server: |
nginx |
content-type: |
text/html; charset=UTF-8 |
transfer-encoding: |
chunked |
connection: |
close |
vary: |
Accept-Encoding |
cache-control: |
no-cache, private |
date: |
Thu, 03 Oct 2024 06:10:25 GMT |
content-security-policy: |
default-src 'self' https://hotelcard.com/ https://*.hotelcard.com/ https://www.google-analytics.com/ https://firebaseinstallations.googleapis.com/ https://fcmregistrations.googleapis.com/ https://firebase.googleapis.com/ https://stats.g.doubleclick.net/ https://bid.g.doubleclick.net/ https://api.trustyou.com/ https://s7.addthis.com/ https://hotelcard.ch/ https://*.hotelcard.ch/ https://www.awin1.com/ https://the.sciencebehindecommerce.com/ https://www.paypal.com/ https://player.vimeo.com/ https://www.youtube.com/ https://youtu.be/ https://api-public.addthis.com/ https://www.getback.ch/ https://apps.elfsight.com/ https://api.instacloud.io/ https://m.youtube.com/ https://wchat.eu.freshchat.com/ https://500159408622426.eu.webpush.freshchat.com/ https://tagmanager.google.com/ https://unbounce.com/ https://landing.hotelcard.com/ https://ads.google.com/ https://www.hotjar.com/ https://www.facebook.com/ https://m.addthis.com/ https://vars.hotjar.com/ https://in.hotjar.com/ https://ws7.hotjar.com/ http://*.hotjar.com https://*.hotjar.com http://*.hotjar.io https://*.hotjar.io wss://*.hotjar.com https://e-payment.postfinance.ch/ https://epayment.postfinance.ch/ https://maps.googleapis.com/ https://secure.pointspay.com/ https://*.pointspay.com/ https://cdn.adt612.com/ https://hooks.stripe.com https://*.google-analytics.com https://analytics.google.com https://td.doubleclick.net https://pagead2.googlesyndication.com https://cdn.linkedin.oribi.io https://analytics.tiktok.com https://*.analytics.google.com http://cnv.adt670.com https://gtm.adt313.net https://pspui.reka.ch https://capig.stape.org https://px.ads.linkedin.com; font-src 'self' https://fonts.gstatic.com/ https://use.fontawesome.com/ https://fonts.gstatic.com/ http://script.hotjar.com https://script.hotjar.com http://*.hotjar.com https://*.hotjar.com http://*.hotjar.io https://*.hotjar.io https://cdnjs.cloudflare.com/; img-src 'self' data: https: https://hotelcard-files.ams3.cdn.digitaloceanspaces.com/ https://hotelcard-files.ams3.digitaloceanspaces.com/ https://maps.gstatic.com/ https://hotelcard-stage-files.fra1.digitaloceanspaces.com/ https://www.facebook.com/ https://www.google.com/ http://www.awin1.com/ http://*.hotjar.com https://*.hotjar.com http://*.hotjar.io https://*.hotjar.io https://script.hotjar.com http://script.hotjar.com https://cdn.valuesportal.com https://log.adtraction.fail; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://use.fontawesome.com/ https://www.gstatic.com/ https://maps.googleapis.com/ https://www.googletagmanager.com/ https://s3.amazonaws.com/ http://s3.amazonaws.com/ https://www.google-analytics.com/ https://www.googleadservices.com/ http://www.googleadservices.com/ https://connect.facebook.net/ https://googleads.g.doubleclick.net/ https://cdnjs.cloudflare.com/ https://cdn.jsdelivr.net/ https://s7.addthis.com/ https://z.moatads.com/ https://v1.addthisedge.com/ https://m.addthis.com/ https://hotelcard.us12.list-manage.com/ https://www.dwin1.com/ https://code.jquery.com/ https://maxcdn.bootstrapcdn.com/ https://static.profity.ch/ https://www.getback.ch/ https://www.awin1.com/ https://the.sciencebehindecommerce.com/ https://www.google.com/ https://static.getback.ch/ https://apps.elfsight.com/ https://static.elfsight.com/ https://wchat.eu.freshchat.com/ https://assetscdn-wchat.eu.freshchat.com/ https://snap.licdn.com/ http://static.hotjar.com https://static.hotjar.com/ https://script.hotjar.com/ http://www.awin1.com/ https://ws7.hotjar.com/ http://*.hotjar.com https://*.hotjar.com http://*.hotjar.io https://*.hotjar.io http://*.addthis.com/ https://cdn.adt612.com/ https://*.hotelcard.de/ https://gtm.adt313.net https://analytics.tiktok.com https://analytics.google.com https://valuesportal.com https://cnv.adt670.com https://lantern.roeyecdn.com; style-src 'self' 'unsafe-inline' https://fonts.googleapis.com/ https://use.fontawesome.com/ https://cdnjs.cloudflare.com/ https://maxcdn.bootstrapcdn.com/ https://www.getback.ch/ https://static.getback.ch/ https://wchat.eu.freshchat.com/, frame-ancestors https://admin.hotelcard.com 'self'; |
permissions-policy: |
accelerometer=(self), autoplay=(self), camera=(self), cross-origin-isolated=(self), document-domain=*, encrypted-media=(self), fullscreen=(self), geolocation=(self), gyroscope=(self), magnetometer=(self), microphone=(self), midi=(self), payment=(self), picture-in-picture=*, publickey-credentials-get=(self), screen-wake-lock=(self), sync-xhr=*, usb=(self), xr-spatial-tracking=(self) |
strict-transport-security: |
max-age=31536000; includeSubDomains; preload |
x-download-options: |
noopen |
x-permitted-cross-domain-policies: |
none |
x-xss-protection: |
1; mode=block, 1; mode=block |
referrer-policy: |
no-referrer |
cross-origin-embedder-policy: |
unsafe-none |
cross-origin-opener-policy: |
unsafe-none |
cross-origin-resource-policy: |
cross-origin |
set-cookie: |
XSRF-TOKEN=eyJpdiI6IkVDN1lXcE1Scis4MGpiRDZoUC9FTHc9PSIsInZhbHVlIjoicTl2TnFtV09INWxPQnA5SHBGZGlTUUNTeURJOEkwZDY0eVdJbTcybHBFZmwxQnpIMXlZRjJpUGlXZnZRTXVxT25wMU9KaGI1MlcwdFBUUU8yNzRwZzJlNFByanpkb1VyanBkdmFwT0cyUWpZemc1Sm9WNW9UVTlpa1BMcEpWOEMiLCJtYWMiOiIyMDA5MTgwZDBiNzZmNTQyZTNkNDgxYzRjMjNmNWExZDcwYTNiM2YyZGFlYWQxYzI3M2RiMmU5Y2Q2YmM5NmJmIiwidGFnIjoiIn0%3D; expires=Sat, 05-Oct-2024 06:10:25 GMT; Max-Age=172799; path=/; samesite=lax,hotelcard_session=eyJpdiI6IldXb2lIcDBXTE8ycnB5ak1mM3lwZ0E9PSIsInZhbHVlIjoicTBBS0tLKzB1MU9wQWhlVU1mSjl1cE1SanFRU2FGakQrWWRqWituTFBvcjM5dTZOdmNMUWo3Z0NYY3kyS1pmYnN1OEFHWEpUR3ZYU0Rpc2FsSnNxMG00K3RDcHZWdC8rb0J2WFEwNEdMRklRTmszZ0ZKSUo3YTUxM2hoMlZSRmUiLCJtYWMiOiJhMmY4MTQwZGZkOTY4YjcyZDQ4MTQ1NWVhNTM4MDFhOTgyNWQ5Y2EyZGMxMzliNDc5OTg1YTNhM2IwYTFiNzBkIiwidGFnIjoiIn0%3D; expires=Sat, 05-Oct-2024 06:10:25 GMT; Max-Age=172799; path=/; httponly; samesite=lax,locale=en; expires=Thu, 31-Oct-2024 06:10:23 GMT; Max-Age=2419197; path=/; secure; httponly; samesite=lax |
x-content-type-options: |
nosniff |
|