Meta Pixel and Conversions API Setup
By CodexierPublished 7 min read
If you advertise on Facebook or Instagram, Meta's algorithm decides who sees your ads based on who converted before. That decision is only as good as the conversion data you send back. The Pixel sends it from the browser, the Conversions API sends it from your server, and the two together, correctly deduplicated and consent-aware, give the algorithm a truthful picture. This guide sets that up for a Swedish business without breaking GDPR or your own reports.
Pixel vs Conversions API
The Pixel has been the standard for a decade: a script that fires on page views and on actions such as add to cart or purchase, sending them with browser identifiers to Meta. Its weakness is that it lives in the browser, where Safari's tracking prevention, Firefox, ad blockers and, in Europe, the consent banner all reduce what it sees. The Conversions API moves the sending to a place you control: your webshop's backend, a server-side tag manager or an integration app in Shopify or WooCommerce. It can include data the browser never had, such as an order confirmed by the payment provider or a lead that qualified in the CRM days later. It does not replace the Pixel; the two complement each other, and Meta expects both.
Events worth sending
The temptation is to send every click. The useful set is small and mirrors your funnel, with parameters that let Meta value each event. For a webshop that is view content, add to cart, initiate checkout and purchase, with value, currency and content IDs. For a service business it is lead, schedule and, if you use one, a qualified lead sent from the CRM. Each event must fire once per real action, with the same parameters from the browser and the server.
| Event | Sent by | Key parameters | Note |
|---|---|---|---|
| PageView | Browser | None | Baseline; not worth sending server-side |
| ViewContent | Browser | content_ids, content_type, value | Product pages; feeds catalogue ads |
| AddToCart | Browser and server | content_ids, value, currency | Deduplicate; server copy survives blockers |
| InitiateCheckout | Browser and server | value, currency, num_items | Useful for abandoned-checkout audiences |
| Purchase | Server primarily, browser as backup | value, currency, order_id as event_id | Send from the order confirmation on the backend |
| Lead | Server preferred | event_id, lead source | From the form handler or CRM, not just the thank-you page |
Values in SEK with currency set to SEK. Sending gross order value including VAT is common; whichever you choose, be consistent so the return on ad spend is comparable over time.
Deduplication between the two
When the same purchase arrives from the browser and from the server, Meta needs to know it is one event. The mechanism is a shared event ID: the browser sends event_id with the Pixel call, the server sends the same value as event_id in the API call, and Meta keeps one. The natural choice for purchases is the order number; for leads, a unique form submission ID generated when the form is rendered and passed to both sides. The event name must also match exactly, and the two events should arrive within a short window. Without this, every purchase counts twice, your reported return on ad spend doubles, and the algorithm optimises toward a fiction.
- Generate the event ID once, on the page or in the order, and pass the same value to the Pixel and to the API.
- Use identical event names and parameter values on both sides.
- Send the server event promptly; a delayed server event may not deduplicate.
- Check the deduplication column in Events Manager after setup; it should show a high rate for every dual-sent event.
Consent and data minimisation
Moving events to the server does not move them out of GDPR. The Conversions API sends personal data, including hashed email, phone, IP address and browser identifiers, to Meta in the United States. In Sweden, IMY's position and the ePrivacy rules mean marketing tracking requires consent, and that applies whether the request leaves from a browser or from your server. So the server-side integration must read the visitor's consent state and send marketing events only when consent was given. Server-side is a delivery mechanism that beats blockers, not a way around the banner. What you can do is minimise: send only the parameters that improve match quality, hash them as Meta requires, and do not send events for consent-declined visitors at all.
Consent signal
Pass the consent state from your banner to the server integration; block marketing events when it is missing or declined.
Customer information parameters
Email and phone, hashed with SHA-256, plus external ID improve match quality. Send what the customer gave you in the transaction, nothing scraped.
Data processing options
Use Meta's limited data use settings where applicable, and document the transfer in your privacy notice and records of processing.
Privacy notice
Name Meta as a recipient, state the purpose and the legal basis, and explain how to withdraw consent.
Testing in Events Manager
Events Manager has a Test Events tab where you can see browser and server events arrive in real time, with a test code that keeps them out of production data. Walk through the funnel yourself: view a product, add to cart, start checkout and complete a test order. For each step you should see the browser event and the server event with the same event ID, and a deduplicated indicator. Then check the event match quality score, which tells you how well Meta could match the customer parameters to real accounts; a low score means parameters are missing or hashed wrongly. Finally, repeat the walk with consent declined and confirm nothing marketing-related arrives.
When you do not need this: if you do not run Meta ads, do not install the Pixel at all; it adds a third-party data flow you have to explain to visitors for no benefit. And if your ad budget is small and campaigns are occasional, the Pixel alone with a proper consent setup is fine; the Conversions API earns its setup cost once you optimise on purchases or leads continuously. This work is what our tracking and analytics setup covers, alongside GA4 and consent mode. Whether your setup is double-counting today is something we can see in a 15-minute call, together with the crawl and indexing basics in the technical SEO audit checklist.
- Tracking and analytics setupPixel, Conversions API, GA4 and consent mode set up together, tested and documented.
- Technical SEO audit checklistThe organic side of the same measurement foundation.
- Book a free 15-minute callShare access to Events Manager and we tell you what is being double-counted or lost.
Frequently asked questions
Do I still need the Pixel if I use the Conversions API?
Yes. The Pixel supplies browser signals that help matching and covers events the server does not see, such as product views. Meta recommends running both with deduplication. The API is a second path, not a replacement.
Does the Conversions API let me skip cookie consent?
No. It sends personal data to Meta regardless of where the request originates. Under GDPR and Swedish practice you need consent for marketing tracking, and the server integration must respect the visitor's choice. Server-side improves delivery for consenting visitors; it does not add non-consenting ones.
How do I set it up on Shopify or WooCommerce?
Shopify's Facebook and Instagram app sends server events natively with deduplication handled for standard events. WooCommerce needs a plugin or a server-side tag manager. In both cases you still have to connect the consent banner and verify deduplication in Events Manager; the apps do not do that for you.
What is a good event match quality score?
Meta rates it out of ten. Scores improve with hashed email, phone, name, external ID and browser identifiers sent correctly. For a webshop sending purchase events with the customer's checkout details, a good score is realistic; a low one usually means a parameter is missing or formatted wrongly before hashing.
Not sure whether your Meta data is double-counted or half missing?
Fifteen minutes with an engineer: give us read access to Events Manager and we show you the deduplication rate, the match quality and what the consent setup is doing to your numbers.
Book a free 15-minute call