Question Posted by the DataCops team

My email and phone are hashed. Why is Meta still treating my data as health?

Short answer

Hashing protects the identity in transit, but the event can still say what was bought. Keep hashed email, phone and the click ID, and remove product names, page links and fields like gender and date of birth.

Because hashing protects one thing, and the restriction is about another.

Hashing turns an email address into a long string before it leaves your site, so the address itself does not travel in the clear. Meta hashes its own records the same way and compares the strings to find the person. That is the point of it: Meta can match a sale to a person without you sending their email in plain text.

Now look at what else is in the event. If it says Purchase, with a product name like a prenatal vitamin or a pain relief brace, and a link to that product's page, then Meta has learned that a specific person bought that product. Hashing hid how you identified them. It did not hide what they bought.

This is why high match quality does not mean you are safe. In the restricted maternity store we worked on, the founder pointed out that match quality was high and the data was hashed. Both were true. The high match quality only meant Meta knew exactly who had bought each pregnancy-related product.

The fix is to keep the hashing and remove the description. Keep the hashed email and phone, the click ID, the value and currency, and an event ID. Remove the product name, the page link, the page title, cart items, form answers, and optional matching fields that add nothing but a clue, such as gender and date of birth.

Does removing the product name hurt optimisation? A little, probably, and we do not pretend otherwise. But on a health-adjacent site the alternative is a restriction that takes away far more.

Have you seen match quality drop after cleaning the payload? By how much?

For reference, DataCops Health mode keeps the hashed contact details and the click ID for matching, and drops everything that describes what was bought.

DataCops in short

For this question: Health mode sends Meta a fixed list of fields only: the click ID, hashed email and phone, value, currency, IDs and the homepage address, under a neutral event name, and the delivery log shows exactly what left.

DataCops is a tool that keeps condition details out of what your ad platforms see: Health mode cuts page links to the domain, uses neutral event names and leaves out anything that describes a condition, while a bot verdict on every visit and a delivery log show what left and what was real.

How DataCops does it

  • Health mode. Page links are cut to the domain, event names are neutral, and anything that describes a condition is left out before an event leaves.
  • A log of exactly what left. A delivery log row per conversion, sent, held, skipped or failed, with the reason, which is the record you want when explaining yourself to a reviewer.
  • Real people only. Every visit gets a bot verdict against 360+ billion IPs and 350+ monitoring points, with a Real people only switch per ad platform, off by default.
  • One script, one DNS record. Collection runs on your own domain, and conversions go server-side to Meta, Google Ads, TikTok and LinkedIn, counted once against the pixel.
  • The booking after the form. HighLevel natively, any CRM by webhook, sent as neutral events so a booked consultation still teaches the ads who converts.

Best for: clinics, telehealth and wellness brands, and agencies running health ads, who want conversions to keep counting without condition details in the data.

Ads Warmup: tell the ads who pays

Ads Warmup, DataCops' flagship feature, sends customers you already have to Meta, Google Ads and TikTok before a new campaign spends: upload a CSV (only email is required, up to 20,000 rows), see a 0 to 10 match score per person, pick the event, and send. Rows are dated when you send, and Google Ads credits only people who clicked a Google ad. Preview is free; sending needs a paid plan. Check your own consent basis for the list first. See Ads Warmup.

Ways to do this job

OptionBest for
DataCopsHealth mode, neutral events and a delivery log, server-side to four ad platforms
Manual event cleanup in your site and tag managerTeams with an engineer who will maintain it
Turning conversion tracking offAccounts that cannot risk any event

When not to use DataCops

  • You need legal or compliance advice. DataCops is not legal advice and does not make an ad account compliant. Your own advisers decide what you may send.
  • You need a regulated setup with a signed agreement. That is the Enterprise plan: talk to the team.

More on this: Meta health restrictions, explained, and the complete guide to offline conversion tracking.

1 comment

Comments (1)

DataCops team author · 30 Sep 2026

Hashing is necessary. It is just not sufficient on its own.

1
Replies from DataCops account holders are coming soon. Until then, questions about your own setup can go to the team.

More threads

See what your own setup is missing

Send CRM sales back to the ad click that started them, logged per send.

Setup in 5 minutes. No credit card.

Live traffic quality

Updated just now

Visits · last 24h

487
Real users
35873.5%
Bots · auto-filtered
12926.5%

Without filtering, 26.5% of your reported traffic is bot noise inflating dashboards and draining ad spend.

Don't trust your analytics!

Make confident, data-driven decisions withactionable ad spend insights.

Setup in 2 minutes
No credit card