Skip to main content

First Party Data

Meta's Health and Wellness Restrictions: What Shopify Brands Need to Know

October 10, 2026 · Michael Alt · 11 min read

Meta's health and wellness restrictions are limits on the data your Pixel and Conversions API can share once Meta places your website or dataset in its health and wellness category. Depending on the tier, Meta strips custom parameters and URL paths (Core Setup), restricts certain mid and lower funnel events, or blocks event sharing entirely in some regions.

This post covers what Meta restricts and why, who is affected, where to check your dataset, how these data rules differ from Meta's ad policies for health claims, and what a compliant setup looks like for a Shopify store. If you're new to the Conversions API, start with our guide to Meta CAPI and first-party data.


What are Meta's health and wellness restrictions?

The restrictions apply to the Meta Business Tools, which Meta says include the Meta Pixel, the Conversions API and its app and offline event tools. Meta may assign a category to any website or app that sends data through those tools, and some categories carry extra data-sharing restrictions. Health and wellness is one. Meta describes it as a data source that "is associated with medical conditions or specific health statuses, provider/patient relationships, services for accessing personal health information, or health-related products and services."

Once a data source is in a restricted category, Meta applies one or more of three restrictions:

RestrictionWhat Meta restrictsWhat Meta suggests
Core SetupCustom parameters and anything in a URL after the domainMost campaigns keep running; review affected features
Restriction on certain standard events"Specific mid and lower funnel events"Optimize toward events that remain available
Full restrictionsAll events, in specific regions or all regionsAwareness, Engagement or Traffic objectives

Why does Meta restrict health and wellness data?

Meta's stated reason is its terms. Meta says it does "not want or permit advertisers" to use the Business Tools to share prohibited information about people, which includes health information and anything defined as sensitive under applicable laws, regulations and industry guidelines. On its prohibited domains page, Meta frames this as protecting users' privacy.

Meta's list of prohibited health information covers conditions, reproductive and mental health, treatments, and "prescription medications, and over-the-counter (OTC) and supplements for specific medical conditions." Meta also says its filters are "not a substitute for your own compliance mechanisms," so the payload is the advertiser's responsibility.


Who do Meta's health and wellness restrictions apply to?

Meta categorizes data sources "based on the topics related to the data source and the products and/or services provided." The category follows your site and catalog, not a single event. Meta's core setup article lists four ways a dataset ends up restricted:

  • Meta determined the data source falls under a category that requires it.
  • Someone on your account assigned the dataset to a restricted category (self-categorization is optional).
  • You received multiple notifications that your data potentially breaks the Business Tools Terms, which Meta says can mean Core Setup for at least 90 days.
  • You turned Core Setup on yourself.

You can edit categories you assigned, but Meta says "you will not be able to modify a Meta-assigned categorization."

On geography, Meta says restrictions "can be specific to certain countries or regions, or they could be applied globally," and that it informs affected advertisers by email and in Events Manager. The help center articles we reviewed don't publish a start date or country list for health and wellness, so treat your own notifications and dataset settings as the source of truth.

In the Shopify accounts we audit, Meta's definition is broader than most brands expect. Supplements, skincare with active claims, fitness, sexual wellness and anything that implies a condition or an outcome can land in the category.


What changes when Meta restricts your dataset?

Under Core Setup

Meta's example: https://jaspersmarket.com/clothes/summer/dresses?item=10 is shortened to https://jaspersmarket.com/. Standard parameters such as value, currency and content_ids aren't custom parameters, so Core Setup itself doesn't remove them. Meta lists these side effects:

  • Custom audiences built on URL rules or custom parameters may stop updating.
  • Automatic advanced matching may be unavailable, so advanced matching has to be set up manually.
  • Pixel-based catalog updates may stop working.
  • Custom events are blocked until you review and confirm them.

Under event and full restrictions

Meta describes this tier as restricting "specific mid and lower funnel events" without a fixed list in the article. For a store, that part of the funnel is where AddToCart, InitiateCheckout and Purchase sit, the events conversion campaigns typically optimize on. Meta's advice is to check which events are restricted for your dataset and explore alternatives. Under full restrictions, Meta says the Business Tools "cannot be used for ads purposes" in the affected regions.

