connection: |
close |
content-security-policy: |
upgrade-insecure-requests; |
content-security-policy-report-only: |
font-src fonts.gstatic.com use.typekit.net *.fontawesome.com *.cloudflare.com data: *.gstatic.com *.sagepay.com *.googleapis.com maxcdn.bootstrapcdn.com *.criteo.net *.criteo.com *.tremorhub.com *.mediavine.com *.omnitagjs.com *.klarnacdn.net data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com secure.authorize.net test.authorize.net pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com * *.savile-row.whoson.com *.awin1.com *.zenaps.com *.facebook.com *.criteo.net *.criteo.com *.tremorhub.com *.mediavine.com *.omnitagjs.com *.sagepay.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com 'self' 'unsafe-inline'; frame-ancestors *.google.com savile-row.whoson.com *.savile-row.whoson.com *.zenaps.com *.catalink.com *.awin1.com *.trustpilot.com data: *.gstatic.com *.sagepay.com *.googleapis.com maxcdn.bootstrapcdn.com *.criteo.net *.criteo.com *.tremorhub.com *.mediavine.com *.omnitagjs.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com secure.authorize.net test.authorize.net www.googletagmanager.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ https://widget.trustpilot.com/ https://vars.hotjar.com/ * *.savile-row.whoson.com savile-row.whoson.com *.zenaps.com *.clear-reports.com *.awin1.com *.trust-provider.com *.doubleclick.com *.doubleclick.net *.criteo.net *.criteo.com *.tremorhub.com *.mediavine.com *.omnitagjs.com *.hotjar.com *.trustpilot.com *.facebook.com *.pdmntn.com *.google.com *.dotdigital-pages.com *.dotdigital.com *.sagepay.com *.addthis.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com 'self' data: www.googleadservices.com www.google-analytics.com www.paypalobjects.com t.paypal.com *.ftcdn.net *.behance.net data: p.typekit.net www.paypal.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com validator.swagger.io https://lantern.roeye.com https://bat.bing.com https://pixel.quantserve.com https://www.google.com https://www.google.co.uk https://www.facebook.com https://images.clickdealer.co.uk *.cloudflare.com *.superbikefactory.co.uk *.instagram.com *.cdninstagram.com services.postcodeanywhere.co.uk *.whoson.com * *.zenaps.com *.catalink.com *.clear-reports.com *.awin1.com *.doubleclick.net pixel.tapad.com pixel-sync.sitescout.com ad.turn.com *.criteo.net *.omnitagjs.com *.mediavine.com *.smaato.net *.smartclip.net *.taboola.com *.outbrain.com *.criteo.com *.liadm.com *.ivitrack.com/ *.tremorhub.com/ *.yieldmo.com/ *.gstatic.com *.advertising.com *.yahoo.com *.openx.net *.adnxs.com *.mgid.com *.adform.net *.amazon.com *.payments-amazon.com *.adsymptotic.com *.linkedin.com *.facebook.com *.bing.com *.riskified.com *.nosto.com *.trust-provider.com *.googleadservices.com *.google-analytics.com *.paypal.com *.ytimg.com *.cloudfront.net maxcdn.bootstrapcdn.com *.dwin1.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com secure.authorize.net test.authorize.net unpkg.com commerce.adobedtm.com www.googleadservices.com www.google-analytics.com www.googletagmanager.com www.paypalobjects.com js.braintreegateway.com www.paypal.com amcglobal.sc.omtrdc.net commerce.adobe.net use.typekit.net www.sandbox.paypal.