Track Acuity Scheduling bookings as ad conversions, HIPAA-compliant
When a visitor clicks your ad and then leaves your site to book on Acuity Scheduling, the click ID and UTMs stay behind, so the booking can't be credited to the ad on its own. Curve Compliance carries that attribution across with a bridge token and credits the booking to the original ad click when Acuity's webhook arrives. It then sends the conversion server-side to Meta, Google, TikTok, Microsoft and LinkedIn, and a booking made days after the click still matches.
See how Curve Compliance tracks Acuity Scheduling bookings on your own funnel.
How it works
Step 1
One script replaces your ad pixels
Curve's team installs the Curve Compliance script on your site in place of your browser ad pixels, so conversions reach your ad platforms from Curve's servers.
Step 2
The click to Acuity carries a bridge token
When a visitor clicks a plain link to Acuity Scheduling, Curve keeps their ad attribution: click IDs, UTM parameters, the session and the page the click came from. It adds a short reference to that attribution, called a bridge token, to the booking link and records a booking_intent event. The token carries no form content and is not a patient identifier.
Step 3
Acuity returns the token with the booking
Acuity keeps the token with the appointment and includes it in the webhook it sends when the booking is made. Where a custom field is needed to carry the token into that webhook, Curve's team sets it up.
Step 4
Curve credits the booking to the ad click
The webhook is set up in Curve under Incoming Webhooks to match on the bridge token, and Curve's team configures it with you. When it arrives, Curve credits the booking to the original visit, even when the patient books days after the click.
Step 5
The conversion goes out server-side
Curve forwards the booking as a conversion to Meta, Google, TikTok, Microsoft and LinkedIn. Campaign Reporting then puts your ad spend next to the tracked bookings for each campaign.
What reaches Meta and Google
Meta and Google receive the Acuity booking as a conversion sent from Curve's servers and credited to the ad click that started it. TikTok, Microsoft and LinkedIn receive it the same way.
- Each ad platform receives only a fixed list of fields.
- Contact identifiers are off by default, and SHA-256 hashed when you turn them on.
- The event can use a neutral name such as "Lead" in place of a treatment or condition.
- The bridge token in the Acuity link carries no form content and is not a patient identifier.
- Curve detects PHI-like patterns, such as condition names, form answers and emails in URLs, and flags them so they can be fixed at the source.
- Event Logs show what Curve sent to each platform and what each platform accepted.
Read more about Meta Conversions API and Google Ads with Curve Compliance.
Does Acuity Scheduling sign a BAA?
Yes, on the Powerhouse and Premium plans, once you make the Acuity account HIPAA-enabled. The BAA is entered into with Squarespace.
Squarespace says each Acuity account becomes HIPAA-enabled only when a separate BAA is entered into for that specific account, and that custom BAAs are available on an Enterprise plan.
The BAA doesn't cover other Squarespace features. Squarespace also says that if you connect Acuity to third-party integrations, such as Google Calendar or Stripe, it's your responsibility to determine whether each one is acceptable for your business.
That BAA covers the patient data Acuity holds for you. It does not cover what an ad pixel on an Acuity page sends to an ad platform, which is a separate recipient that has not signed your BAA.
Curve Compliance signs its own BAA with you on every plan.
We checked Squarespace's own pages on September 29, 2026. The quotes and source links are on the Acuity Scheduling entry in the BAA Directory.
Acuity Scheduling booking tracking FAQ
Can I send Acuity Scheduling bookings to Meta Conversions API?
Yes. Curve Compliance credits each Acuity Scheduling booking to the ad click behind it when Acuity's webhook arrives, then sends it from Curve's servers to Meta Conversions API. Meta receives only a fixed list of fields, contact identifiers are off by default and SHA-256 hashed when enabled, and the event can use a neutral name such as "Lead". The same booking can also go to Google, TikTok, Microsoft and LinkedIn.
Does attribution survive if the patient books days later?
Yes. Acuity keeps the bridge token with the appointment and sends it back in its webhook, so Curve Compliance matches the booking to the original visit, with its click IDs, UTM parameters and the page the click came from, even when the patient books days after the ad click.
Does Acuity Scheduling sign a BAA?
Yes, on the Powerhouse and Premium plans, once you make the Acuity account HIPAA-enabled and enter into a BAA with Squarespace for that account. Custom BAAs are available on an Enterprise plan. The BAA does not cover other Squarespace features or the ad platforms that receive your conversions. Curve Compliance signs its own BAA with you on every plan.
What if the Acuity Scheduling booking page is embedded or opens in a pop-up?
Curve's team sets that up. Plain links to Acuity Scheduling are handled automatically, and embedded booking widgets, pop-ups and buttons that open the scheduler with JavaScript get a small custom setup from Curve's team. Either way, the booking is credited to the ad click that started it.
How long does setup take?
About a week; it varies case by case. Curve's team does the setup: it replaces your browser ad pixels with one script, configures the Acuity webhook under Incoming Webhooks, sets up any custom field the token needs and turns on forwarding to your ad platforms. Curve signs a BAA on every plan.
Track Acuity Scheduling Bookings as Conversions
Curve's team sets up the Acuity handoff, the webhook and server-side delivery to your ad platforms, with a BAA on every plan.
- BAA on every plan
- Set up by Curve's team
- Server-side delivery