Skip to content
HDHD Agency
trackingPixel & CAPIaccount health

Facebook Pixel + CAPI Setup Guide to Avoid Bans

Set up Meta Pixel and Conversions API correctly: deduplication, hashed data, domain verification and signals that protect your ad account.

HHHung Hien · · 6 min read
Table of contents
  1. Why tracking quality affects account health
  2. Pixel vs Conversions API: what each does
  3. Step 1: Verify your domain
  4. Step 2: Install the Pixel base code
  5. Step 3: Send the same events through CAPI
  6. Hash personal data correctly
  7. Step 4: Deduplicate browser and server events
  8. Step 5: Improve Event Match Quality
  9. Step 6: Configure Aggregated Event Measurement
  10. What not to send
  11. Using your pixel with a rented account
  12. Testing your setup before you spend
  13. Choosing a CAPI implementation
  14. Quick checklist

Most advertisers think of the Meta Pixel as a measurement tool. At scale, it's much more: it's the data feed that tells Meta's algorithm who your customers are, and it's part of the evidence Meta uses to judge whether your business is legitimate. A clean, complete Pixel and Conversions API (CAPI) setup improves results — and a sloppy one can put your account at risk.

This guide walks through a setup that works on your own accounts and on any account you get through facebook ads account rental.

Why tracking quality affects account health

Meta's systems look at the whole picture of an advertiser. A business that sends consistent, high-quality conversion events from a verified domain looks like what it is: a real company with real customers. An account that drives traffic to a domain with no events, broken events or suspicious data patterns looks riskier.

Tracking also affects cost. Better data means better optimization, which means lower CPA and fewer wasted impressions. In our client base, moving from Pixel-only to Pixel plus properly deduplicated CAPI lowers CPA by 10–25% on average.

Pixel vs Conversions API: what each does

Meta PixelConversions API
Runs inVisitor's browserYour server
Affected by ad blockersYesNo
Affected by iOS/Safari limitsYesMuch less
Can send offline eventsNoYes
Setup difficultyEasyModerate

You want both. The Pixel catches what it can in the browser; CAPI sends the same events from your server so nothing is lost.

Step 1: Verify your domain

In Business Settings, go to Brand Safety → Domains and add your domain. Verify with a DNS TXT record (recommended) or a meta-tag. Domain verification proves you control the site and is required for configuring web events.

If you're using a rented Business Manager, verify the domain in the BM that owns your pixel — ideally your own BM, so ownership stays with you.

Step 2: Install the Pixel base code

Add the base code to every page, inside the head. It initializes the pixel and fires a PageView event. On single-page apps (Next.js, React), also fire PageView on route changes.

Then add standard events where they happen:

  • ViewContent on product pages
  • AddToCart when an item is added
  • InitiateCheckout at checkout start
  • Purchase on the thank-you page, with value and currency
  • Lead when a form is submitted

Use standard event names wherever possible. Custom events can't be used for optimization as easily.

Step 3: Send the same events through CAPI

Your server sends events to the Graph API endpoint for your pixel with an access token generated in Events Manager. Each event needs:

  • event_name — matching the browser event (for example, Lead)
  • event_time — Unix timestamp in seconds
  • event_id — a unique ID, identical to the one sent by the browser
  • action_source — "website"
  • event_source_url — the page where the event happened
  • user_data — hashed customer information plus IP and user agent

Hash personal data correctly

Email, phone, first name, last name, city and external ID must be normalized and hashed with SHA-256 before sending:

  • Email: trim spaces, lowercase, then hash.
  • Phone: digits only including country code, then hash.
  • Names: lowercase, no punctuation, then hash.

Never send raw personal data. IP address, user agent and the fbp and fbc cookie values are sent unhashed.

Step 4: Deduplicate browser and server events

If both the Pixel and CAPI send a Lead event, Meta will count it twice unless you deduplicate. The rule is simple: send the same event_name and event_id from both. Generate the ID in the browser when the form is submitted, pass it to the Pixel as eventID, and send it to your server with the form data so CAPI uses the same value.

In Events Manager, the event details show a "Deduplicated" status when it works.

