926.5%

Without filtering, 26.5% of your reported traffic is bot noise inflating dashboards and draining ad spend.

Don't trust your analytics!

Make confident, data-driven decisions withactionable ad spend insights.

Setup in 2 minutes
No credit card