webtracking.org
F 16/100

Meta Pixel & Conversions API

Built to send user behavior and hashed identifiers to Meta for ad targeting. The Conversions API moves collection server-side, bypassing browser-based blocking; repeatedly implicated in receiving sensitive data.

verified 2026-06-08 · grade set per the published methodology

How the grade breaks down

Data minimization 0/5

How little it collects, and whether collection is purpose-bound.

Consent honoring 1/5

Whether it respects GPC, consent state, and tracking-prevention signals.

Identifier strategy 1/5

Cookieless vs. persistent IDs, cross-site linkage, fingerprinting risk.

Residency & sharing 1/5

Where data lives and whether it is shared with third parties.

Transparency 1/5

How verifiable and documented its real behavior is.

At a glance

Category advertising-pixel
Cookieless no
Consent for lawful use required
Data residency global
Shares w/ third parties yes
Sends PII by default hashed
Honors GPC no
Open source no

The Meta Pixel transmits page views, events, and hashed user identifiers to Meta to power cross-site ad targeting and measurement, feeding Meta’s advertising graph. The Conversions API (CAPI) sends the same data from the server, which bypasses browser-level ad and tracker blocking and is harder to intercept client-side. The pixel has been repeatedly implicated in transmitting sensitive information (including from health and finance sites) when implemented without strict field controls. It requires consent and does not honor GPC by default. This is a technical description of how the tools operate.

Sources & basis for grade

Grades reflect documented behavior, vendor documentation, and ad.rip scans as of the date above. Each assessment is reproducible and vendors may request correction.

  • Meta Pixel & Conversions API (CAPI) documentation
  • Meta Advanced Matching (hashed PII) docs
  • Public reporting on Meta Pixel sensitive-data transmission (2022-2023)