Step 5: Improve Event Match Quality

Event Match Quality (EMQ) scores how well Meta can match your events to real people. Raise it by sending more identifiers with each server event:

  1. Hashed email (biggest impact)
  2. Hashed phone number
  3. fbp and fbc cookies
  4. Client IP address and user agent
  5. Hashed external ID (your customer ID)

Most of our clients go from an EMQ of 4–6 to 8+ within a week of switching on full CAPI.

Step 6: Configure Aggregated Event Measurement

For iOS traffic, rank your conversion events by priority in Events Manager. Put your most valuable event (Purchase or Lead) at the top. Only the highest-priority event completed in a session is reported for opted-out iOS users.

What not to send

Some data can get your pixel or account restricted:

  • Sensitive categories. Don't send health conditions, financial status or other sensitive information in URLs, event parameters or content names.
  • Unhashed PII in any parameter, including in URL query strings.
  • Events from pages you don't own.

Audit your URLs: a thank-you page like /thank-you?email=john@example.com leaks PII to the Pixel automatically.

Using your pixel with a rented account

When you rent a Facebook ads account, keep the pixel in your Business Manager and share it with the rented ad account. Your data, audiences and learning stay with you. If the ad account is ever replaced, you share the pixel to the new account and campaigns resume with full history. That's why pixel setup is included in our Growth and Scale plans.

Pair a solid tracking setup with a gradual spend ramp — see how to warm up a rented Facebook ads account — and new accounts exit learning much faster.

Testing your setup before you spend

Before driving real traffic, test the whole chain:

  1. Open Events Manager → Test Events and enter your site URL. Browse your site and complete a test conversion.
  2. Confirm the browser event arrives with the right parameters (value, currency, content IDs).
  3. Send a server test event using the test event code in your CAPI requests. It should appear in the same Test Events view.
  4. Check deduplication. Complete one test conversion; you should see a single deduplicated event, not two.
  5. Review the event details for Event Match Quality and the identifiers received.
  6. Remove the test event code before going live, so production events aren't flagged as tests.

Choosing a CAPI implementation

There are three common ways to implement Conversions API:

MethodEffortFlexibility
Platform integration (Shopify, WooCommerce)LowLimited
Conversions API GatewayMediumGood
Custom server integrationHigherFull control

Ecommerce stores on major platforms should start with the built-in integration and check that it sends email and phone. Lead-gen sites and custom stacks usually benefit from a direct server integration, where the form handler sends the Lead event right after saving the lead.

Quick checklist

  • Domain verified in the BM that owns the pixel
  • Pixel base code on every page, PageView on route change
  • Standard events on key actions
  • CAPI sending the same events with matching event_id
  • Email and phone hashed with SHA-256
  • EMQ of 6+ on your main conversion event
  • No sensitive data in URLs or parameters

For more on keeping accounts healthy, read why your Facebook ads account keeps getting banned.

Want us to set it up for you? Message us — Pixel and CAPI setup is included with every Growth plan.

Frequently asked questions

Do I still need the Pixel if I use Conversions API?

Yes. Meta recommends running both. The Pixel captures browser events and cookies, while CAPI fills the gaps caused by ad blockers and browser privacy features. Deduplication prevents double counting.

What is a good Event Match Quality score?

Aim for 6.0 or higher for Purchase and Lead events. Scores above 8 are excellent and usually come from sending hashed email, phone and external ID with every server event.

Can a bad pixel setup get my account banned?

Tracking alone rarely causes a ban, but sending unhashed personal data or sensitive health or financial information can violate Meta's business tools terms and lead to restrictions.

Can I use the same pixel on a rented agency account?

Yes. You keep ownership of your pixel in your own Business Manager and share it with the rented ad account, so all your historical data stays with you.

HH

Written by

Hung Hien

Founder of HD Agency. 5+ years scaling ecommerce, lead-gen and app offers on Meta across the US and EU, with millions in managed ad spend. Hung writes about ad account infrastructure, tracking and scaling without interruptions.

Message Hung

Stop losing days to dead accounts.

Every day your ads are offline, your competitors take your customers. Message us now — reply in 5 minutes, account shared to your BM right after payment.