Will server-side tracking, the Conversions API, or renaming events get around a health restriction?
On this page
No. Meta restricts health data by data source, not by delivery route, so an event sent through the Conversions API is judged by the same rules as one sent from the browser pixel. Renaming the event does not help either. Meta says the names you choose for events, conversions and Custom Audiences "must not reflect, imply, or be based on any prohibited information", and "You must not attempt to send data that has previously been detected and removed." Sending restricted data by another route, or under another name, breaks Meta's terms and invites tighter restrictions. The path changed. The verdict did not.
Curve Compliance does send conversions server-side, but as a control on what leaves your site, never as a way past a restriction. Only the fields you explicitly map are sent, personal identifiers are SHA-256 hashed as the platforms' APIs require, PHI-like patterns are detected before anything goes out, and a BAA is signed on every plan. Curve does not lift restrictions, restore restricted events, fix creative or file appeals, and it does not rename events to get them through. If you want your setup checked, book a call with Curve.
Why the route does not change the rule
Meta assigns a category to a data source "based on the topics related to the data source and the products and/or services provided". Its Health and wellness category covers anything "associated with medical conditions or specific health statuses, provider/patient relationships, services for accessing personal health information, or health-related products and services", with examples including a "telemedicine platform" and a "pharmacy". That is a judgement about your business, not about how an event reaches Meta.
When a data source lands in a restricted category, Meta says it "may limit or fully restrict the ability to share event data with us via the Meta Business Tools". The Conversions API is one of those tools: Meta's Business Tools Terms name the ad products they cover as including "Meta Pixel, Conversions API, Facebook SDK for App Events, Offline Conversions and App Events API". An event Meta has restricted is restricted whether it comes from a browser, a server or a partner integration.
The restriction takes one of three forms. Core setup "Restricts the sharing of custom parameters and parts of URLs following the domain." A restriction on certain standard events "Restricts the sharing of specific mid and lower funnel events", which is where booking and purchase events usually sit. Under full restrictions, "Meta Business Tools cannot be used for ads purposes where restrictions are in place." And "you will not be able to modify a Meta-assigned categorization for your data source."
Why renaming events is not a fix
The common advice is to fire a custom event with a neutral name, such as Event 4, on the same booking. Meta's rules close that off in three places.
- Names and criteria. Meta says "the names you choose and criteria you establish for your events, conversions, and Custom Audiences must not reflect, imply, or be based on any prohibited information." An event that fires only on a hormone consult booking is based on that booking, whatever you call it.
- Review. While a data restriction is in place, "custom events are automatically blocked until you review and confirm them". Meta asks you to confirm a custom event only if "Your custom event data, including the event name and parameters, follows the Meta Business Tools Terms and doesn't include prohibited information."
- Re-sending. "You must not attempt to send data that has previously been detected and removed." A renamed event carrying the same booking is the same data sent again.
What happens if you try anyway
Meta says sharing prohibited information "in any form violates the Meta Business Tools Terms", and that failure to comply "can lead to a variety of consequences, such as performance issues, data restrictions, or suspension or termination of your use of our products and services, including the Meta Business Tools." Repeated notices are one of the reasons Meta lists for putting a dataset into core setup, and repeat blocked-parameter notices can mean core setup "for at least 90 days".
It also damages your own reporting: once a booking is called Event 4 everywhere, nobody can tell later what it measures.
The same goes for other versions of the idea:
- Sending the restricted event from a second pixel, dataset or domain.
- Moving health detail into custom parameters or URL query strings.
- Self-categorizing the dataset into a category without restrictions.
What server-side tracking legitimately helps with
Server-side tracking is a control on what you send, not a key to what Meta refuses. It will not change a category, lift a restriction or bring back a restricted event. It does help with:
- Deciding what leaves. A browser pixel sends what the page gives it, including full URLs and query strings. Meta warns that "UTM parameters in a URL string may contain prohibited data from the landing pages viewed." A server-side setup can send only the fields you choose.
- Fewer repeat notices. Fixing the source of prohibited information is how you avoid the repeated notices that can push a dataset into core setup.
- Reliable delivery of the events Meta still accepts, including the upper-funnel events it suggests.