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ https://lantern.roeyecdn.com https://static.elfsight.com https://apps.elfsight.com https://cdn.segment.com https://static.hotjar.com https://script.hotjar.com https://connect.facebook.net https://bat.bing.com https://api.visitor.chat https://cdn.visitor.chat https://widget.trustpilot.com https://www.gstatic.com https://js-agent.newrelic.com https://bam.nr-data.net https://cdn.popt.in https://secure.quantserve.com https://rules.quantcount.com https://googleads.g.doubleclick.net https://cdnjs.cloudflare.com *.cloudflare.com *.clarity.ms *.amazonaws.com wss://cs-alb.visitor.chat:53087/socket.io/ *.visitor.chat *.visitor.chat:53087 *.cloudfront.net *.superbikefactory.co.uk *.braze.eu *.jsdelivr.net cookiebot.com *.cookiebot.com *.newrelic.com *.nr-data.net services.postcodeanywhere.co.uk savile-row.whoson.com *.whoson.com *.zenaps.com *.catalink.com *.clear-reports.com *.bing.com *.hotjar.com *.pdmntn.com *.doubleclick.com *.doubleclick.net *.dwin1.com *.awin1.com *.trust-provider.com *.trustpilot.com *.nosto.com *.popupdomination.com *.criteo.net *.criteo.com *.tremorhub.com *.mediavine.com *.omnitagjs.com *.licdn.com *.facebook.net *.riskified.com *.google-analytics.com *.gstatic.com *.google.com *.amazon.co.uk *.amazon.com *.payments-amazon.com *.paypalobjects.com *.paypal.com *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com *.klarnacdn.net *.klarnaservices.com *.klarnauserservices.com *.zdassets.com timeandtidestores.zendesk.com widget-mediator.zopim.com *.feefo.com s7.addthis.com *.sagepay.com *.addthis.com *.moatads.com *.addthisedge.com *.pinterest.com *.avada.io assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com songbirdstag.cardinalcommerce.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.cloudflare.com *.superbikefactory.co.uk *.braze.eu *.jsdelivr.net services.postcodeanywhere.co.uk *.googleapis.com *.whoson.com *.gstatic.com *.trustedshops.com *.usercentrics.eu maxcdn.bootstrapcdn.com *.criteo.net *.criteo.com *.tremorhub.com *.mediavine.com *.omnitagjs.com *.fontawesome.com *.klarnacdn.net unsafe-inline assets.braintreegateway.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com api.magento.com commerce.adobe.io commerce.adobedtm.com commerce.adobedc.net www.google-analytics.com *.adobe.io performance.typekit.net www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com commerce.adobe.net qa-api.magedevteam.com https://region1.google-analytics.com https://www.google-analytics.com https://cdn.segment.com https://stats.g.doubleclick.net https://api.visitor.chat https://www.googleadservices.com https://www.google.co.uk https://api.segment.io https://display.popt.in https://bam.nr-data.net https://in.hotjar.com * *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com *.klarnacdn.net *.klarnaservices.com *.klarnauserservices.com *.zdassets.com timeandtidestores.zendesk.com widget-mediator.zopim.com *.feefo.com ekr.zdassets.com/ *.sagepay.com *.addthis.com https://get.geojs.io *.avada.io api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com 'self'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.newrelic.com *.nr-data.net 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; |
content-type: |
text/html; charset=UTF-8 |
expires: |
Mon, 07 Oct 2024 20:39:23 GMT |
pragma: |
cache |
traceresponse: |
00-17fbf7a3839183190da06523f74ad8c3-33f01bd760ed2473-01 |
x-content-type-options: |
nosniff |
x-debug-info: |
eyJyZXRyaWVzIjowfQ== |
x-esi: |
1 |
x-frame-options: |
SAMEORIGIN |
x-platform-server: |
i-0a03099d56aab61d5, i-0a03099d56aab61d5 |
x-xss-protection: |
1; mode=block |
accept-ranges: |
bytes |
age: |
361 |
date: |
Sun, 06 Oct 2024 20:45:25 GMT |
x-served-by: |
cache-lhr-egll1980035-LHR, cache-ams2100115-AMS |
x-cache: |
HIT, MISS |
x-cache-hits: |
10, 0 |
cache-control: |
no-store, no-cache, must-revalidate, max-age=0 |
vary: |
Accept-Encoding,Cookie |
strict-transport-security: |
max-age=31557600 |
transfer-encoding: |
chunked |