date: |
Thu, 10 Oct 2024 13:48:04 GMT |
content-type: |
text/html |
transfer-encoding: |
chunked |
connection: |
close |
content-security-policy: |
base-uri 'self'; default-src 'self' data: 'unsafe-inline' 'unsafe-eval' 'strict-dynamic' yscds2.a.searchspring.io *.adsrvr.org *.aftership.com *.akamaihd.net *.bing.com *.boltdns.net *.brightcovecdn.com *.cf.brightcove.com *.creativecdn.com *.criteo.com *.criteo.net *.doubleclick.net *.espssl.com *.g.doubleclick.net *.google-analytics.com *.googletagmanager.com *.listrak.com *.listrakbi.com *.media.brightcove.com *.myunidays.com *.playground.klarna.com *.playground.klarnaevt.com *.playground.klarnaservices.com *.prod.boltdns.net *.quantserve.com *.returnscenter.com *.snapchat.com *.sync.ad.cpe.dotomi.com *.taboola.com *.twitter.com *.typekit.net *.yotpo.com ajax.googleapis.com arttrk.com blob: cdn-widgetsrepository.yotpo.com ct.pinterest.com d3cgm8py10hi0z.cloudfront.net evt-eu.klarnaservices.com filesystem hls.ak.o.brightcove.com http://localhost http://localhost:3000 http://localhost:3100 https://api.keen.io https://assets.rise-ai.com https://beacon.searchspring.io https://builder.io https://cdn.builder.io https://cdn.builder.io https://cdn.jsdelivr.net https://cdn.shopify.com https://contact.gorgias.help https://data.debugbear.com/ https://fonts.gstatic.com https://maps.googleapis.com https://maps.gstatic.com https://metrics.brightcove.com https://players.brightcove.net https://storemapper-herokuapp-com.global.ssl.fastly.net https://storemapper.co https://str.rise-ai.com https://toms.returns.international https://unpkg.com https://www.google.com https://www.storemapper.co js.klarna.com na.klarnaevt.com osm.klarnaservices.com sc-static.net t.co tagmanager.google.com tags.creativecdn.com vjs.zencdn.net www.youtube.com x.klarnacdn.net cdn.cookielaw.org *.onetrust.com www.google.com *.securedvisit.com track.sv.rkdms.com agkn.com safevisit.online s3.amazonaws.com *.gorgias.chat *.gorgias.io *.gorgias.work https://storage.googleapis.com *.id.me *.metrics.convertexperiments.com logs.convertexperiments.com *.convertexperiments.com 'self' 'nonce-f1b4d285947f7710dad5a87d36591573' https://cdn.shopify.com https://shopify.com; frame-ancestors 'self' http://localhost http://localhost:3000 http://localhost:3100 https://cdn.shopify.com https://cdn.builder.io https://builder.io https://www.youtube.com *.listrakbi.com *.listrak.com *.yotpo.com *.securedvisit.com track.sv.rkdms.com agkn.com safevisit.online *.gorgias.chat *.gorgias.io *.gorgias.work https://storage.googleapis.com *.id.me *.metrics.convertexperiments.com logs.convertexperiments.com *.convertexperiments.com; style-src 'self' data: 'unsafe-inline' *.listrakbi.com *.typekit.net *.yotpo.com http://localhost http://localhost:3000 http://localhost:3100 https://builder.io https://cdn.builder.io https://cdn.jsdelivr.net https://cdn.shopify.com https://fonts.googleapis.com https://fonts.gstatic.com https://maps.gstatic.com players.brightcove.net ws://localhost:8002 x.klarnacdn.net cdn.cookielaw.org www.googletagmanager.com *.securedvisit.com track.sv.rkdms.com agkn.com safevisit.online s3.amazonaws.com *.gorgias.chat *.gorgias.io *.gorgias.work https://storage.googleapis.com *.id.me *.metrics.convertexperiments.com logs.convertexperiments.com *.convertexperiments.com 'self' 'unsafe-inline' https://cdn.shopify.com; connect-src 'self' *.akamaihd.net *.amplitude.com *.billypx.com *.bing.com *.boltdns.net *.cookielaw.org *.creativecdn.com *.criteo.com *.g.doubleclick.net *.google-analytics.com *.google.com *.googlesyndication.com *.gorgias.chat *.intentiq.com *.listrak.com *.listrakbi.com *.onetrust.com *.playground.klarna.com *.playground.klarnaevt.com *.playground.klarnaservices.com *.snapchat.com *.taboola.com *.tiktok.com *.toms.com *.yotpo.com *.myunidays.com *.prod.unidays.io *.safevisit.online ct.pinterest.com edge.api.brightcove.com evt-eu.klarnaservices.com hits.getelevar.com http://localhost http://localhost:3000 http://localhost:3100 https://api.keen.io https://application.rise-ai.com https://beacon.searchspring.io https://builder.io https://cdn.builder.io https://data.debugbear.com https://manifest.prod.boltdns.net https://maps.googleapis.com https://storemapper-herokuapp-com.global.ssl.fastly.net https://storemapper.co https://unpkg.com https://www.storemapper.co js.klarna.com na.klarnaevt.com osm.klarnaservices.com placehold.co players.brightcove.net staticw2.yotpo.com ws://localhost:8002 wss://*.gorgias.chat wss://perfect-alive-akita.ngrok-free.app www.youtube.com www.google.com x.klarnacdn.net yscds2.a.searchspring.io *.securedvisit.com track.sv.rkdms.com agkn.com safevisit.online *.liadm.com *.amazon-adsystem.com *.paa-reporting-advertising.amazon *.yottaa.net *.gorgias.chat *.gorgias.io *.gorgias.work https://storage.googleapis.com *.id.me *.metrics.convertexperiments.com logs.convertexperiments.com *.convertexperiments.com 'self' https://monorail-edge.shopifysvc.com; font-src 'self' data: *.typekit.net *.unidays.world *.yotpo.com cdn.shopify.com fonts.googleapis.com fonts.gstatic.com mediacdn.espssl.com x.klarnacdn.net *.securedvisit.com track.sv.rkdms.com agkn.com safevisit.online *.gorgias.chat *.gorgias.io *.gorgias.work https://storage.googleapis.com *.id.me *.metrics.convertexperiments.com logs.convertexperiments.com *.convertexperiments.com; img-src 'self' data: *; media-src blob: *.akamaihd.net manifest.prod.boltdns.net *.securedvisit.com track.sv.rkdms.com agkn.com safevisit.online *.gorgias.chat *.gorgias.io *.gorgias.work https://storage.googleapis.com *.id.me *.metrics.convertexperiments.com logs.convertexperiments.com *.convertexperiments.com; frame-src *.adsrvr.org *.aftership.com *.bing.com *.creativecdn.com *.criteo.com *.doubleclick.net *.g.doubleclick.net *.gorgias.chat *.gorgias.help *.klarnaservices.com *.listrak.com *.quantserve.com *.rise-ai.com *.snapchat.com *.sync.ad.cpe.dotomi.com *.taboola.com *.twitter.com arttrk.com ct.pinterest.com *.returnscenter.com t.co www.myunidays.com *.toms.com toms.returns.international s3.amazonaws.com hosted-pages.id.me *.securedvisit.com track.sv.rkdms.com agkn.com safevisit.online *.amazon-adsystem.com *.gorgias.chat *.gorgias.io *.gorgias.work https://storage.googleapis.com *.id.me *.metrics.convertexperiments.com logs.convertexperiments.com *.convertexperiments.com |
oxygen-full-page-cache: |
uncacheable |
powered-by: |
Shopify, Oxygen, Hydrogen |
x-request-id: |
o2-6907cd41-cdc7-4aae-8450-8bd096886978.8d0710da687c9ffc |
x-shopid: |
74105291043 |
set-cookie: |
__cf_bm=TiGchKFKf0Q_gkwXuUBqnWI5hoPV3CijvhrhEz0paYs-1728568084-1.0.1.1-lvL7zFvbsJeigOEA6w2I6fzgt8hQGnDV1WG6LBfDghAKNo7qfZyxF086nK3D7DH5L.DHn9viWvN6AecjtGGDsg; path=/; expires=Thu, 10-Oct-24 14:18:04 GMT; domain=.www.toms.com; HttpOnly; Secure; SameSite=None |
report-to: |
{"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=FZVvlGo0amI4cxbX8i4vPELTuuQ1F8D6Us1QB9vhVK35y6GDITNWBTLGBzH0k7BdYVgVcwx89tFAmeweEh%2F1JEF2xtJmOl2LYTmtlsERx0rcbbcalCouol7MFecipg%3D%3D"}],"group":"cf-nel","max_age":604800} |
nel: |
{"success_fraction":0.01,"report_to":"cf-nel","max_age":604800} |
server: |
cloudflare |
cf-ray: |
8d0710da687c9ffc-AMS |
alt-svc: |
h3=":443"; ma=86400 |