How to add a Privacy Policy Link to Facebook Lead Ads
By Paul Cranmer, Founder · Last verified August 2026 · Meta Ads Manager · Instant Forms
It is 10pm. Your Facebook lead ad is ready, then Instant Forms blocks publish because Privacy Policy URL is empty. Meta will not let the form go live without a public link that explains how you use the lead data people submit. This page shows the exact field, what to paste, and how to confirm it works on mobile.
Who this is for
- Small business owners and solo marketers launching Facebook or Instagram lead ads
- Anyone stuck on the Privacy Policy URL field inside an Instant Form
- Agencies pasting a client’s live policy link so the form can publish tonight
Not for
- A full Meta Ads Manager course (we only cover the privacy link gate)
- Legal advice or a custom attorney-drafted policy for every jurisdiction
- App Store or Chrome extension listings (those use a different free path)
What the platform requires
- Every lead ad Instant Form needs a privacy policy URL in the Privacy section before you can publish.
- The URL must open a normal web page. Meta says it cannot link directly to a PDF, image, or file download.
- You can reuse an existing business privacy policy if it covers how you handle lead form data. You do not need a Meta-only policy page.
- The page should be public (no login wall), load on mobile, and clearly belong to your business, not Meta’s own privacy policy.
Get a live URL first
You need a live HTTPS page that names your business, explains what you collect from the form, and shows a contact email. Privacy Policy URL hosts that page for ads and lead forms at $9.99/yr while active. Mobile apps, browser extensions, and API/SDK listings stay on the free path. Answer a few questions, get the link, then paste it below.
Get unblocked nowStep-by-step: paste your privacy policy URL
- Open the Instant Form. In Meta Ads Manager, create or edit a lead ad that uses an Instant Form (sometimes labeled Lead form). Open the form editor for the form attached to this campaign.
- Go to Privacy. In the form builder, open the Privacy section. This is where Meta requires your public privacy policy link before the form can publish.
- Paste Privacy Policy URL. Click to add or edit the privacy policy, then paste your live HTTPS URL into the Privacy Policy URL field. Leave Link text as “Privacy Policy” unless you have a clearer brand-safe label.
- Preview on mobile. Use Preview and tap the policy link on a phone-sized view. Confirm the page opens fast, shows your business name, and does not ask for a login.
- Publish and spot-check. Save the form, publish the ad, and run a tiny test if you can. If Meta flags the form, re-check that the URL loads in a private browser and that the policy names your company.
- Keep one stable URL. Use the same link in your website footer when you have one. Update the policy text when practices change, but keep the URL stable so you do not rebuild every form.
Field labels to look for
- Privacy Policy URL
- Required field inside the Instant Form Privacy section. Paste a full https:// link to a live HTML page.
- Link text
- Optional label people see on the form (often “Privacy Policy”). Keep it plain so leads know what they are opening.
- Privacy / Instant Form settings
- If you cannot find the field, you are probably in the ad creative only. Open the Lead form / Instant Form editor, not just the campaign budget screen.
Common reasons the form fails
- Empty Privacy Policy URL (the form will not publish).
- PDF, Google Doc export, or image link instead of a web page.
- Link to Meta’s privacy policy instead of your own.
- Page behind login, geo-block, or a soft 404.
- Policy that never names your business or how lead data is used.
- Brand name on the ad that does not match the policy page.
Instagram and other placements
Facebook and Instagram lead ads that share the same Instant Form use the same privacy policy URL. You do not need a second policy page for Instagram placements on that form. If you build a separate Instant Form, paste the same stable URL again.
FAQ
Do I need a privacy policy link for Facebook lead ads?
Yes. Instant Forms require a public privacy policy URL in the Privacy section. Without it, Meta will not let you publish the form.
Can I use my homepage as the privacy policy URL?
Usually no. Reviewers and people on the form expect a dedicated privacy policy page, not a marketing homepage. Use a page that clearly explains data use and contact details.
Can the policy be a PDF?
Meta’s help center says the privacy policy cannot link directly to a PDF, image, or direct download. Use a normal HTTPS web page.
Do I need a brand-new policy only for Meta?
No. Meta says you can use an existing business privacy policy URL if it covers your lead handling. Keep one stable URL and update the text when practices change.
What should the policy page include for lead ads?
Name your business, say you collect lead form details (such as name, email, phone), explain why you use that data, note any sharing with tools you use, and give a contact email for privacy questions.
Is Privacy Policy URL free for Facebook ads?
Ads, lead forms, and stores use the $9.99/yr hosted plan while active. Mobile App, Browser Extension, and API/SDK stay free. Cancel anytime; your link stays live while the plan is active.
Does Instagram need a different URL?
Not for the same Instant Form. Instagram placements on that form reuse the same Privacy Policy URL. Separate forms should paste the same stable link.
What if Meta disapproves after I publish?
Open the URL in a private mobile browser, confirm it is your policy (not Meta’s), fix branding mismatches, then update the form and resubmit. Broken or vague pages are the usual cause.