Why performance drops

Meta says an ad set usually exits the learning phase after about 50 results in the week after its last significant edit. Fewer usable conversions make that harder. Brands in supplements, skincare and wellness often tell us performance dropped without warning after a restriction. Lower-volume, higher-ticket advertisers feel it most, because each lost conversion is a bigger share of the signal.


How do you check if Meta has restricted your dataset?

  1. Check email and Events Manager notifications. Meta says it notifies advertisers of restrictions.
  2. Open dataset settings. In Events Manager, go to Datasets, select your dataset and open Settings. Look for Dataset categories and Manage data source categories (Meta's steps).
  3. Check Data restrictions. In the same tab, find the Core setup section. If Meta turned Core Setup on, you can't turn it off.
  4. Check Diagnostics. An "Event parameters blocked" message leads to the parameters Meta blocked.
  5. Request a review if the category is wrong. Under Manage data source categories, click View details, then Request review. Meta emails its decision.

In our experience appeals rarely succeed, so plan as if the restriction will stay and fix what you send.


Meta health ad policies vs data restrictions: what's the difference?

They're separate systems. Meta's Health and Wellness ad policy governs ad content and targeting: ads for dietary, health, weight loss or weight gain products must target people 18 or older, and ads can't claim to cure listed incurable diseases such as diabetes or cancer. The Drugs and Pharmaceuticals policy adds certification, authorization and country rules for prescription drug ads.

Ad policiesData restrictions
GovernsCreative, claims, targetingEvent data from Pixel, CAPI and SDK
Applied toIndividual adsDatasets and data sources
Where you see itAd rejectionsEvents Manager settings, diagnostics, email
What fixes itEdit the ad or request a reviewChange what you send; request a category review

An ad can pass review while its dataset sits in Core Setup, and a clean dataset doesn't make a prohibited claim acceptable. Review both.


Does server-side tracking fix Meta's health and wellness restrictions?

No. The Conversions API is one of the Business Tools, and the restrictions apply to your dataset and data sources, not to the Pixel alone. Events Manager shows pages, parameters and URLs sent through both the Pixel and the Conversions API.

Moving events server-side changes the transport, not the content. If a product name with a health keyword, a "Health & Wellness" category value or a condition in a URL is in the payload, it's still in the payload. The same applies to Meta's Conversions API Gateway, which relays what the Pixel captured. Server-side tracking is worth doing for signal quality, as our server-side tracking and Conversions API guide explains, but it isn't a compliance fix.

Starting over doesn't fix it either. In the accounts we work with, a new pixel on the same domain that receives the same events is usually flagged again within days, and a new ad account carries the same restriction, because the category sits on the dataset and the domain rather than the ad account. What changes the outcome is what the data contains and what else is connected to the dataset.

What should health and wellness brands send to Meta?

Stop sending fields that describe the product or a condition

FieldWhat to remove
content_nameProduct titles with health keywords, ingredients or conditions
content_categoryValues such as "Health & Wellness" or "Supplements"
content_typeValues such as supplement or vitamin (Meta's Pixel reference expects product or product_group)
Custom propertiesDescriptions naming an ingredient, condition or outcome
URLs and UTMsPaths or campaign names that name a condition
Custom events and conversionsNames referencing a condition (Meta flags custom conversions that mention conditions such as arthritis)

Meta's prohibited information guidance names content names, custom properties and UTM parameters as fields to check. It also requires event_source_url for website events sent through the Conversions API, so send a URL without a product or condition in its path, such as your domain (the same truncation Core Setup applies). If you send content_ids, use opaque IDs rather than SKUs that spell out an ingredient.

Keep sending the identifiers Meta matches on

ParameterWhat it isMeta's handling rule
em, phEmail and phoneSHA-256 hashing required
fbcClick ID from fbclidDo not hash
client_ip_address, client_user_agentBrowser connection dataDo not hash
external_idYour stable customer IDHashing recommended
value, currencyPurchase amountRequired for purchase events

These describe who converted and for how much, not what they bought or why. Meta's customer information parameters page sets the hashing rules. Because automatic advanced matching may be unavailable under Core Setup, sending these fields from your server matters more. Our pillar explains what data the Conversions API sends to Meta, and our Event Match Quality reference guide covers how each identifier affects matching.

