
Acquisition to intake
Meta Ads to Legal Intake: A Privacy-Safe Handoff Architecture
A technical handoff model for moving a Meta campaign response into secure legal intake without returning claimant facts to Meta business tools.
Meta ads for law firms should end at a privacy boundary. The ad, landing page, and coarse quiz may establish campaign context and a person's willingness to continue. Sensitive claimant facts and documents belong in secure, firm-controlled legal intake. The handoff should remove campaign query strings, create a new intake record, preserve the approved source data, and stop Meta business tools from receiving the facts collected after that point.
Draw the boundary before building the funnel
A campaign funnel and a legal intake system have different jobs. The campaign explains the subject, records a limited response, and moves an interested person to the firm's next step. Intake identifies the prospective claimant, asks case-type questions, collects supporting evidence, and prepares a review-ready file for authorized staff.
Combining those jobs creates an avoidable data path. A diagnosis entered into a campaign quiz can appear in analytics, URLs, form exports, tag-manager logs, or downstream automation before anyone has reviewed whether the collection was appropriate. A broad event name can disclose an injury or exposure category even when the event carries no separate value. A document uploaded before the handoff can enter systems that were configured for campaign measurement rather than prospective-client information.
The boundary should be a technical control, not a note in a launch checklist. The sensitive form begins on a firm-controlled domain or approved subdomain. Meta Pixel, Conversions API, campaign scripts, replay tools, and unrelated analytics do not load on that intake surface unless firm counsel and privacy staff approve a narrowly defined use. Query strings are stripped before the first sensitive question is displayed.
Meta's guide to lead ads with forms describes both instant forms and website forms. It identifies a website form as the path when a person needs to take a specific action or share sensitive information. A law firm should treat that product choice as the start of its own review, not as permission to collect any legal or medical detail through advertising tools.
The handoff architecture
The safest design assigns one data purpose and one owner to each layer. Data moves forward only when the next system needs it. Sensitive intake data never moves backward into the campaign layer.
| Layer | Operational job | Data allowed at this layer | Required control | System of record |
|---|---|---|---|---|
| Meta ad | Explain the campaign topic and offer a next step | Campaign and ad identifiers approved for use | No claimant facts in creative, event names, or destination parameters | Campaign platform |
| Landing page | Provide public information and record coarse engagement | Landing-page identifier and approved campaign attribution | No sensitive questions, no uploaded records, no legal narrative | Public web analytics under firm policy |
| Coarse quiz | Determine whether the visitor wants the secure intake path | Limited non-sensitive routing answers approved by firm counsel and privacy staff | Keep the quiz noindex, reject free text, and stop before sensitive categories |
Minimal campaign record |
| Handoff service | Create a controlled transition | Opaque one-time handoff reference and approved source metadata | Remove query strings, expire the reference, and prevent source values from appearing in the URL | Firm-controlled handoff log |
| Secure intake | Collect the facts and evidence needed for firm review | Identity, case-type answers, documents, consent, corrections, and source history | No campaign tags or Meta business tools on sensitive pages unless specifically approved | Firm-controlled intake record |
| Review queue | Present a review-ready file and unresolved gaps | Structured facts, evidence, provenance, exceptions, and review history | Only authorized firm roles make legal, conflict, qualification, or engagement decisions | Governed case record |
The handoff reference should identify a server-side record, not encode campaign data in a visible token. It should be short-lived, single-use where practical, and useless outside the destination. The intake service can resolve the reference, copy only approved source fields into the new record, and record when the transfer occurred. It should not preserve the visitor's incoming query string on the secure route.
Keep the ad and coarse quiz coarse
The campaign layer needs less information than many funnel builders assume. It may need to know which landing page produced the transition and whether the visitor started the approved quiz. It does not need the person's case narrative to perform that job.
Do not collect or send any of the following through a Meta instant form, Meta Pixel, Conversions API, campaign URL, ad event, or campaign-side quiz:
- diagnoses, injuries, symptoms, treatment, medication, or disability
- exposure facts, dates, locations, products, employers, or suspected causes
- legal narrative, allegations, claimed loss, financial harm, or dispute details
- document names, document contents, extracted document facts, or upload metadata
- Social Security, insurance, medical-record, government, or case identifiers
- claimant names, email addresses, phone numbers, or other identifiers beyond controls expressly permitted and approved for the defined campaign use
Meta's Lead Ad Terms place responsibility on the advertiser for the lead feature, required disclosures, permissions, use of lead data, and compliance with applicable requirements. Those terms also restrict sensitive or prohibited collection. The Meta Commercial Terms govern business use of Meta products and place compliance duties on the business using them. Firm counsel and privacy staff should review the current versions, the firm's jurisdiction, campaign design, notices, consent language, vendors, retention rules, and permitted contact fields before launch.
If the firm approves a Meta instant form, keep it to the minimum information needed for the approved next step. The secure intake must still begin before case facts are requested.
The coarse quiz should use fixed choices and provide a neutral path to secure intake. Avoid free-text fields because they invite a person to disclose facts the campaign layer was not designed to hold. If a coarse question is skipped, record it as unanswered. Do not translate a skipped answer into "no," "not eligible," or an unknown case fact. Unknown and unanswered become useful states only after the firm asks an approved intake question in the secure system.