- Other platforms. Google Ads, TikTok, Microsoft and LinkedIn each apply their own rules, so a conversion Meta restricts may still be usable elsewhere, subject to that platform's policies.
- Your own measurement. Knowing which campaigns produced booked appointments does not depend on Meta crediting them.
What to do instead
If Meta has restricted events on a health data source, work in this order. The peptide clinic guide walks through the same logic for one specialty.
- Open Events Manager, go to Datasets, then Settings, then Manage data source categories, and note the category, who assigned it and which restriction applies.
- If Meta assigned the category and it is wrong, select View details and Request review, and Meta will email its decision. If it is right, do not try to change it.
- Choose an optimization event from what Meta still accepts. Meta suggests "leveraging more upper-funnel events", and under full restrictions, objectives such as Awareness, Engagements and Traffic.
- Check the Diagnostics tab and fix what your site sends at the source. Never re-send data Meta removed.
- Confirm only the custom events whose names and parameters carry no prohibited information, and leave the rest blocked.
- Measure booked appointments outside Meta so you still know what each campaign produces. If conversions stopped and you are not sure why, check whether it is a restriction or a tracking break.
Where Curve Compliance fits
What Curve does
- Sends conversions server-side to Meta Conversions API, Google Ads, TikTok, Microsoft and LinkedIn.
- Sends only the fields you explicitly map, so URLs and custom parameters that carry condition detail are not sent unless you map them.
- SHA-256 hashes personal identifiers, as the platforms' APIs require.
- Detects PHI-like patterns before data leaves.
- Keeps attribution through booking tools with bridge tokens. A BAA is signed on every plan.
What Curve doesn't do
- Does not get restricted events past Meta, by any route or under any name.
- Does not lift restrictions or change a data source category.
- Does not restore restricted events or blocked custom events.
- Does not fix creative or file appeals.
Frequently asked questions
Does the Conversions API follow different rules from the Meta Pixel?
No. Meta's Business Tools Terms cover both, and its data source restrictions limit sharing "via the Meta Business Tools", which includes the Conversions API.
Can we rename Purchase to a custom event like Event 4?
No. Meta says event names "must not reflect, imply, or be based on any prohibited information" and that "You must not attempt to send data that has previously been detected and removed."
Does hashing make health data acceptable to send?
No. Meta requires some customer information parameters to be hashed with SHA-256, but hashing is the required format, not permission. It does not change what an event says about a person or lift a category.
Will Curve Compliance get our restricted events back?
No. Curve does not lift restrictions, restore restricted events or rename events to get them through. It controls what your site sends and keeps attribution through booking tools with bridge tokens.
Then why use server-side tracking at all?
Because it lets you decide field by field what leaves your site, which helps prevent the repeat notices that tighten restrictions. It also delivers the events each platform still accepts.
Sources
- Meta Business Help Center: About data source categories in Meta Events Manager
- Meta Business Help Center: Understand data sharing restrictions based on data source categories
- Meta Business Tools Terms
- Meta Business Help Center: About prohibited information
- Meta Business Help Center: Troubleshoot Meta Business Tools prohibited information notifications
- Meta Business Help Center: About reviewing custom events in Meta Events Manager
- Meta Business Help Center: About core setup
- Meta Business Help Center: How to review blocked parameters in Meta Events Manager
Last verified
Related pages
- Meta Restricted Purchase Events for Health and WellnessWhy Meta restricts Purchase and other lower-funnel events for health and wellness sites, what still works in each tier, and the compliant way back.
- Meta Blocked My Custom Events Until I Review ThemWhy Meta blocks every custom event once a dataset has data restrictions, which events to confirm, which to keep blocked, and why renaming is not a fix.
- Meta Removed Potentially Prohibited Information: Next StepsWhat Meta's prohibited information notice means for a health business, where to find what was removed, how to fix it, and why you must never re-send it.
- Meta Conversions Stopped: Restriction or Broken Tracking?Meta conversions dropped. How to tell a data restriction from broken tracking or a page change, event by event, and which layer to fix first.
Talk to Curve about the data side of your restriction
Curve Compliance fixes the data layer: conversions go server-side and only explicitly mapped fields leave. It does not lift a restriction or restore restricted events.
Book a call