BYPASS
8436710df9c0642b-LHR
max-age=0, must-revalidate, no-cache, no-store
keep-alive
gzip
text/html; charset=UTF-8
Wed, 10 Jan 2024 16:54:23 GMT
Tue, 10 Jan 2023 15:09:55 GMT
{"success_fraction":0,"report_to":"cf-nel","max_age":604800}
{"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v3?s=N4u2PEcNCDbmujWf3hEwcVOyVmv65DtarU2jzHNLIEP6wmGVg5YMvHM8%2FHxHUVbvRcTZOpXb1iGtTmOiFS%2Fjl%2F%2FOrFCpIIhx1FjEGfsVaL6Rsn%2B6qetaYmy4CP%2FflCyOIbDW9u%2BQ8Q%3D%3D"}],"group":"cf-nel","max_age":604800}
cloudflare
PHPSESSID=h42u0so8thr15rjjebpquk9fap; expires=Wed, 24-Jan-2024 16:54:23 GMT; Max-Age=1209600; path=/; domain=www.badkamerwinkel.nl; secure; HttpOnly; SameSite=Lax
max-age=63072000; preload;
Accept-Encoding
h3=":443"; ma=86400
font-src script.hotjar.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ https://www.googletagmanager.com/ js.mollie.com gum.criteo.com myclang.com vars.hotjar.com www.google.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io https://images.unsplash.com http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ https://www.google.com/ https://www.mollie.com ad.360yield.com ads.yahoo.com bat.bing.com belco-prod.s3-eu-central-1.amazonaws.com c.bing.com *.clarity.ms cm.adform.net cm.g.doubleclick.net cm.mgid.com contextual.media.net criteo-sync.teads.tv dis.criteo.com eb2.3lift.com i.liadm.com i6.liadm.com match.sharethrough.com pixel.advertising.com pixel.rubiconproject.com r.casalemedia.com rtb-csync.smartadserver.com s.ad.smaato.net script.hotjar.com secure.adnxs.com simage2.pubmatic.com sp.analytics.yahoo.com sync-t1.taboola.com sync.e-planning.net sync.outbrain.com ups.analytics.yahoo.com us-u.openx.net www.google.nl x.bidswitch.net ts.tradetracker.net www.magmodules.eu data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ http://www.googletagmanager.com/ https://www.googletagmanager.com/ js.mollie.com ajax.cloudflare.com static.cloudflareinsights.com bat.bing.com cdn.belco.io *.clarity.ms erp.badkamerwinkel.be erp.badkamerwinkel.nl erp.installatievakwinkel.nl script.hotjar.com sslwidget.criteo.com static.criteo.net static.hotjar.com www.google.com bam.nr-data.net bam-cell.nr-data.net js-agent.newrelic.com tm.tradetracker.net 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com http://stats.g.doubleclick.net/ https://stats.g.doubleclick.net/ http://www.google-analytics.com/ https://www.google-analytics.com/ cloudflareinsights.com adservice.google.com bat.bing.com cdn.belco.io chat.belco.io wss://chat.belco.io *.clarity.ms erp.badkamerwinkel.be erp.badkamerwinkel.nl erp.installatievakwinkel.nl surveystats.hotjar.io vc.hotjar.io *.hotjar.com wss://*.hotjar.com www.google.com bam.nr-data.net bam-cell.nr-data.net 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline';
no-cache
strict-origin-when-cross-origin
Hyva Themes
nosniff
SAMEORIGIN
IE=edge
1; mode=block
|