Use only coarse campaign events
Event design can disclose claimant information even without a form field. An event label that names a diagnosis or a URL containing an exposure type reveals a fact through the label itself. A custom parameter can carry the same risk. The event vocabulary should describe progress through the public funnel, not the person's legal or medical circumstances.
Use only these example events for this architecture:
| Event | Meaning | Data rule |
|---|---|---|
landing_view |
The approved public landing page loaded | No sensitive parameters or claimant facts |
quiz_started |
The visitor began the approved coarse quiz | No answer values or claimant identifiers in the event |
handoff_to_secure_intake |
The browser left the campaign layer for the protected intake destination | No destination query string, case type, or claimant detail in the event |
secure_intake_completed |
The firm-controlled system recorded completion | Send no answers, documents, qualification result, reviewer decision, or claimant identifiers |
Do not create dynamic event names from quiz answers. Do not include diagnoses, injuries, exposure facts, narrative, document content, qualification state, or intake field values as event parameters. The completion event reports a coarse transition only. It does not report whether the firm considers the inquiry viable.
Meta describes the Conversions API as a connection through which marketing data can be sent from a server, website, app, or CRM to Meta for measurement and optimization. Server-side delivery does not make claimant data suitable for advertising systems. It changes the transmission path. The firm's allowlist should apply to both browser and server events, and a blocked field should remain blocked in each path.
Build the secure intake as the case record's first stage
After the handoff, the client intake process can ask the questions that the case type requires. The record should preserve the notice shown, consent state, original answer, correction history, uploaded evidence, source location, and assigned review queue. A mass tort intake process may add campaign criteria, expected-evidence lists, duplicate review, and high-volume exception queues.
The intake system should distinguish answered, unknown, unanswered, not asked, and needs-confirmation states. A claimant who does not know a treatment date needs different follow-up from someone who left the field blank. Neither state should be inferred in the campaign system.
Each accepted handoff should create one prospective-claimant record. Duplicate matching can compare the new submission with existing intake records under firm policy. A possible match belongs in a staff queue. It should not cause the browser to reveal whether another person or record exists.
Documents should enter through the secure intake destination. Retain the original file, receipt time, submitter, request that prompted it, and any proposed classification. If software extracts a fact, keep the proposal linked to its source and require the firm's configured review for material values. The campaign layer receives no document-derived status.
Preserve evidence about the handoff
A reviewable implementation needs evidence of what happened at the boundary. Keep a versioned configuration for the landing page, quiz, notice, handoff endpoint, approved event allowlist, and prohibited-field rules. Record who approved each version and when it became active.
For each transition, the firm-controlled log should show the campaign source fields that were accepted, the handoff configuration version, the time of transfer, the secure intake record created, and any rejected input. Access to that log should follow the firm's role and retention policy.
Test controls with synthetic data. Enter a diagnosis in every campaign-side free-text surface that remains. Place an injury term in a query string. Try to pass a document name as an analytics value. Confirm that the handoff rejects or removes each value, that sensitive pages load without unapproved campaign tags, and that no blocked value appears in browser requests, server logs, event tools, or campaign exports.
Assign review and ownership
The campaign owner controls creative and landing-page deployment within the approved design. The intake owner controls questions, evidence requests, state definitions, and queues. Engineering controls the handoff, script boundary, event allowlist, logging, and test evidence. Firm counsel and privacy staff control the final implementation, including applicable legal requirements, Meta terms, notices, consent, data scope, vendor access, retention, and any allowed identifier use.
No automated result should decide conflict resolution, legal merit, qualification, representation, deadline treatment, or advice. The secure workflow may assemble facts and route gaps. A lawyer or authorized firm staff member makes the decision under the firm's rules.
Before launch, require written approval of the data inventory and inspect the real network traffic from the public funnel through the secure intake completion page. Repeat that review when Meta terms, campaign questions, vendors, tags, or intake fields change.
Implementation checklist
- Publish the public landing page without sensitive questions.
- Keep the coarse campaign quiz
noindexand free of open narrative fields. - Place secure intake on a firm-controlled domain or approved subdomain.
- Strip query strings before sensitive intake begins.
- Use an opaque, expiring handoff reference instead of encoded claimant data.
- Allow only
landing_view,quiz_started,handoff_to_secure_intake, andsecure_intake_completedas example campaign events. - Confirm that event names and parameters contain no sensitive facts or claimant identifiers.
- Keep Meta Pixel and Conversions API outside the sensitive intake surface unless the firm approves a narrow configuration.
- Preserve the handoff version, source, timestamp, rejected inputs, and destination record in a controlled log.
- Test blocked fields and network traffic with synthetic records.
- Require firm counsel and privacy staff to approve the final implementation and every material change.
This architecture gives acquisition a defined endpoint. Meta can support discovery and approved coarse measurement. The firm's secure intake owns the claimant facts, documents, provenance, correction history, and review path that form the beginning of the case record.
Start with one case type