9b70f19b5e5af0ee-DUB
no-store, no-cache, must-revalidate, max-age=0
keep-alive
gzip
text/html; charset=UTF-8
Thu, 01 Jan 2026 09:20:58 GMT
cloudflare
DYNAMIC
font-src www.paypalobjects.com fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com https://www.googletagmanager.com *.googleapis.com https://fonts.gstatic.com *.cloudflare.com *.digitalbridgehq.com *.elev.io *.fixtuur.com *.goinstore.com *.honey.io *.tawk.to https://www.gstatic.com *.fontawesome.com https://fonts.bunny.net data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.arcot.com *.cardinalcommerce.com *.facebook.com *.realexpayments.com *.touch.tech *.tawk.to 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net www.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com www.paypalobjects.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.google.com account.fetchify.com *.acdcproc.com *.addthis.com *.americanexpress.com *.arcot.com *.cardinalcommerce.com *.criteo.com *.criteo.net *.digitalbridgehq.com *.doubleclick.net *.fixtuur.com *.flashtalking.com *.google.co.uk *.googlesyndication.com *.hotjar.com *.jotform.com *.kaptcha.com *.klarna.com *.klarnacdn.net *.klarnaservices.com *.lloydsbankinggroup.com *.modirum.com *.monzo.com *.pinterest.com *.playground.klarna.com *.playground.klarnaservices.com *.realexpayments.com *.rsa3dsauth.co.uk *.sandbox.paypal.com *.touch.tech *.zenaps.com ct.pinterest.com servedby.flashtalking.com *.tawk.to magento-cloudflare.jetrails.com js.mollie.com *.trustpilot.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com * https://*.google.com https://hcaptcha.com https://*.hcaptcha.com https://challenges.cloudflare.com 'self' 'unsafe-inline'; img-src data: assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com www.googleadservices.com *.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net *.analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io https://images.unsplash.com *.360yield.com *.addthis.com *.adform.net *.adnxs.com *.ads.yieldmo.com *.advertising.com *.amazon-adsystem.com *.amazonaws.com *.awin1.com *.bidswitch.net *.bing.com *.bluekai.com *.bnmla.com *.casalemedia.com *.creativecdn.com *.criteo.com *.criteo.net *.digitaleast.mobi *.dmxleo.com *.doubleclick.net *.elfsight.com *.elfsightcdn.com *.exelator.com *.feefo.com *.goinstore.com *.google.com *.google.ie *.googleapis.com *.honey.io *.imrworldwide.com *.ivitrack.com *.liadm.com *.mediavine.com *.mediawallahscript.com *.narrative.io *.outbrain.com *.pinterest.com *.postcodeanywhere.co.uk *.pubmatic.com *.revcontent.com *.rubiconproject.com *.sagepay.co.uk *.semasio.net *.smaato.net *.smartadserver.com *.socdm.com *.stickyadstv.com *.taboola.com *.tapad.com *.thebrighttag.com *.trackedlink.net *.tvsquared.com *.twiago.com *.yahoo.com *.yieldlab.net *.zdassets.com *.zemanta.com *.zenaps.com *.zendesk.com bat.bing.com beacon.krxd.net contextual.media.net coviyr.modafurnishings.co.uk criteo-partners.tremorhub.com criteo-sync.teads.tv eb2.3lift.com google.com id5-sync.com jadserve.postrelease.com maps.googleapis.com match.sharethrough.com static.elfsight.com visitor.omnitagjs.com www.coupert.com www.google.ae www.google.cn www.google.co.in www.google.co.ma www.google.co.uk www.google.co.za www.google.com.ag www.google.com.au www.google.com.bd www.google.com.eg www.google.com.lb www.google.com.my www.google.com.ph www.google.com.sa www.google.com.tr www.google.com.ua www.google.de www.google.es www.google.fr www.google.gg www.google.im www.google.it www.google.je www.google.lu www.google.nl *.tawk.to *.cdninstagram.com *.mollie.com *.ytimg.com https://www.mollie.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com https://*.google.com https://*.gstatic.com https://*.googleapis.com https://*.googleusercontent.com https://firebasestorage.googleapis.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com tagmanager.google.com https://www.googletagmanager.com https://maps.googleapis.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.cloudflare.com *.tawk.to *.app-us1.com *.bing.com *.clickguard.com *.craftyclicks.co.uk *.criteo.com *.criteo.net *.digitalbridgehq.com *.dwin1.com *.dynamicyield.com *.elev.io *.elfsight.com *.feefo.com *.finance-calculator.co.uk *.fixtuur.com *.goinstore.com *.hotjar.com *.jsdelivr.net *.opentok.com *.pcapredict.com *.pennies.org.uk *.pinimg.com *.pureclarity.net *.responsetap.com *.sciencebehindecommerce.com *.tvsquared.com *.vimeo.com *.zdassets.com *.zenaps.com trackcmp.net *.mollie.com *.googleapis.com *.salesfire.co.uk js.mollie.com *.trustpilot.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com https://*.google.com https://*.gstatic.com https://*.googleapis.com https://*.ggpht.com https://*.googleusercontent.com https://hcaptcha.com https://*.hcaptcha.com https://challenges.cloudflare.com *.avada.io *.shopify.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com https://www.googletagmanager.com tagmanager.google.com *.googleapis.com https://fonts.googleapis.com cc-cdn.com *.braintreegateway.com *.digitalbridgehq.com *.feefo.com *.finance-calculator.co.uk *.fixtuur.com *.goinstore.com *.google.com *.tawk.to *.trustpilot.com assets.braintreegateway.com https://hcaptcha.com https://*.hcaptcha.com *.fontawesome.com https://fonts.bunny.net 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net *.google-analytics.com www.googleadservices.com *.analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.snplow.net commerce.adobedc.net https://www.google-analytics.com https://*.google-analytics.com https://*.analytics.google.com https://maps.googleapis.com https://player.vimeo.com api.craftyclicks.co.uk pcls1.craftyclicks.co.uk *.addthis.com *.amazonaws.com *.app-us1.com *.bing.com *.cardinalcommerce.com *.clickguard.com *.cookiebot.com *.digitalbridgehq.com *.doubleclick.net *.dynamicyield.com *.elev.io *.elfsight.com *.feefo.com *.finance-calculator.co.uk *.fixtuur.com *.googleapis.com *.googlesyndication.com *.hotjar.com *.hotjar.io *.jsdelivr.net *.loggly.com *.my.sentry.io *.pennies.org.uk *.pinterest.com *.postcodeanywhere.co.uk *.sciencebehindecommerce.com *.smooch.io *.tokbox.com *.trustpilot.com *.ucweb.com *.zdassets.com *.zendesk.com *.zuko.io adservice.google.com bat.bing.com eu.prd.impact.fixtuur.com maps.googleapis.com www.google.co.uk www.google.it www.google.je www.google.nl www.wepowerconnections.com wss://*.tawk.to *.tawk.to *.instagram.com *.smartmetrics.co.uk *.salesfire.co.uk api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com https://ipinfo.io https://*.google.com https://*.gstatic.com https://*.googleapis.com https://hcaptcha.com https://*.hcaptcha.com https://get.geojs.io *.avada.io 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri /csp/report; report-to report-endpoint;
-1
none
no-cache
{"group":"report-endpoint","max_age":10886400,"endpoints":[{"url":"\/csp\/report"}]}
max-age=31536000; includeSubDomains
Accept-Encoding, Accept-Encoding
Hyva Themes
nosniff
SAMEORIGIN
HIT
1; mode=block
|