Filter per destination, not at the source

Your warehouse and analytics still need product names and categories, so stripping them at the source breaks reporting. Upstack applies field rules per destination: Meta receives a filtered payload while analytics and warehouse destinations receive full data.

This is data minimization, not evasion. It doesn't change a category Meta has assigned or lift a restriction Meta has applied. It keeps prohibited fields out of what you send, lowers the risk of repeat blocked-parameter notifications, and keeps the matching signals that remain as strong as they can be.

Check creative against Meta's ad policies separately. For the data side, Meta itself tells advertisers to work with their own legal counsel on a data sharing compliance plan. This post isn't legal advice.

Don't rely on a renamed custom event

Optimizing on a custom event in place of Purchase used to be a common workaround. In the accounts we work with, it stopped working in January 2026: Meta categorizes the data, not the event name, so the custom event ends up restricted too, and in the meantime you optimize on a weaker signal than Purchase.


How do health and wellness brands get purchase optimization back?

A dataset or domain Meta has categorized usually stays categorized. The approach we use with health and wellness brands is a new, clean data source that only ever receives filtered data:

  1. A new pixel with nothing else connected. Upstack is the only thing sending it data, so unfiltered events from the browser pixel, the Shopify Facebook & Instagram app's data sharing or another integration never reach it.
  2. Events sent from a neutral domain. A second domain with one simple page and no health claims or product language. Customers keep landing on your store.
  3. Server-side only, with health terms removed. The browser pixel comes off the store. Product names, URLs, categories and descriptions are stripped; identifiers, value and currency go through.
  4. Optimization on the standard Purchase event, not a renamed custom event.

Keep the old pixel. It holds your audiences and history, and campaigns move across gradually as you duplicate your strongest ad sets onto the new one. Match quality holds up without the browser pixel because hashed email and phone, click ID, IP address, user agent and external ID are all sent from the server. Our health and wellness page explains how Upstack restores purchase optimization, step by step.

None of this changes your ad policy obligations. Your ads and landing pages still have to follow Meta's rules, and what each event contains is still your responsibility.


Frequently asked questions

Does Meta's Core Setup block purchase events?

No. Core Setup restricts custom parameters and URL paths, while standard events and parameters such as value and currency keep flowing. Restricting specific mid and lower funnel events is a separate tier that Meta notifies advertisers about by email and in Events Manager.

Can you turn off Core Setup?

Only if you or someone on your account turned it on. Meta's core setup settings guide says you can't turn it off if Meta applied it. You can request a review of a Meta-assigned category, though in our experience these rarely succeed.

Will a new pixel fix a health and wellness restriction?

Not on its own. A new pixel on the same domain that receives the same events is usually flagged again, often within days, because Meta categorizes the domain and the data. In the accounts we work with, what works is a new pixel that receives only filtered, server-side events from a neutral domain, with nothing else connected to it, optimized on the standard Purchase event.

Do supplements count as health and wellness on Meta?

Often, yes. Meta's category covers health-related products and services, and its prohibited information list names supplements for specific medical conditions. In the accounts we audit, Meta's definition reaches further than most brands expect, including skincare with active claims, fitness and sexual wellness.

Is it allowed to remove product details from Meta events?

Yes. Meta tells advertisers to review content names, custom properties and URL parameters and keep prohibited information out. Removing product and condition details while keeping hashed identifiers, value and currency is data minimization, though it doesn't remove a category Meta has assigned.


Key takeaways

  • Meta's restrictions come in three tiers: Core Setup, restricted events and full restrictions.
  • Meta categorizes by your site's topics and products; a Meta-assigned category can only be reviewed, not edited.
  • Health ad policies and data restrictions are separate systems. Check both.
  • Server-side tracking alone fixes nothing: if a field is in the payload, Meta still receives it.
  • A new pixel or ad account alone doesn't help, and custom-event workarounds stopped working in January 2026.
  • What works is a clean pixel that receives only filtered, server-side events and optimizes on standard Purchase.
  • Stop sending product and condition details; keep sending hashed identifiers, click ID, IP, user agent, value and currency.

Request a demo and we'll review what your Meta payload sends today.

Want similar results?

Start free for 21 days and see what clean signal does for your performance. No card, no contract.